Real-time file integrity · Rust · inotify
ARGUS
SEES IT.
The hundred-eyed watchman for your most sensitive files — change detected the instant it happens.
SigilWard seals a baseline and checks it daily. Argus is the live half: it watches the exact same paths, classifies every real write against the same baseline, logs it, and pings your desktop. Reads never trigger it — only actual changes do.
01 / Live watch
Writes, not reads.
Signal, not noise.
notify + notify-debouncer-full watch every path in SigilWard's config. A pure read — sudo opening /etc/sudoers on every call, anything polling unit files — is filtered out before it's ever re-hashed. Only real writes are classified and logged.
argus: watching /etc/systemd/system (recursive)argus: watching /etc/ssh (recursive)argus: watching /usr/local/bin (recursive)argus: daemon running, 16 watch root(s) 19:42:07 MODIFIED /home/you/.ssh/authorized_keys (content)19:42:07 notify-watch: 1 new event(s), notifying19:58:31 NEW /etc/systemd/system/backdoor.service
ONE SOURCE OF TRUTH
Every change is judged against SigilWard's own sealed baseline — the daily check and the live watch never disagree.
ACCEPT, SURGICALLY
argus opens the event log; accept one reviewed change straight into the baseline with a key — no blanket re-seal of everything else.
JSON ON TAP
argus events --since <RFC3339> dumps the log as JSON for your own tooling.
02 / Design
Two processes.
Least privilege.
A root service can't reliably reach your desktop session, and a desktop process shouldn't be root. So Argus splits the job — and neither half gets more power than it needs.
argus daemon
Watches and logs. Read access via CAP_DAC_READ_SEARCH, everything else read-only; writes only its own event log. Never notifies.
Runs a root-owned binary from /usr/local/bin — a root service must never execute a file your user can swap.
argus notify-watch
Tails the event log inside your real session and fires desktop toasts. No privileges at all.
Only new events notify — a restart never re-spams what's already in the log.
03 / Setup
Open
the eyes.
Set up SigilWard first — Argus reads its config and baseline. Then install the privileged watcher and your notifier.
git clone https://github.com/cybercore-tech/argus
cd argus && cargo build --release
sudo install -m 755 target/release/argus /usr/local/bin/argus
install -m 755 target/release/argus ~/.local/bin/argus
mkdir -p ~/.local/state/argus # required before first start
sudo install -m 644 argus.service /etc/systemd/system/
sudo systemctl enable --now argus.service
install -m 644 argus-notify.service ~/.config/systemd/user/
systemctl --user enable --now argus-notify.serviceargus # TUI event viewer + accept
argus daemon # watch loop (argus.service)
argus notify-watch # desktop toasts (user unit)
argus events --since 2026-10-01T00:00:00Z
- Watches what SigilWard watches: add paths in
~/.config/sigilward/config.toml. - Missing paths (e.g. an absent
/etc/ld.so.preload) can't be watched live — SigilWard's daily check still catches them appearing.
04 / Theme matrix
Change
the lens.
Every Cybercore palette from the shared schema, grouped by family — plus Argus's own signature mashups. Your pick follows you across Cybercore sites.