◆ SENTINEL

ATTENTION
Live security posture · 17 components tracked · generated 2026-10-01T16:50:02Z · auto-refresh 2 min

Health

suricata
ACTIVE
systemd unit
fail2ban
ACTIVE
systemd unit
dnsmasq
ACTIVE
systemd unit
sentinel-canary
ACTIVE
systemd unit
Jarvis gateway
EXITED
openclaw-ynsy
Vaultwarden
RUNNING
identity vault
Wazuh XDR
3/3 UP
manager+indexer+dash
Mac backup
33h ago
restic offsite pull

Protected devices

DeviceProtectionConnectionActivity todayStatus
Saad-iPhone
10.13.13.4
All traffic shielded · Private DNS · Ad/malware block · Spyware watchOffline
last seen 1d ago
0 DNS lookups today · 23 MiB in / 77 MiB outProtected — no problems. 0 ad/tracker/malware lookups blocked for this device today; nothing suspicious seen from it.
Saad-iPhone (backup DNS profile)
10.13.13.2
DNS filtering only (ads/malware + spyware watch when this profile is in use)Standby — not connected
this profile has never dialled in
0 DNS lookups today · 0 MiB in / 0 MiB outNo problems. This backup profile is not currently in use — Saad-iPhone runs on its full-tunnel profile instead.
Partner-phone
10.13.13.3
DNS filtering only (ads/malware + spyware watch when this profile is in use)Standby — not connected
this profile has never dialled in
0 DNS lookups today · 0 MiB in / 0 MiB outNo problems. This backup profile is not currently in use — Saad-iPhone runs on its full-tunnel profile instead.
Partner-iPhone-2
10.13.13.5
All traffic shielded · Private DNS · Ad/malware block · Spyware watchOffline
last seen 1d ago
0 DNS lookups today · 0 MiB in / 0 MiB outProtected — no problems. 0 ad/tracker/malware lookups blocked for this device today; nothing suspicious seen from it.
Every device routes through the VPS tunnel: encrypted upstream DNS (Quad9 over TLS), the 334k-domain ad/malware blocklist, and the Amnesty spyware-DNS watch. Full-tunnel devices send all traffic through it; DNS-only profiles filter lookups only.

Detection activity

Canary trips (today)
10
decoy-file opens · 733 all-time
Suricata IDS (today)
367
high-sev alerts · 54885 fast.log lines
Spyware DNS hits
134
Amnesty IOC matches
Ads/malware blocked
00
bad domains stopped today (all devices)
Breach password checks
1
HIBP corpus matches flagged

Recent IDS alerts (Suricata)

Time (UTC)PriSourceSignature
10/01/2026-16:45:41.024411P2195.184.76.24[1:2402000:7878] ET DROP Dshield Block Listed Source group 1
10/01/2026-16:45:41.024411P2195.184.76.24[1:2403580:112108] ET CINS Active Threat Intelligence Poor Reputation IP group 281
10/01/2026-16:45:41.331472P291.231.89.251[1:2403450:112108] ET CINS Active Threat Intelligence Poor Reputation IP group 151
10/01/2026-16:46:12.995312P291.230.168.124[1:2403445:112108] ET CINS Active Threat Intelligence Poor Reputation IP group 146
10/01/2026-16:46:56.011200P291.230.168.233[1:2403446:112108] ET CINS Active Threat Intelligence Poor Reputation IP group 147
10/01/2026-16:48:23.534251P291.196.152.222[1:2403444:112108] ET CINS Active Threat Intelligence Poor Reputation IP group 145
10/01/2026-16:48:59.247575P391.108.121.200[1:2048911:4] ET INFO Observed DNS Over HTTPS Domain (dns .quad9 .net in TLS SNI)
10/01/2026-16:49:50.048668P3105.77.200.133[1:2210044:2] SURICATA STREAM Packet with invalid timestamp

Patch & update freshness

ItemStateDetail
unattended-upgrades10h ago2026-10-01T06:42:14Z
OpenClaw gatewaypinneddiff-review before upgrade (monthly)
Skillspinnednever blind-pull; re-review diffs

Component inventory (SENTINEL.md · live)

ComponentLayerVersion / feedLastCadenceNote
OpenClaw gatewayPlatformv2026.7.12026-07-1930dcheck latest stable monthly; pinned, diff-review before upgrade
VPS host OSPlatformDebian2026-07-197dapply security patches weekly
Skills (pinned)Platformpinned2026-07-2530ddiff re-review before any `skills update` — never blind-pull
Mobile spyware DNS-watchDetection1167 Amnesty IOCs2026-07-261dWireGuard DNS-only + dnsmasq + spyware-dns-check; refresh 04:17 daily; alerts Saad on a hit
Ad/malware DNS blocker (OISD)Network334k domains2026-07-261doisd-block.conf on wg0 dnsmasq; refresh 04:37 daily, validated + auto-rollback
WireGuard full-tunnel VPNNetworkwg0 10.13.13.0/242026-07-2930dpersonal VPN; all peer traffic egresses via VPS so Sentinel DNS-watch + OISD block + DoT apply to the phone; port 51820/udp; peers 10.13.13.2-.7; Noura .7 added 2026-07-29 (full-tunnel, preshared-key)
Encrypted upstream DNS (DoT)NetworkQuad9 TLS2026-07-2630dsystemd-resolved DNSOverTLS strict; dnsmasq->127.0.0.53->Quad9:853; no plaintext leak (verified)
Canary tripwiresDetection3 decoy files2026-07-2690dsentinel-canary.service (inotify); WhatsApp alert on any open; log /var/log/sentinel-canary.log
VaultwardenIdentityself-hosted2026-07-2630dvault.91.108.121.200.sslip.io; signups disabled; nightly backup 03:15
Restic offsite backup (VPS->Mac)Resiliencerestic 0.19.12026-07-261ddaily 10:00 pull to Saad Mac, encrypted, keep 14d/8w; WhatsApp alert on failure
Immutable backup mirrorResiliencerest-server append-only2026-07-2630d2nd Restic repo on Mac; nightly restic copy; deletes rejected 403 (ransomware insurance); verified
ufw firewallNetworkdefault-deny2026-07-2630donly 22, 80, 443, 51820/udp + wg0; verified vault/DNS/WG unaffected
fail2ban (sshd)Networksystemd backend2026-07-2630dauto-bans SSH brute-force IPs
unattended-upgradesPlatformsecurity-only2026-07-261ddaily security patches, no auto-reboot; supersedes weekly-manual patching
AIDE file integrityDetectiondaily 05:072026-07-261dalerts Saad on filesystem changes, auto-rebaselines after alert
rkhunter rootkit scanDetectionweekly Sun 05:172026-07-267dalerts Saad on warnings
Break-glass playbookHumandoc v12026-07-26180d~/Desktop/Jarvis docs/Sentinel-Break-Glass-Playbook.html; 6 incident runbooks; Saad to print