File-integrity monitor · Rust · SHA-256

SIGIL
WARD

Seal your file state. Catch the moment the seal breaks.

A sigil is a mark that attests nothing has been tampered with. SigilWard baselines every watched file — hash, mode, owner, size — then tells you exactly what changed, not just that something did. Same category as AIDE and Tripwire; written in Rust.

◆ SHA-256◆ SYSTEMD TIMER◆ NO ROOT NEEDED*◆ MIT

01 / Verdicts

Four ways a seal
can break.

sigilward check walks every watched path, compares it to the sealed baseline, and reports each change separately — a chmod alone shows as a permissions change, never a false content change. Any drift exits non-zero, made for timers and alerting.

[NEW]

A file exists now that wasn't in the baseline.

[DELETED]

A baselined file is gone.

[MODIFIED]

Content, permissions or ownership changed — each reported as its own reason.

[UNREADABLE]

It exists but couldn't be read to verify. Never mistaken for a deletion — and never a silent pass.

● ● ●   blackbox / sigilward-check.serviceLIVE
❯ sigilward checksigilward: walking 17 watch entries…[NEW]     /etc/systemd/system/backdoor.service[MODIFIED] /etc/ssh/sshd_config (content)[MODIFIED] /usr/local/bin/argus (content, permissions)[DELETED] /etc/sudoers.d/90-ops 4 change(s) from baseline.exit 1 — review, then `sigilward update` to re-seal

02 / How it works

Walk. Hash.
Seal. Compare.

A point-in-time baseline/compare tool — the AIDE/Tripwire operating model. For change detection the moment it happens, pair it with Argus, which watches the same paths live against the same baseline.

WALK

Every [[watch]] path from the TOML config, recursively. Symlinks are recorded by their own metadata — never followed out of the tree.

HASH

SHA-256 of content plus mode, uid, gid and size for each file.

SEAL

init writes the trusted baseline JSON. update re-seals after you've reviewed a change.

COMPARE

check diffs live state against the seal: new, deleted, modified, unreadable.

◆ LEAST PRIVILEGE

READ ALL, OWN NOTHING

Run as your user with one capability, CAP_DAC_READ_SEARCH: it can read /etc/shadow and /etc/sudoers without being root, and the baseline stays yours.

◆ HONEST REPORTS

NO FALSE ALARMS

A permission-denied file is [UNREADABLE], not [DELETED] — the classic integrity-tool false alarm, fixed.

◆ CYBERCORE

THEMED OUTPUT

Reports render in the shared CYBERGRID palette, or plain with --no-color for logs and timers.

03 / Setup

Seal it
in minutes.

Build from source, point it at the files that matter, seal, and let a daily systemd timer do the watching. Install the binary root-owned — a tool with read-everything powers must not be swappable by your user.

BUILD + INSTALL
git clone https://github.com/cybercore-tech/sigilward
cd sigilward && cargo build --release
sudo install -m 755 target/release/sigilward /usr/local/bin/

sigilward init     # walk + write the baseline
sigilward check    # compare, non-zero exit on drift
sigilward update   # re-seal after review
~/.config/sigilward/config.toml
baseline_path = "~/.local/state/sigilward/baseline.json"

[[watch]]
path = "/etc/systemd/system"

[[watch]]
path = "/etc/ssh"

[[watch]]
path = "/etc/sudoers"

[[watch]]   # absent today — [NEW] if it ever appears
path = "/etc/ld.so.preload"
/etc/systemd/system/sigilward-check.service
[Service]
Type=oneshot
User=youruser
ExecStart=/usr/local/bin/sigilward check --no-color
AmbientCapabilities=CAP_DAC_READ_SEARCH
CapabilityBoundingSet=CAP_DAC_READ_SEARCH
NoNewPrivileges=true
ProtectSystem=strict
ProtectHome=read-only
ReadWritePaths=/home/youruser/.local/state/sigilward
/etc/systemd/system/sigilward-check.timer
[Timer]
OnCalendar=daily
Persistent=true
RandomizedDelaySec=15min

[Install]
WantedBy=timers.target
  • Known limit: point-in-time, not continuous — use Argus for live watching.
  • Trust anchor: the baseline is protected by file permissions only; keep it 600.

04 / Theme matrix

Pick your
signal.

Every Cybercore palette from the shared schema, grouped by family — plus SigilWard's own signature mashups, blending one palette's surfaces with another's neons. Your choice follows you across Cybercore sites.

NOW RUNNING · …
…
dev@cybercoretech.net