Skip to content

Operate

Everything about running the sensor rather than understanding what it detects.

The shortest useful loop

# Is this host able to see what I think it can?
python3 -m shadowclaw --self-test

# Run bounded, so it stops on its own
sudo ./scripts/run-sensor.sh --esf --dns-sniffer --duration 300

# Read what it found
python3 -m shadowclaw --ledger --since 10m

# Confirm nothing edited the record
python3 -m shadowclaw --ledger verify

Operating principles worth knowing before you deploy

Nothing resolves against the working directory. Config and findings paths are anchored to the package, to /etc, or to the ledger directory. Starting the sensor from a different shell used to mean the policy silently vanished and findings scattered into whatever scratch directory happened to be current.

A config named by hand must exist. --config and $SHADOWCLAW_CONFIG are treated as explicit requests, so a missing file is fatal rather than a silent fall back to built-in defaults.

The ledger is written before export. A collector or Splunk outage can never cost you a finding.

Degraded coverage is stated in the banner. A sensor that could not look never reports a clean host.

There is no allowlist. min_risk_to_report is a uniform threshold; sanctioned_endpoints is a label. Neither can be aimed at a specific process or vendor.