CLI reference
All commands. sentinel --help prints the same.
init
sentinel init ~/Documents
sentinel init . --jobs 8 --vault-mb 5
Hashes all files to .sentinel/baseline.db and fills .sentinel/vault with small clean copies. Vault is what protect and diff use later.
update
sentinel update .
Rehash only what changed by size or mtime. Fast for big folders.
status
sentinel status .
Shows count, dates, vault size.
verify
sentinel verify .
sentinel verify . --json
sentinel verify . --fail
sentinel verify . --html report.html
Diff vs baseline. --fail exits 1 on changed or deleted. Good for CI.
diff
sentinel diff .
sentinel diff . --n 5
Unified diffs for changed text files using vault copies.
scan
sentinel scan .
sentinel scan . --json
sentinel scan . --sarif > results.sarif
sentinel scan . --html report.html
Score 0 to 100. Prints 40+. Use --sarif for GitHub code scanning.
why
sentinel why ./weird.enc
One file score, entropy, size, reasons.
check
sentinel check .
sentinel check . --json
sentinel check . --sarif > results.sarif
sentinel check . --fail-warn
Verify plus scan plus one risk number. The one to run in CI. Fails on high or drift by default, on warn with --fail-warn.
watch
sentinel watch .
sentinel watch . --burst 25 --window 10 --cooldown 30
sentinel watch . --webhook "$URL" --notify --kill
sentinel watch . --daemon
sentinel watch . --response auto
Live loop. Order per event: canary, note, rename or delete storm, burst, single scrambled file. Cooldown keeps it to 1 or 2 alerts per hit.
--response picks warn, auto, or paranoid. auto kills the writer and jails its binary. paranoid also freezes the rest. --daemon forks to bg and writes .sentinel/watch.pid. On Windows use win-task to run at logon.
learn
sentinel learn . --secs 60
Sit quiet while you work, then suggests burst and window.
protect
sentinel protect .
sentinel protect . --restore-clean all
sentinel protect . --restore-clean a.txt,b.txt
Fill vault, or bring clean copies back. This beats plain quarantine because it restores pre hit text, not post hit junk.
harden, netscan, persist
sentinel harden .
sentinel harden . --json
sentinel netscan
sentinel persist
harden does one pass: canaries, autostart scan, odd connections, drift, tier. netscan shows live odd connections. persist lists autostart entries scored for bad signs. Full story in Protection and Windows pages.
quar and win-task
sentinel quar .
sentinel quar . --resume-pid 1234
sentinel win-task "C:\Data" --create
sentinel win-task "C:\Data" --remove
quar lists jailed binaries with sha. --resume-pid unfreezes a held proc. win-task prints or makes the logon task on Windows.
bench, policy, prune, incident, service, intel
sentinel bench .
sentinel policy .
sentinel policy . --file weird.enc
sentinel prune . --max-mb 500
sentinel incident . --out case.zip
sentinel service ~/Documents --install
sentinel intel . --add <sha>
sentinel intel . --import-file feed.txt
bench prints hash rate. policy shows tier, rules, config gripes. prune trims snaps and logs. incident zips a case bundle. service prints always on steps per OS. intel manages the local sha blocklist.
events and timeline
sentinel events .
sentinel events . --json
sentinel timeline . --n 30
Last hits from .sentinel/events.jsonl.
snaps and restore
sentinel snaps .
sentinel restore .
sentinel restore . 20240101_120000
Quarantine packs are post hit copies for forensics. Vault is for real restores. Use both.
report and serve
sentinel report . --out report.html
sentinel serve . --port 8000
report writes one offline html file. serve hosts it at http://127.0.0.1:8000 with json at /json.
config-init and doctor
sentinel config-init
sentinel config-init my.yaml
sentinel doctor .
Scaffold yaml, or self test perms and baseline.
clean and demo
sentinel clean .
sentinel demo
sentinel demo ./scratch
Wipe state, or build a fake hit to test rules.