Real-time file integrity · Rust · inotify

ARGUS
SEES IT.

The hundred-eyed watchman for your most sensitive files — change detected the instant it happens.

SigilWard seals a baseline and checks it daily. Argus is the live half: it watches the exact same paths, classifies every real write against the same baseline, logs it, and pings your desktop. Reads never trigger it — only actual changes do.

◆ INOTIFY◆ SIGILWARD BASELINE◆ DESKTOP ALERTS◆ MIT

01 / Live watch

Writes, not reads.
Signal, not noise.

notify + notify-debouncer-full watch every path in SigilWard's config. A pure read — sudo opening /etc/sudoers on every call, anything polling unit files — is filtered out before it's ever re-hashed. Only real writes are classified and logged.

● ● ●   journalctl -u argus -fWATCHING
argus: watching /etc/systemd/system (recursive)argus: watching /etc/ssh (recursive)argus: watching /usr/local/bin (recursive)argus: daemon running, 16 watch root(s) 19:42:07 MODIFIED /home/you/.ssh/authorized_keys (content)19:42:07 notify-watch: 1 new event(s), notifying19:58:31 NEW      /etc/systemd/system/backdoor.service
◆ SAME BASELINE

ONE SOURCE OF TRUTH

Every change is judged against SigilWard's own sealed baseline — the daily check and the live watch never disagree.

◆ REVIEW TUI

ACCEPT, SURGICALLY

argus opens the event log; accept one reviewed change straight into the baseline with a key — no blanket re-seal of everything else.

◆ SCRIPTABLE

JSON ON TAP

argus events --since <RFC3339> dumps the log as JSON for your own tooling.

02 / Design

Two processes.
Least privilege.

A root service can't reliably reach your desktop session, and a desktop process shouldn't be root. So Argus splits the job — and neither half gets more power than it needs.

ROOT · SYSTEM SERVICE

argus daemon

Watches and logs. Read access via CAP_DAC_READ_SEARCH, everything else read-only; writes only its own event log. Never notifies.

Runs a root-owned binary from /usr/local/bin — a root service must never execute a file your user can swap.

YOU · USER SERVICE

argus notify-watch

Tails the event log inside your real session and fires desktop toasts. No privileges at all.

Only new events notify — a restart never re-spams what's already in the log.

03 / Setup

Open
the eyes.

Set up SigilWard first — Argus reads its config and baseline. Then install the privileged watcher and your notifier.

BUILD + INSTALL
git clone https://github.com/cybercore-tech/argus
cd argus && cargo build --release
sudo install -m 755 target/release/argus /usr/local/bin/argus
install -m 755 target/release/argus ~/.local/bin/argus
mkdir -p ~/.local/state/argus     # required before first start

sudo install -m 644 argus.service /etc/systemd/system/
sudo systemctl enable --now argus.service
install -m 644 argus-notify.service ~/.config/systemd/user/
systemctl --user enable --now argus-notify.service
USAGE
argus                 # TUI event viewer + accept
argus daemon          # watch loop (argus.service)
argus notify-watch    # desktop toasts (user unit)
argus events --since 2026-10-01T00:00:00Z
  • Watches what SigilWard watches: add paths in ~/.config/sigilward/config.toml.
  • Missing paths (e.g. an absent /etc/ld.so.preload) can't be watched live — SigilWard's daily check still catches them appearing.

04 / Theme matrix

Change
the lens.

Every Cybercore palette from the shared schema, grouped by family — plus Argus's own signature mashups. Your pick follows you across Cybercore sites.

NOW RUNNING · …
…
dev@cybercoretech.net