Skip to content

CLI reference

All commands. sentinel --help prints the same.

init

sentinel init ~/Documents
sentinel init . --jobs 8 --vault-mb 5

Hashes all files to .sentinel/baseline.db and fills .sentinel/vault with small clean copies. Vault is what protect and diff use later.

update

sentinel update .

Rehash only what changed by size or mtime. Fast for big folders.

status

sentinel status .

Shows count, dates, vault size.

verify

sentinel verify .
sentinel verify . --json
sentinel verify . --fail
sentinel verify . --html report.html

Diff vs baseline. --fail exits 1 on changed or deleted. Good for CI.

diff

sentinel diff .
sentinel diff . --n 5

Unified diffs for changed text files using vault copies.

scan

sentinel scan .
sentinel scan . --json
sentinel scan . --sarif > results.sarif
sentinel scan . --html report.html

Score 0 to 100. Prints 40+. Use --sarif for GitHub code scanning.

why

sentinel why ./weird.enc

One file score, entropy, size, reasons.

check

sentinel check .
sentinel check . --json
sentinel check . --sarif > results.sarif
sentinel check . --fail-warn

Verify plus scan plus one risk number. The one to run in CI. Fails on high or drift by default, on warn with --fail-warn.

watch

sentinel watch .
sentinel watch . --burst 25 --window 10 --cooldown 30
sentinel watch . --webhook "$URL" --notify --kill
sentinel watch . --daemon
sentinel watch . --response auto

Live loop. Order per event: canary, note, rename or delete storm, burst, single scrambled file. Cooldown keeps it to 1 or 2 alerts per hit.

--response picks warn, auto, or paranoid. auto kills the writer and jails its binary. paranoid also freezes the rest. --daemon forks to bg and writes .sentinel/watch.pid. On Windows use win-task to run at logon.

learn

sentinel learn . --secs 60

Sit quiet while you work, then suggests burst and window.

protect

sentinel protect .
sentinel protect . --restore-clean all
sentinel protect . --restore-clean a.txt,b.txt

Fill vault, or bring clean copies back. This beats plain quarantine because it restores pre hit text, not post hit junk.

harden, netscan, persist

sentinel harden .
sentinel harden . --json
sentinel netscan
sentinel persist

harden does one pass: canaries, autostart scan, odd connections, drift, tier. netscan shows live odd connections. persist lists autostart entries scored for bad signs. Full story in Protection and Windows pages.

quar and win-task

sentinel quar .
sentinel quar . --resume-pid 1234
sentinel win-task "C:\Data" --create
sentinel win-task "C:\Data" --remove

quar lists jailed binaries with sha. --resume-pid unfreezes a held proc. win-task prints or makes the logon task on Windows.

bench, policy, prune, incident, service, intel

sentinel bench .
sentinel policy .
sentinel policy . --file weird.enc
sentinel prune . --max-mb 500
sentinel incident . --out case.zip
sentinel service ~/Documents --install
sentinel intel . --add <sha>
sentinel intel . --import-file feed.txt

bench prints hash rate. policy shows tier, rules, config gripes. prune trims snaps and logs. incident zips a case bundle. service prints always on steps per OS. intel manages the local sha blocklist.

events and timeline

sentinel events .
sentinel events . --json
sentinel timeline . --n 30

Last hits from .sentinel/events.jsonl.

snaps and restore

sentinel snaps .
sentinel restore .
sentinel restore . 20240101_120000

Quarantine packs are post hit copies for forensics. Vault is for real restores. Use both.

report and serve

sentinel report . --out report.html
sentinel serve . --port 8000

report writes one offline html file. serve hosts it at http://127.0.0.1:8000 with json at /json.

config-init and doctor

sentinel config-init
sentinel config-init my.yaml
sentinel doctor .

Scaffold yaml, or self test perms and baseline.

clean and demo

sentinel clean .
sentinel demo
sentinel demo ./scratch

Wipe state, or build a fake hit to test rules.