Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
c-sentinel β€” Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis | Kitploit
Tools/GitHubGitHub/speytech/c-sentinel
Vulnerability AnalysisNetwork SecurityCloud SecurityDevSecOpsThreat IntelligenceAuthenticationIntrusion DetectionIncident ResponseAI SecurityAnomaly DetectionLog Analysis
728176 months agoReviewed by Kitploit
GitHub
speytech/c-sentinel

c-sentinel

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

View RepositoryWebsite

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

C-Sentinel

Semantic Observability for UNIX Systems

A lightweight, portable system prober written in C that captures "system fingerprints" for AI-assisted analysis of non-obvious risks. Features auditd integration, explainable risk scoring, and a live web dashboard with enterprise-grade multi-user authentication.

License: MIT Version

Live Demo: sentinel.speytech.com

Screenshots

Security Dashboard

Security Dashboard

Multi-Host Overview

Hosts Dashboard

User Profile & Security Settings

Profile Page

Two-Factor Authentication

SetupLogin
2FA Setup2FA Login

Personal API Keys

API Keys

Admin Features

Session Management

Sessions

Audit Log

Audit Log

Secure Login

Login Page

What's New in v0.6.0

  • πŸ‘₯ Multi-User Authentication - Role-based access control (Admin/Operator/Viewer)
  • πŸ” Two-Factor Authentication - TOTP support with Google Authenticator, Authy, etc.
  • πŸ”‘ Personal API Keys - Per-user API keys for automation and CI/CD
  • πŸ“‹ Admin Audit Log - Track all user actions with filtering
  • πŸ’» Session Management - View active sessions, revoke access, force logout
  • πŸ“§ Email & Slack Alerts - Proactive notifications with rich formatting
  • 🎨 Modern Toast Notifications - No more 1990s JavaScript alerts!
  • πŸ‘οΈ Public Demo Mode - Read-only access for showcasing your dashboard
  • πŸ“± Mobile Responsive - Full functionality on phones and tablets

Previous Releases

v0.5.x: Security posture summary, risk trend sparkline, learning indicator, explainable risk factors, email alerts, event history

v0.4.0: Auditd integration, brute force detection, privacy-preserving username hashing, process attribution, risk scoring

v0.3.0: Web Dashboard, SHA256 checksums, systemd service, baseline learning, network probe, watch mode

The Problem

Modern observability tools like Dynatrace, Datadog, and Prometheus are excellent at metric collection and threshold alerting. But they answer a narrow question: "Is this metric outside its expected range?"

They struggle with:

  • Causal reasoning: Why did something fail?
  • Context synthesis: Connecting a config change last week to today's latency spike
  • Non-obvious degradation: Things that aren't "broken" but are drifting toward failure
  • Security context: Understanding who accessed what and why it matters

C-Sentinel takes a different approach: capture a comprehensive system fingerprintβ€”including security eventsβ€”and use LLM reasoning to identify the "ghosts in the machine."

Quick Start

# Clone and build
git clone https://github.com/williamofai/c-sentinel.git
cd c-sentinel
make

# Quick analysis
./bin/sentinel --quick --network

# Quick analysis with security events (requires root for audit logs)
sudo ./bin/sentinel --quick --network --audit

# Learn baselines (automatic with --audit flag)
./bin/sentinel --learn --network

# Continuous monitoring with full context
sudo ./bin/sentinel --watch --interval 300 --network --audit

Dashboard Features

The web dashboard provides real-time security monitoring across your infrastructure.

Multi-User Authentication

Enterprise-grade access control with three roles:

RolePermissions
AdminFull access: manage users, view audit logs, all operations
OperatorAcknowledge events, reset counters, view all data
ViewerRead-only access to dashboards and data

Two-Factor Authentication (TOTP)

Secure your account with industry-standard TOTP:

  • Works with Google Authenticator, Authy, Microsoft Authenticator
  • QR code setup for easy configuration
  • Required on every login when enabled
  • Email notifications on enable/disable

Personal API Keys

Each user can create their own API keys for automation:

  • Named keys (e.g., "CI/CD Pipeline", "Monitoring Script")
  • Optional expiration dates
  • Enable/disable without deleting
  • Last-used tracking
  • Keys inherit user's role permissions
# Use your personal API key
curl -X POST https://sentinel.example.com/api/ingest \
  -H "Content-Type: application/json" \
  -H "X-API-Key: sk_your_personal_key" \
  -d @fingerprint.json

Admin Audit Log

Track all user actions for compliance and security:

  • Login/logout events with IP addresses
  • User management actions (create, update, delete)
  • Password changes
  • Session revocations
  • Filterable by user, action type, and time range

Session Management

Full visibility into active sessions:

  • See who's logged in and from where
  • Device and browser detection
  • Revoke individual sessions
  • "Logout all others" for security incidents
  • Automatic cleanup of expired sessions

Security Posture Summary

Plain English explanation of your system's security status:

"This system shows no security concerns. Authentication patterns are normal with no failures detected. No privilege escalation activity detected. Overall posture: HEALTHY."

Explainable Risk Scoring

Every risk score includes factors that explain why:

FactorWeight
10 authentication failures (200% above baseline - high)+30
Brute force attack pattern detected+10
2 sensitive file(s) accessed+4
Total44

Learning/Calibration Indicator

The system learns what's "normal" for your environment:

SamplesStatusMeaning
< 10🧠 LearningBuilding initial baseline
10-50🧠 CalibratingRefining normal patterns
> 50(hidden)Fully calibrated

Risk Trend Sparkline

A mini chart showing 24-hour risk score history - instantly see if things are getting better or worse.

Email & Slack Alerts

Automatic notifications via email and/or Slack when:

  • Risk score β‰₯ 16 (high/critical)
  • Brute force attack detected
  • Executions from /tmp or /dev/shm
  • User login from new IP
  • Password or 2FA changes

Slack alerts include rich formatting with colour-coded severity, clickable dashboard links, and structured risk factor details.

Auditd Integration

C-Sentinel summarises auditd logs for semantic security analysis.

Example Output

C-Sentinel Quick Analysis
========================
Hostname: axioma-validator
Uptime: 14.5 days
Load: 0.02 0.04 0.00
Memory: 49.2% used
Processes: 120 total

Potential Issues:
  Zombie processes: 0
  High FD processes: 1
  Long-running (>7d): 95
  Config permission issues: 0

Network:
  Listening ports: 26
  Established connections: 14
  Unusual ports: 12 ⚠
Download Tool