Vulnerability Management v1.2.0

SentinelCore

Reconstruct any LAN as a living map. SentinelCore discovers every host via ARP-scan and nmap, draws them as a real-time topology graph, and correlates detected services against the CVE feed as they appear. A Rust backend does the scanning and scoring; a React console renders the graph, severity badges, and per-host remediation plans.

Capabilities

What ships in the box

Active discovery

ARP-scan sweeps the subnet, nmap fingerprints services and OS, hosts appear on the graph within seconds.

Live topology

Device nodes with domain-specific icons, thin connecting lines, and a status legend — pan, zoom, and edit links.

CVE correlation

Matches detected versions against a bundled offline CVE database. Refresh the feed manually in air-gapped sites.

Remediation plans

Per-host, ranked by severity, exportable as a work order for the operations team.

Minimum requirements

Operating system
Debian 13 · trixie / x86_64
CPU
4 vCPU · x86-64-v2
Memory
4 GB RAM · 8 GB for > 500 hosts
Disk
20 GB SSD · thin-provisioned
Network
1 NIC · L2 access to scan targets
Console
HTTPS :443 · self-signed by default, HTTP redirects
Downloads

Choose your format

Every artifact is GPG-signed and published with a detached SHA256 checksum. Verify before you install.

.tar.gz Debian install 16 MB
sentinelcore-v1.2.0-linux-x86_64.tar.gz
SHA2563f429fd95c4ff24b…8747b720
TargetDebian 12/13 · x86_64
.ova VirtualBox / VMware 678 MB
sentinelcore-v1.2.0-linux-x86_64.ova
SHA256b377e8af3e47c15c…2b569c2e
ApplianceDebian 13 · 20 GB · bridge NIC
ImportFile → Import Appliance
.qcow2 KVM / Proxmox 702 MB
sentinelcore-v1.2.0-linux-x86_64.qcow2
SHA256220fc031b69c4fe4…a858ab26
Formatqcow2 · virtio · Debian 13
Importqm importdisk / virt-manager
Documentation

Manuale utente

Guida completa in italiano — installazione, ruoli e permessi, configurazione, rete e asset, vulnerabilità e rischio, report e remediation.

Quick install

Choose your format

The installer handles all dependencies, the database, nginx (HTTPS with a self-signed certificate by default), and the systemd unit. You need a clean Debian 12 or 13 host and root access — nothing else.

1

Download the tarball and the checksum

Save both files in the same directory on the target server.

bash
wget https://dognet-technologies.online/downloads/sentinelcore-v1.2.0-linux-x86_64.tar.gz
wget https://dognet-technologies.online/downloads/sentinelcore-v1.2.0-linux-x86_64.tar.gz.sha256
2

Verify the checksum

The command should print sentinelcore-v1.2.0-linux-x86_64.tar.gz: OK. If it fails, re-download.

bash
sha256sum -c sentinelcore-v1.2.0-linux-x86_64.tar.gz.sha256
3

Extract the archive

bash
tar -xzf sentinelcore-v1.2.0-linux-x86_64.tar.gz
cd sentinelcore-v1.2.0-linux-x86_64
4

Run the installer as root

install.sh installs PostgreSQL, nginx, nmap, arp-scan, applies all migrations, generates a self-signed TLS certificate and configures nginx for HTTPS (HTTP redirects automatically), registers the systemd unit, starts the service, and creates the first admin user — automatically, with no prompts.

bash
sudo ./install.sh
5

Read the credentials printed at the end

When install.sh finishes it prints the console URL and the generated admin password. Copy the password before closing the terminal — it is not stored anywhere.

example output
   URL:        https://192.168.1.10
   Admin:      admin  /  Xk7mR9qP2vAa1!
   ⚠️  CAMBIA questa password al primo accesso.
6

Open the console and change the password

Navigate to https://<server-ip> in a browser on the same network — the browser will warn about the self-signed certificate, this is expected for LAN use. Log in with admin and the generated password, then go to Settings → Profile and set a permanent password.

bash — verify service is running
sudo systemctl status sentinelcore
Upgrading

Already running SentinelCore?

Every release ships an in-place upgrade script that backs up your database with pg_dump, swaps the binary and frontend, applies any pending schema changes, and restarts the service — no data loss, no reinstall. It works the same way regardless of how your current instance was installed: tar.gz, OVA, or qcow2 all converge to the same layout once running.

Covered versions

v1.0.1-beta → v1.2.0
Use the procedure below as-is · no extra steps
1

Download the new package and checksum

On the server or VM that already runs SentinelCore — this is not a fresh install.

bash
wget https://dognet-technologies.online/downloads/sentinelcore-v1.2.0-linux-x86_64.tar.gz
wget https://dognet-technologies.online/downloads/sentinelcore-v1.2.0-linux-x86_64.tar.gz.sha256
sha256sum -c sentinelcore-v1.2.0-linux-x86_64.tar.gz.sha256
2

Extract and run the upgrade script as root

upgrade.sh — not install.sh — detects the existing installation automatically.

bash
tar -xzf sentinelcore-v1.2.0-linux-x86_64.tar.gz
cd sentinelcore-v1.2.0-linux-x86_64
sudo ./upgrade.sh
3

What happens automatically

In order: database backup (pg_dump, saved locally for manual restore if ever needed), stop the service, back up the current binary and frontend, install the new ones, apply pending migrations, restart, and verify /api/health. If the migration step fails, the previous binary and frontend are restored and the service is restarted — the database itself is never modified until migrations are confirmed to succeed.

example output
Versione installata: 1.0.1-beta   →   Nuova: 1.2.0
✅ Migration applicate con successo (91 totali incorporate).
✅ Aggiornamento completato: 1.0.1-beta → 1.2.0
   Backup DB pre-upgrade: /opt/sentinelsuite/sentinelcore/backups/pre-upgrade-*.dump