Operate¶
Everything about running the sensor rather than understanding what it detects.
CLI referenceEvery flag, the ledger sub-actions, the helper scripts, and the Make targets.
The local ledgerEpisodes, the hash chain, tamper evidence, retention, and reports.
Startup checksThree ways a sensor runs perfectly while producing the wrong answer.
VerificationThe synthetic detection matrix and the coordinated test scored against declared truth.
UninstallIncluding the changes ShadowClaw made inside other products — and why the ledger survives.
The shortest useful loop¶
# Is this host able to see what I think it can?
python3 -m shadowclaw --self-test
# Run bounded, so it stops on its own
sudo ./scripts/run-sensor.sh --esf --dns-sniffer --duration 300
# Read what it found
python3 -m shadowclaw --ledger --since 10m
# Confirm nothing edited the record
python3 -m shadowclaw --ledger verify
Operating principles worth knowing before you deploy¶
Nothing resolves against the working directory. Config and findings paths are anchored to the package, to /etc, or to the ledger directory. Starting the sensor from a different shell used to mean the policy silently vanished and findings scattered into whatever scratch directory happened to be current.
A config named by hand must exist. --config and $SHADOWCLAW_CONFIG are treated as explicit requests, so a missing file is fatal rather than a silent fall back to built-in defaults.
The ledger is written before export. A collector or Splunk outage can never cost you a finding.
Degraded coverage is stated in the banner. A sensor that could not look never reports a clean host.
There is no allowlist. min_risk_to_report is a uniform threshold; sanctioned_endpoints is a label. Neither can be aimed at a specific process or vendor.