Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis
Semantic Observability for UNIX Systems
A lightweight, portable system prober written in C that captures "system fingerprints" for AI-assisted analysis of non-obvious risks. Features auditd integration, explainable risk scoring, and a live web dashboard with enterprise-grade multi-user authentication.
Live Demo: sentinel.speytech.com



| Setup | Login |
|---|---|
![]() | ![]() |




v0.5.x: Security posture summary, risk trend sparkline, learning indicator, explainable risk factors, email alerts, event history
v0.4.0: Auditd integration, brute force detection, privacy-preserving username hashing, process attribution, risk scoring
v0.3.0: Web Dashboard, SHA256 checksums, systemd service, baseline learning, network probe, watch mode
Modern observability tools like Dynatrace, Datadog, and Prometheus are excellent at metric collection and threshold alerting. But they answer a narrow question: "Is this metric outside its expected range?"
They struggle with:
C-Sentinel takes a different approach: capture a comprehensive system fingerprintβincluding security eventsβand use LLM reasoning to identify the "ghosts in the machine."
# Clone and build
git clone https://github.com/williamofai/c-sentinel.git
cd c-sentinel
make
# Quick analysis
./bin/sentinel --quick --network
# Quick analysis with security events (requires root for audit logs)
sudo ./bin/sentinel --quick --network --audit
# Learn baselines (automatic with --audit flag)
./bin/sentinel --learn --network
# Continuous monitoring with full context
sudo ./bin/sentinel --watch --interval 300 --network --audit
The web dashboard provides real-time security monitoring across your infrastructure.
Enterprise-grade access control with three roles:
| Role | Permissions |
|---|---|
| Admin | Full access: manage users, view audit logs, all operations |
| Operator | Acknowledge events, reset counters, view all data |
| Viewer | Read-only access to dashboards and data |
Secure your account with industry-standard TOTP:
Each user can create their own API keys for automation:
# Use your personal API key
curl -X POST https://sentinel.example.com/api/ingest \
-H "Content-Type: application/json" \
-H "X-API-Key: sk_your_personal_key" \
-d @fingerprint.json
Track all user actions for compliance and security:
Full visibility into active sessions:
Plain English explanation of your system's security status:
"This system shows no security concerns. Authentication patterns are normal with no failures detected. No privilege escalation activity detected. Overall posture: HEALTHY."
Every risk score includes factors that explain why:
| Factor | Weight |
|---|---|
| 10 authentication failures (200% above baseline - high) | +30 |
| Brute force attack pattern detected | +10 |
| 2 sensitive file(s) accessed | +4 |
| Total | 44 |
The system learns what's "normal" for your environment:
| Samples | Status | Meaning |
|---|---|---|
| < 10 | π§ Learning | Building initial baseline |
| 10-50 | π§ Calibrating | Refining normal patterns |
| > 50 | (hidden) | Fully calibrated |
A mini chart showing 24-hour risk score history - instantly see if things are getting better or worse.
Automatic notifications via email and/or Slack when:
Slack alerts include rich formatting with colour-coded severity, clickable dashboard links, and structured risk factor details.
C-Sentinel summarises auditd logs for semantic security analysis.
C-Sentinel Quick Analysis
========================
Hostname: axioma-validator
Uptime: 14.5 days
Load: 0.02 0.04 0.00
Memory: 49.2% used
Processes: 120 total
Potential Issues:
Zombie processes: 0
High FD processes: 1
Long-running (>7d): 95
Config permission issues: 0
Network:
Listening ports: 26
Established connections: 14
Unusual ports: 12 β