Aientrophy Nightwatch
Real-time file monitoring agent with YARA scanning and AI-powered malware analysis.
Features
- Real-time file monitoring — watchdog-based filesystem watcher with event deduplication
- Multi-layer scanning pipeline — Hash DB → Extension mismatch → YARA rules → Cloud AI
- YARA rule engine — Compiled rule matching with auto-update from cloud
- Extension disguise detection — Detects executables/scripts masquerading as images/documents
- Quarantine management — Automatic isolation with metadata tracking and restore capability
- Cloud AI analysis — Escalates suspicious files to Claude API for deep inspection
- Lightweight agent — ~50MB RAM footprint, all heavy analysis offloaded to cloud
Quick Start
# Install
pip install aientrophy-nightwatch
# Scan a single file
nightwatch scan /path/to/suspicious/file
# Start monitoring daemon
nightwatch start --config /etc/aientrophy/agent.yml
# Check status
nightwatch status
One-line Server Install
curl -sL https://install.aientrophy.com/agent | sudo bash -s -- --key YOUR_API_KEY
Configuration
watch:
paths:
- /var/www
- /tmp
recursive: true
scan:
yara_rules_dir: /var/lib/aientrophy/yara-rules
hash_db_path: /var/lib/aientrophy/hash-db/malware_hashes.txt
action:
on_detect: quarantine # quarantine | alert | block
cloud:
server: https://malware.aientrophy.com
Requirements
- Python 3.10+
- Linux (recommended) or Windows
Links
- Homepage: https://aientrophy.com
- Documentation: https://docs.aientrophy.com/nightwatch
Metadata
Release files for aientrophy-nightwatch 0.2.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aientrophy_nightwatch-0.2.3.tar.gz | 37.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aientrophy_nightwatch-0.2.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 72.4 kB
Release files / aientrophy_nightwatch-0.2.3.tar.gz
| Download URL | aientrophy_nightwatch-0.2.3.tar.gz |
|---|---|
| Size | 37.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f6a8a4618f90439a5403c4dcafc6d8caaa7ab63ef43e83d964cc24e0f4d47061
|
|
BLAKE2b-256 checksum How to use checksums |
5f367872f990d1278022c1f5d48349f63bdd60fe2ede5f17cf2b275bd9ea86c5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.10.10
|
Release files / aientrophy_nightwatch-0.2.3-py3-none-any.whl
| Download URL | aientrophy_nightwatch-0.2.3-py3-none-any.whl |
|---|---|
| Size | 35.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5b1db6e79817ed8bdda7d5c3c7ae4fa0ce9b6bece0e8fa7a33811c79648b9117
|
|
BLAKE2b-256 checksum How to use checksums |
730c75f57ae8b659f55657ff34f105c52cd4a1a37a155edf5720262ccd6dd46d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.10.10
|