File-integrity monitor · Rust · SHA-256
SIGIL
WARD
Seal your file state. Catch the moment the seal breaks.
A sigil is a mark that attests nothing has been tampered with. SigilWard baselines every watched file — hash, mode, owner, size — then tells you exactly what changed, not just that something did. Same category as AIDE and Tripwire; written in Rust.
01 / Verdicts
Four ways a seal
can break.
sigilward check walks every watched path, compares it to the sealed baseline, and reports each change separately — a chmod alone shows as a permissions change, never a false content change. Any drift exits non-zero, made for timers and alerting.
[NEW]A file exists now that wasn't in the baseline.
[DELETED]A baselined file is gone.
[MODIFIED]Content, permissions or ownership changed — each reported as its own reason.
[UNREADABLE]It exists but couldn't be read to verify. Never mistaken for a deletion — and never a silent pass.
❯ sigilward checksigilward: walking 17 watch entries…[NEW] /etc/systemd/system/backdoor.service[MODIFIED] /etc/ssh/sshd_config (content)[MODIFIED] /usr/local/bin/argus (content, permissions)[DELETED] /etc/sudoers.d/90-ops 4 change(s) from baseline.exit 1 — review, then `sigilward update` to re-seal
02 / How it works
Walk. Hash.
Seal. Compare.
A point-in-time baseline/compare tool — the AIDE/Tripwire operating model. For change detection the moment it happens, pair it with Argus, which watches the same paths live against the same baseline.
WALK
Every [[watch]] path from the TOML config, recursively. Symlinks are recorded by their own metadata — never followed out of the tree.
HASH
SHA-256 of content plus mode, uid, gid and size for each file.
SEAL
init writes the trusted baseline JSON. update re-seals after you've reviewed a change.
COMPARE
check diffs live state against the seal: new, deleted, modified, unreadable.
READ ALL, OWN NOTHING
Run as your user with one capability, CAP_DAC_READ_SEARCH: it can read /etc/shadow and /etc/sudoers without being root, and the baseline stays yours.
NO FALSE ALARMS
A permission-denied file is [UNREADABLE], not [DELETED] — the classic integrity-tool false alarm, fixed.
THEMED OUTPUT
Reports render in the shared CYBERGRID palette, or plain with --no-color for logs and timers.
03 / Setup
Seal it
in minutes.
Build from source, point it at the files that matter, seal, and let a daily systemd timer do the watching. Install the binary root-owned — a tool with read-everything powers must not be swappable by your user.
git clone https://github.com/cybercore-tech/sigilward
cd sigilward && cargo build --release
sudo install -m 755 target/release/sigilward /usr/local/bin/
sigilward init # walk + write the baseline
sigilward check # compare, non-zero exit on drift
sigilward update # re-seal after reviewbaseline_path = "~/.local/state/sigilward/baseline.json"
[[watch]]
path = "/etc/systemd/system"
[[watch]]
path = "/etc/ssh"
[[watch]]
path = "/etc/sudoers"
[[watch]] # absent today — [NEW] if it ever appears
path = "/etc/ld.so.preload"[Service]
Type=oneshot
User=youruser
ExecStart=/usr/local/bin/sigilward check --no-color
AmbientCapabilities=CAP_DAC_READ_SEARCH
CapabilityBoundingSet=CAP_DAC_READ_SEARCH
NoNewPrivileges=true
ProtectSystem=strict
ProtectHome=read-only
ReadWritePaths=/home/youruser/.local/state/sigilward[Timer]
OnCalendar=daily
Persistent=true
RandomizedDelaySec=15min
[Install]
WantedBy=timers.target
- Known limit: point-in-time, not continuous — use Argus for live watching.
- Trust anchor: the baseline is protected by file permissions only; keep it
600.
04 / Theme matrix
Pick your
signal.
Every Cybercore palette from the shared schema, grouped by family — plus SigilWard's own signature mashups, blending one palette's surfaces with another's neons. Your choice follows you across Cybercore sites.