Skip to main content

sentinel

python license version docs ci

Tiny folder watchdog that spots ransomware-like behavior. Baseline it, watch it, get told before it is too late.

Docs site: https://hahaahhdev.github.io/sentinel/

pip install sentinel-watch
sentinel init ~/Documents
sentinel watch ~/Documents

That is the pitch. No server. No signup. Files stay local.


Why this one

Most integrity tools are built for servers and need setup. Most crypto detectors only scan once and miss live hits.

Sentinel does both, plus two things others skip:

  • vault of clean copies, so protect --restore-clean all brings back pre hit text, not post hit junk
  • one risk number via check, so CI and humans read the same line

Live rules plus one shot scan plus real restores. That combo is rare.

Demo in 30 seconds

pip install -e .
sentinel demo
sentinel scan ./demo_run
sentinel check ./demo_run
sentinel report ./demo_run --out report.html

You get entropy, file scores, and a risk line like risk warn 55. Open report.html for the pretty page.

Install

pip install sentinel-watch

From source:

git clone https://github.com/HahaAhhDev/sentinel
cd sentinel
pip install -e .

Needs Python 3.10+. Pulls watchdog, typer, rich, pyyaml, psutil. Dev extras add pytest, mkdocs, mkdocs-material.

Quickstart

sentinel init ~/Documents
sentinel verify ~/Documents
sentinel scan ~/Documents
sentinel check ~/Documents
sentinel watch ~/Documents

Full walk is in docs under Quickstart. Short version: init once, check often, watch when it matters.

Commands

Command What it does
init Hash all, fill vault
update Rehash only changed
status Counts, dates, vault size
verify Diff vs baseline
diff Text diffs via vault
scan Score files, json or sarif
why FILE Explain one file
check Verify plus scan plus risk, for CI
watch Live loop, canary, notes, storms
learn Watch quiet, suggest burst
protect Fill vault or restore clean
events, timeline Last hits
snaps, restore Quarantine packs
report, serve HTML page, local web
config-init, doctor Scaffold yaml, self test
clean, demo Wipe, fake hit

See docs/CLI.md or the web CLI page for flags and copy paste samples.

How it spots trouble

Four small rules that stack, plus one risk roll up.

  • burst: N events in M secs, stock 25 in 10
  • entropy: Shannon on first 1MB, stock line 7.5, zips and pics skipped by magic
  • canary: .sentinel/canary.txt touched means now
  • notes and exts: .locked, READ_ME.txt, words like bitcoin and decrypt

scan scores 0 to 100 per file. check rolls verify plus scan into risk clean, warn, high. Details in Rules.

Tune with learn:

sentinel learn ~/Documents --secs 60

Work like normal for a minute, it tells you a sane burst.

Config

sentinel config-init

Writes sentinel.yaml. Sentinel finds sentinel.yaml, .sentinel.yaml, .sentinel/config.yaml by walking up. Flags beat file.

burst: 25
window: 10
cooldown: 30
entropy_line: 7.5
vault_max_mb: 5
risk_warn: 40
risk_high: 70
webhook: ""
notify: false
kill: false

Ignores merge from built ins, .sentinelignore, and yaml ignore:. Full list in Config.

Alerts and restores

Hits go to terminal, .sentinel/sentinel.log, .sentinel/events.jsonl. Optional webhook, mail via local smtp, desktop popup.

Two safety nets:

  • quarantine in .sentinel/quarantine/<ts>/, post hit copies for forensics
  • vault in .sentinel/vault/, pre hit clean copies for restores
sentinel snaps .
sentinel protect . --restore-clean all

Most tools only do the first. Vault is why restores actually work.

CI and web

sentinel check ./uploads --fail-warn
sentinel scan . --sarif > results.sarif
sentinel report . --out report.html
sentinel serve . --port 8000

Sarif feeds GitHub code scanning. Html is one offline file. Serve adds /json for scripts. Workflow samples in examples/ and Actions.

Web docs build with mkdocs material. mkdocs serve to preview, push to main to publish via Pages. How to in Web docs.

Layout

sentinel/
  cli.py       # commands
  baseline.py  # hash, sqlite, diff
  detect.py    # entropy, notes, risk
  vault.py     # clean copies
  watcher.py   # live loop
  respond.py   # logs, webhook, mail, sarif
  report.py    # html
  serve.py     # local web
  learn.py     # auto tune
  proc.py      # top writer, kill
  config.py    # yaml
docs/          # pages source
examples/
tests/

Contributing

See CONTRIBUTING.md. Fork, pip install -e .[dev], pytest -q, PR with a test and what folder you tried it on.

License

MIT, see LICENSE.

Metadata

Release files for sentinel-watch 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sentinel-watch 0.3.0
File Size Uploaded
sentinel_watch-0.3.0.tar.gz 32.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sentinel-watch 0.3.0
File Interpreter ABI Platform
sentinel_watch-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 56.1 kB

Release files / sentinel_watch-0.3.0.tar.gz

Download URL sentinel_watch-0.3.0.tar.gz
Size 32.3 kB
Tags Source
SHA-256 checksum
How to use checksums
c369c8891ea58e89a217119bbe53ad4d79f3d909844476b3a5c0a1feb2572565
BLAKE2b-256 checksum
How to use checksums
49ed583f9e7b63923b7cb723ef13e7abd8e9fed28fad2b0ca750842ff486ed56
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release files / sentinel_watch-0.3.0-py3-none-any.whl

Download URL sentinel_watch-0.3.0-py3-none-any.whl
Size 23.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a048e5ec164d2ed0b3f67d3f3e7353890bcb700b721af3de0517d347d30b9c42
BLAKE2b-256 checksum
How to use checksums
463db347803a9e7c28f6c8fc16a0c7669b4e96a87857bf146a8e27f404ac4380
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.

Transparency log

Release history Release notifications | RSS feed

0.5.0

2 release files

This release

0.3.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page