Releases: lifeqsoll/SysSpectogram
Release list
v0.9.0 — hardening + product finish
SysSpectogram v0.9.0 — hardening + product finish
v0.9 hardens the single-VPS path without pretending to be kernel EDR, finishes
the operator story (Day-0, golden path, eval, threat model), and cleans up
overloaded README navigation.
Included
Safe artifacts (no pickle on the critical path)
- Train/export write
scaler.jsonandiforest.ssf.npz(+ meta). - Runtime refuses
.joblib; migrate-only legacy read via
artifacts migrate --delete-legacy. - Agent IF train/load uses
.ssf.npz. supply_chain.enforce: truerefuses unsigned / unsafe loads.
Remote alert sinks
alerts:
allow_private_sinks: false
strict_secrets: true
sinks:
- type: file
path: reports/alerts.jsonl
# - type: syslog
# host: siem.example
# port: 6514
# transport: tls
# - type: https
# url: https://collector.example/ingest
# token_env: SS_ALERT_TOKENFail-open per sink. HTTPS SSRF guards + token_env for secrets. Not a full SIEM.
FIM
- Baseline persists to
state/fim-baseline.json(+.sha256seal) via serde_json. - Enabled by default on the
liteload profile (longer interval).
Hybrid watchdog
- Phoenix userspace twin + Dead-man remote emit; systemd
WatchdogSec. - Optional DKMS module
packaging/kmod/sysspectogram_wd(PID registry;
watchdog.kernel_protect: falseby default).
Narrow auto-isolate
kirk:
auto_isolate: false
auto_isolate_host_risk: false
host_risk_threshold: 0.99Host-risk path still requires allow_ssh_cidrs.
Docs & eval
- README EN/RU: grouped links, Limitations, ONNX VPS recipe.
- DAY0_VPS.md, GOLDEN_PATH.md,
EVAL.md, THREAT_MODEL.md,
SUPPLY_CHAIN_STORY.md, AGENT.md. scripts/eval_offline.py,scripts/demo_golden_path.sh.
Migrate existing models
python -m sysspectogram artifacts migrate --model artifacts/live --delete-legacy
python -m sysspectogram supply-chain manifest --root artifacts/live
# re-sign if you enforceVerify
pytest -q
cd agent && cargo check
python scripts/eval_offline.py --dataset dataset/ --methods zscore --out reports/evalHonest ceiling
Same-host root can stop units and wipe local disks. Remote sinks + signatures
make that louder and harder to hide — not impossible. VMI remains v1.0.
SysSpectogram v0.8.0 — signed supply chain
SysSpectogram v0.8.0 — signed supply chain
v0.8 hardens the path from a release or model builder to a running VPS:
signed artifacts, deterministic manifests, SPDX SBOM, distro package recipes,
and a safe model-loading policy.
Included
- Minisign signatures for release binaries, Python distributions, checksums,
SBOM, and profile packs. - Deterministic
artifacts.manifest.jsonwith SHA-256 and size for every model
file. - Optional
supply_chain.enforcepolicy propagated through guard, monitor,
offline analysis, web, and Telegram scoring. cnn.ptloading withweights_only=Trueonly; no unsafe arbitrary-object
fallback.- SPDX 2.3 SBOM generator for installed Python and Cargo dependencies.
- Dependabot configuration for pip, Cargo, and GitHub Actions.
- Buildable AUR and Debian packaging recipes with hardened systemd units.
- Release verification helper that never executes downloaded assets.
Compatibility and rollout
Existing v0.7.x configs continue to work with enforcement disabled:
supply_chain:
enforce: falseAfter installing the release public key and signing the model directory:
supply_chain:
enforce: true
public_key: /etc/sysspectogram/sysspectogram.minisign.pub
manifest_name: artifacts.manifest.json
signature_name: artifacts.manifest.json.minisigUse python -m sysspectogram configure to set this interactively. It refuses
to enable enforcement without a public key.
Verify release assets
minisign -Vm sysspectogram-agent-x86_64-linux-musl \
-p SysSpectogram.minisign.pub \
-x sysspectogram-agent-x86_64-linux-musl.minisig
scripts/verify-release.sh SysSpectogram.minisign.pub \
sysspectogram-agent-x86_64-linux-musl \
sysspectogram-agent-x86_64-linux-musl.sha256Verify model artifacts
python -m sysspectogram supply-chain verify artifacts/real_v3 \
--enforce --public-key /etc/sysspectogram/sysspectogram.minisign.pub--insecure remains available for explicit local profile installation only;
it is not a production trust mode.
Build and package
Builder:
python -m build
python scripts/generate-sbom.py --out dist/sbom.spdx.json
cd agent && cargo build --release --locked --no-default-featuresArch:
cd packaging/aur
makepkg -siDebian/Ubuntu:
dpkg-buildpackage -us -uc -b -dThe packaged agent defaults to userspace mode. eBPF requires a compatible
kernel and the documented capabilities; it is not silently assumed.
Upgrade
git fetch --tags
git checkout v0.8.0
python -m venv .venv
source .venv/bin/activate
pip install -e '.[onnx]'
cd agent && cargo build --release --locked
cd ..
python -m sysspectogram configureKeep response.mode: observe and kirk.auto_isolate: false during the first
upgrade, verify the public key and model signature, then restart the services.
Security notes
iforest.joblib and scaler.joblib remain legacy pickle-compatible files.
They are accepted only after manifest verification when enforcement is enabled.
Prefer ONNX inference on small VPS hosts and generate model artifacts on a
trusted builder. See SUPPLY_CHAIN.md and SECURITY.md.
Known ceiling
kirk.trust: best-effort remains honest on hosts without IMA plus measured
boot evidence. Live VMI is still conditional v1.0 functionality for self-hosted
KVM and is not part of this release.
v0.7.1 — module_hide FP + Ignore mute
SysSpectogram v0.7.1 — module_hide FP + Ignore mute
Fixes
agent_kirk_module_hidefalse positive:/sys/modulelists kernel builtins (acpi, 8250, …) that never appear in/proc/modules. Cross-view now only compares loadable modules (those with/sys/module/*/initstate), so builtin noise no longer floods Telegram.- Ignore button for kirk/host alerts: clicking Ignore on an alert without a process identity used to ack
"ignored"without storing anything. It now mutes byrule_id(persisted instate/process_labels.json), and the guard skips muted rules.
Upgrade
git pull
pip install -e '.[onnx]' # or your usual install
cd agent && cargo build --release
# restart agent + guardIf spam already started, either Ignore once more (now persists) or:
python -c "
from sysspectogram.process_labels import ProcessLabelStore
from pathlib import Path
s = ProcessLabelStore(Path('state/process_labels.json'))
s.mute_rule('agent_kirk_module_hide', note='builtin-fp')
print('muted')
"v0.7.0 — Deeper ops on the VPS
SysSpectogram v0.7.0 — Deeper ops on the VPS
Release after v0.6 agent harden: Day-0 configure, quieter false positives via
ProcessLabelRules, richer digests/audit, cheaper flow, optional IF refit —
without forcing CNN fine-tune on a 1 GB box.
Why it matters
| Before (v0.6) | Now (v0.7) |
|---|---|
Day-0 = edit YAML + thin setup for .env |
configure TUI + host_probe recommendations; overrides need confirm |
| As normal / As anomaly = bias + vague retrain | ProcessLabelRules (exact / prefix / glob / …) + /labels; role FP seeds |
| Full CNN retrain expected somehow on VPS | Rules first; optional IF-only refit; CNN stays builder-only |
Flow = /proc/net/tcp only |
netview (ss) + /proc fallback on full profile |
| Destructive TG actions hard to audit | reports/response_audit.jsonl |
| Kirk trust only in console/TG | Web kirk badge on live dashboard |
| Root = ProcWatcher poll | + eBPF setuid→0 assist (agent_ebpf_setuid_root); ProcWatcher remains fallback |
| Cold install tribal knowledge | COLD_INSTALL.md checklist |
Honest limits: labels do not replace a good host model; IF refit is opt-in and still not a full detector rewrite; eBPF setuid needs root/CAP_BPF and quiet hosts (desktop flood remains a reason to prefer userspace). Trust stays best-effort without IMA+SB/TPM.
What's new
Configure (killer Day-0)
python -m sysspectogram configure— Rich terminal UI (not a browser)host_probe: RAM / vCPU / container / desktop / onnx|torch → recommendlite/full, agent, flow,runtime.prefer, feedback knobs- Changing away from recommendation shows a warning +
y/N --accept-recommended --role sshfor scripted / cold VPS- Writes deep-merged
configs/default.yaml,.env,state/host_probe.json - Optional role FP seed into
state/process_labels.json
Docs: CONFIGURE.md · COLD_INSTALL.md
ProcessLabelRules + feedback loop
- Store:
state/process_labels.json(v2). Legacyoperator_feedback.jsonmigrates. - Match:
exact,comm_prefix,comm_regex,path_glob,path_contains,cmdline_contains - Priority: anomaly > ignore > baseline
- TG: As normal / As anomaly / + similar,
/labels,/label-del - CLI:
labels list|seed|del - Role seeds: ssh / nginx / docker / panel / python / wireguard (role_fp)
- Global threshold bias via
FeedbackLearnerkept - Optional:
feedback.if_refit: true→ debounced / CLIfeedback retrain-if(CNN/ONNX untouched) - Builder full retrain:
feedback retrain(Torch) unchanged
Docs: FEEDBACK.md · TELEGRAM.md
Flow / netview (Track B)
flow:
enabled: true # full preset
backend: netview # proc | netview | both
window_sec: 30
syn_threshold: 80
unique_port_threshold: 40Lite keeps flow off / proc by default.
Response UX (Track C)
- Append-only
reports/response_audit.jsonl(no secrets in payload) - Lockdown / isolate still go through unlock + confirm tokens
- Live web: kirk trust badge + isolated flag (web static)
eBPF setuid assist (Track E)
- Probes:
setuid/setreuid/setresuidtoward uid 0 from non-root - Alert id:
agent_ebpf_setuid_root - Lite / no-eBPF: ProcWatcher
root_watchstill authoritative
Docs: EBPF_SETUP.md · ROOT_WATCH.md
Digests / ops polish (Track A)
/digestincludes alerts_today, response_mode, kirk trust, feedback bias/counts, label count, last IF refit- Version bump: package + agent 0.7.0
Quick start
pip install -e ".[onnx]" # or .[dev] / .[ml] on builder
cd agent && cargo build --release && cd ..
python -m sysspectogram configure --accept-recommended --role ssh
# or interactive:
# python -m sysspectogram configure
python -m sysspectogram guard --model artifacts/real_v3 --telegram --dry-run
# console prints UNLOCK CODE → TG: /unlock NNNNNN
# /labels /digest As normal / + similarOptional IF refit (after enough labeled windows):
python -m sysspectogram feedback retrain-if --model artifacts/real_v3Config knobs (new / important)
load_profile: lite # or full — configure / probe picks this
runtime:
prefer: notorch # torch only if probe says so
agent:
enabled: true
auto_start: true
mode: userspace # ebpf on quiet VPS with root
root_watch: true
flow:
enabled: false
backend: proc # netview on full
feedback:
if_refit: false
widen_rules: comm_prefix # false | comm_prefix | path_glob | both
response:
mode: observe
telegram:
require_console_unlock: trueDocs
- CONFIGURE.md · COLD_INSTALL.md · FEEDBACK.md
- ROADMAP_QUALITY.md — v0.7 shipping; next v0.8 supply chain
- RELEASE_v0.6.0.md — prior agent harden release
- README EN/RU updated for configure Day-0
Upgrade notes
pip install -e '.[onnx]'(or reinstall) —__version__→ 0.7.0.- Rebuild agent (
cargo build --release) for setuid probes + prior root_watch. - Run
configureonce (or merge YAML knobs above by hand). - Old
state/operator_feedback.json→ labels migrate on first guard/labels load. - Prefer
agent.mode: userspaceon desktop;ebpfon quiet VPS as root. - Keep
--dry-run/response.mode: observeuntil unlock + labels are trusted. - Do not expect CNN fine-tune on 1 GB VPS — use labels + optional IF; full retrain on a builder PC.
Not in 0.7
- CNN fine-tune on VPS / Rust CNN training
- minisign / cosign / SBOM (v0.8)
- Live VMI (v1.0)
v0.6.0 — Harden the agent path
SysSpectogram v0.6.0 — Harden the agent path
Release after v0.5 Adopt/Kirk: make the same-UID / lite VPS path honest and usable —
auth, self-protect, unexpected root in Rust, Role Lab packs, operator feedback.
Why it matters
| Before (v0.5) | Now (v0.6) |
|---|---|
| Critical kirk alerts forgeable on same UDS | HMAC + PEERCRED fail-closed + PID allowlist + exe seal |
| Agent death can go quiet | Phoenix watchdog, CLEAN_SHUTDOWN, Dead-man, TG bypass |
Root process watch = Python /proc (heavy on lite) |
Rust ProcWatcher same walk → agent_unexpected_root + TG Kill |
| Unexpected SSH soft | Learn window → Kick tty / Ban IP |
| Packs unsigned locally | HMAC .sig + validate-pack |
| Retrain feedback vague | TG Ignore / As normal / As anomaly → learner (+ retrain CLI) |
| Role baselines hard without VMs | Role Lab collect/train/pack on a PC |
Honest limits: cannot revoke uid=0 without Kill; root can still replace a poorly installed binary — install under root-owned /usr/local/sbin. Cloud IMA/SB often absent → trust stays best-effort.
What's new
Agent auth and seal
- HMAC-SHA256 for critical rules (
state/agent_hmac.secret) - Same-UID PEERCRED fail-closed; refresh allowlist from agent + watchdog PIDs
- Binary seal (
state/agent_binary.seal.json); mismatch → loud alert
Docs: AGENT_PROTECT.md · SECURITY.md
Unexpected root (lite-safe)
agent.root_watch: true(default) — detection in agent, no second/procwalk- Python
root_watchonly ifagent.enabled: false - Rule:
agent_unexpected_root(HMAC required)
Docs: ROOT_WATCH.md
Sessions, Role Lab, feedback, OSINT
CI / packaging
- GitHub Actions pytest + agent checks; release-assets workflow
packaging/sysspectogram-agent.service
Quick start
pip install -e ".[dev]"
cd agent && cargo build --release && cd ..
python -m sysspectogram kirk trust
python -m sysspectogram guard --telegram --dry-run
# console unlock code → TG /unlock NNNNNNAgent (root, optional eBPF):
sudo install -m 0755 -o root -g root \
agent/target/release/sysspectogram-agent /usr/local/sbin/sysspectogram-agent
sudo /usr/local/sbin/sysspectogram-agent --mode ebpf --phoenix \
--socket /run/sysspectogram/agent.sock \
--hmac-secret /opt/sysspectogram/state/agent_hmac.secretConfig knobs (new / important)
agent:
enabled: true
require_hmac: true
require_same_uid: true
root_watch: true
root_learn_sec: 300
root_watch:
enabled: false # Python fallback only without agent
sessions:
enabled: true
learn_sec: 120Docs
- ROADMAP_QUALITY.md — forward plan (v0.7+)
- AGENT.md · KIRK.md · TRUST.md
- RELEASE_v0.5.0.md — prior Adopt/Kirk release
Upgrade notes
- Rebuild agent (
cargo build --release) — root watch + HMAC live in the binary. - Ensure
state/agent_hmac.secretshared by guard and agent. - Prefer systemd unit under
/usr/local/sbin(AGENT_PROTECT.md). - Keep
kirk.auto_isolate: falseuntilallow_ssh_cidrsis set.
SysSpectogram v0.5.0 — VPS Adopt + Kirk trust
SysSpectogram v0.5.0 — VPS Adopt + Kirk trust
Biggest release since v0.4: turn a hybrid ML host IDS into practical VPS defense you can run on a cheap box without PyTorch, with honest kernel-integrity labels and safer response actions.
Why it matters
| Before (v0.4) | Now (v0.5) |
|---|---|
| Torch often blocked 1GB VPS | runtime: notorch / onnx — day-0 without CNN, or light ONNX |
| Retrain pain on the server | Train bridge: collect on VPS → train on PC → artifacts push back |
| “Rootkit” ≈ heuristics | Kirk: module eBPF, cross-view hide, kallsyms presence baseline |
| Unclear trust | kirk.trust: best-effort | measured (IMA + Secure Boot/TPM) — no hype |
| IP bans only | kirk_isolate / kirk_release with TTL; TG /kirk_release (unlock-gated) |
| Flat auto-ban | response.mode: observe → shield → aggressive |
Honest ceiling: many Arch/cloud hosts have no IMA in-kernel and Secure Boot off → trust stays best-effort. That is correct. Live VMI (hypervisor) is deferred to v1.0.
What's new
VPS Adopt
runtime: notorch | onnx | torch_ml(SYSSPECTOGRAM_RUNTIME)- ONNX export/infer; train bridge (
data bundle/artifacts pushwith checksum verify) - Setup/bootstrap helpers
Kirk (in-guest integrity)
- eBPF execve/openat/module; cross-view hide;
--kirk-sealpresence baseline python -m sysspectogram kirk trust(+ reason codes)- Docs: KIRK.md · VMI.md (VMI → v1.0)
Response & safety
- nft
ss_kirkisolate + TTL; refuse emptyallow_ssh_cidrs auto_isolateallowlisted CRITICAL only (default off)- Hardened push paths; no false
measuredon unreadable IMA
Quick start
pip install -e ".[dev]"
cd agent && cargo build --release && cd ..
python -m sysspectogram kirk trust
python -m sysspectogram guard --telegram --dry-run
# ONNX
SYSSPECTOGRAM_RUNTIME=onnx python -m sysspectogram guard \
--model artifacts/real_v3 --telegram --dry-run
# eBPF agent (root)
sudo -E ./agent/target/release/sysspectogram-agent \
--mode ebpf --socket "$XDG_RUNTIME_DIR/sysspectogram-agent.sock"Profile pack
sha256: a8402315fec15ed9dd602f78dcbb8b59c680768d7f904e46175dd22d3abb20b4
python -m sysspectogram profiles pull \
--url https://github.com/lifeqsoll/SysSpectogram/releases/download/v0.5.0/profile-generic-linux-v1.tar.gz \
--out /tmp/p.tar.gz \
--sha256 a8402315fec15ed9dd602f78dcbb8b59c680768d7f904e46175dd22d3abb20b4
python -m sysspectogram profiles install /tmp/p.tar.gz \
--dest artifacts/profiles/generic-linux \
--sha256 a8402315fec15ed9dd602f78dcbb8b59c680768d7f904e46175dd22d3abb20b4Docs
Notes
- Default runtime is notorch (host CNN off until onnx/torch_ml +
--model). - Do not enable
kirk.auto_isolatewithoutallow_ssh_cidrs. - Seal kallsyms as the same user that runs the agent.
v0.4.0
SysSpectogram v0.4.0
Linux hybrid host IDS: CNN + Isolation Forest, perimeter/Telegram SOAR-lite, live web / Mini App, and a Rust integrity agent.
What's new
- Fuse
risk— host ML + agent IF (ensemble.host_weight/agent_weight) - Profile packs — shareable
tar.gzbaselines (profiles pack/pull/install) - Load budgets —
lite(small VPS) /full(large VDS); envSYSSPECTOGRAM_LOAD_PROFILE - FIM — optional sha256 path watches (
full) - Flow lite —
/proc/net/tcpheuristic (full) - Console unlock — TG
/unlock+ Mini App gate (stolen.envalone cannot kill/ban) - eBPF — optional
execve/openatvia clang BPF + Aya loader (attach needs root; on Archsetcapalone is not enough)
Assets
| File | Purpose |
|---|---|
profile-generic-linux-v1.tar.gz |
Baseline host + agent-IF pack |
profile-generic-linux-v1.tar.gz.sha256 |
Integrity check (required by profiles pull/install) |
python -m sysspectogram profiles pull \
--url https://github.com/lifeqsoll/SysSpectogram/releases/download/v0.4.0/profile-generic-linux-v1.tar.gz \
--out /tmp/p.tar.gz \
--sha256 a8402315fec15ed9dd602f78dcbb8b59c680768d7f904e46175dd22d3abb20b4
python -m sysspectogram profiles install /tmp/p.tar.gz \
--dest artifacts/profiles/generic-linux \
--sha256 a8402315fec15ed9dd602f78dcbb8b59c680768d7f904e46175dd22d3abb20b4Quick start
pip install -e ".[dev]"
cd agent && cargo build --release && cd ..
python -m sysspectogram guard --model artifacts/real_v3 --telegram --dry-run
# eBPF agent:
# sudo -E ./agent/target/release/sysspectogram-agent --mode ebpf --socket "$XDG_RUNTIME_DIR/sysspectogram-agent.sock"Docs
SysSpectogram v0.2.0 - hybrid host ML + perimeter + Telegram
Tag: v0.2.0
Title: SysSpectogram v0.2.0 — hybrid host ML + perimeter + Telegram
--- paste below into GitHub Release description ---
SysSpectogram v0.2.0
First public release of a Linux hybrid IDS: host behavioral ML (CNN + Isolation Forest) plus perimeter/egress guard and a Telegram SOAR-lite control plane.
Repo: https://github.com/lifeqsoll/SysSpectogram
Highlights
- Host pipeline:
collect→build-dataset→train→monitor/analyze - Perimeter: SSH auth fail/brute, inbound scan heuristics, egress denylist, suspicious DNS
guard: perimeter + host ML + Telegram slash/inline (confirm before ban/kill/lockdown)- Dual alert panel (metrics heatmap + top-PID CPU)
- OSINT recon (PTR/enrich/DNS/CT); nmap only via lab allowlist
- Local load sims + intrusion lab scripts (localhost only)
- Safer defaults: recon/nmap off, TG simulate/collect off, nft unban by handle, temporal val split, artifact checksums, webhook HMAC
Install
git clone https://github.com/lifeqsoll/SysSpectogram.git
cd SysSpectogram
python -m venv .venv && source .venv/bin/activate
pip install torch --index-url https://download.pytorch.org/whl/cpu
pip install -e ".[dev]"
cp .env.example .env # optional TelegramQuick start
# train your own artifacts (not shipped)
python -m sysspectogram collect --out data/normal.csv --duration 1800
# …sim + anomaly collect…
python -m sysspectogram build-dataset --normal data/normal.csv --anomaly data/anomaly.csv --out dataset/real
python -m sysspectogram train --dataset dataset/real --out artifacts/real
# live (dry-run safe)
python -m sysspectogram guard --model artifacts/real --telegram --dry-runDocs
Safety
- Linux only. No Win/Mac.
- Destructive TG actions require confirm; ban/kill need real privileges (omit
--dry-run). - Do not aim sims/nmap at third-party networks.
- Model quality = your labeled data; no pretrained weights in the repo.
Known limitations
- Live nft without dry-run needs suitable privileges/systemd caps
- Retrain to get
checksums.sha256on artifacts - Not antivirus / full NIDS / SIEM