SentinelCore
Reconstruct any LAN as a living map. SentinelCore discovers every host via ARP-scan and nmap, draws them as a real-time topology graph, and correlates detected services against the CVE feed as they appear. A Rust backend does the scanning and scoring; a React console renders the graph, severity badges, and per-host remediation plans.
What ships in the box
Active discovery
ARP-scan sweeps the subnet, nmap fingerprints services and OS, hosts appear on the graph within seconds.
Live topology
Device nodes with domain-specific icons, thin connecting lines, and a status legend — pan, zoom, and edit links.
CVE correlation
Matches detected versions against a bundled offline CVE database. Refresh the feed manually in air-gapped sites.
Remediation plans
Per-host, ranked by severity, exportable as a work order for the operations team.
Minimum requirements
- Operating system
- Debian 13 · trixie / x86_64
- CPU
- 4 vCPU · x86-64-v2
- Memory
- 4 GB RAM · 8 GB for > 500 hosts
- Disk
- 20 GB SSD · thin-provisioned
- Network
- 1 NIC · L2 access to scan targets
- Console
- HTTPS :443 · self-signed by default, HTTP redirects
Choose your format
Every artifact is GPG-signed and published with a detached SHA256 checksum. Verify before you install.
Manuale utente
Guida completa in italiano — installazione, ruoli e permessi, configurazione, rete e asset, vulnerabilità e rischio, report e remediation.
Choose your format
The installer handles all dependencies, the database, nginx (HTTPS with a self-signed certificate by default), and the systemd unit. You need a clean Debian 12 or 13 host and root access — nothing else.
Download the tarball and the checksum
Save both files in the same directory on the target server.
wget https://dognet-technologies.online/downloads/sentinelcore-v1.2.0-linux-x86_64.tar.gz wget https://dognet-technologies.online/downloads/sentinelcore-v1.2.0-linux-x86_64.tar.gz.sha256
Verify the checksum
The command should print sentinelcore-v1.2.0-linux-x86_64.tar.gz: OK. If it fails, re-download.
sha256sum -c sentinelcore-v1.2.0-linux-x86_64.tar.gz.sha256
Extract the archive
tar -xzf sentinelcore-v1.2.0-linux-x86_64.tar.gz cd sentinelcore-v1.2.0-linux-x86_64
Run the installer as root
install.sh installs PostgreSQL, nginx, nmap, arp-scan, applies all migrations, generates a self-signed TLS certificate and configures nginx for HTTPS (HTTP redirects automatically), registers the systemd unit, starts the service, and creates the first admin user — automatically, with no prompts.
sudo ./install.sh
Read the credentials printed at the end
When install.sh finishes it prints the console URL and the generated admin password. Copy the password before closing the terminal — it is not stored anywhere.
URL: https://192.168.1.10
Admin: admin / Xk7mR9qP2vAa1!
⚠️ CAMBIA questa password al primo accesso.
Open the console and change the password
Navigate to https://<server-ip> in a browser on the same network — the browser will warn about the self-signed certificate, this is expected for LAN use. Log in with admin and the generated password, then go to Settings → Profile and set a permanent password.
sudo systemctl status sentinelcore
The OVA ships with a bridged network adapter — the VM will receive an IP from your LAN's DHCP, exactly like a physical host. VirtualBox will ask which host interface to bridge to during import. VMware users open the file with File → Open.
Download and verify
Download the OVA from ProtonDrive (browser required), then verify the checksum:
→ sentinelcore-v1.2.0-linux-x86_64.ova (678 MB) SHA256
wget https://dognet-technologies.online/downloads/sentinelcore-v1.2.0-linux-x86_64.sha256 sha256sum -c --ignore-missing sentinelcore-v1.2.0-linux-x86_64.sha256
Import — VirtualBox
GUI: File → Import Appliance → select the OVA → choose your bridge interface when prompted.
CLI (headless):
VBoxManage import sentinelcore-v1.2.0-linux-x86_64.ova \
--vsys 0 --vmname sentinelcore
# replace eth0 with your host's LAN interface
VBoxManage modifyvm sentinelcore \
--memory 4096 --cpus 4 --bridgeadapter1 eth0
VBoxManage startvm sentinelcore --type headless
# wait ~2 min, then get the guest IP
VBoxManage guestproperty get sentinelcore \
"/VirtualBox/GuestInfo/Net/0/V4/IP"
Import — VMware Workstation / Fusion
GUI: File → Open → select the OVA → follow the import wizard, then edit VM settings to set the NIC to Bridged.
CLI (ovftool):
ovftool --name=sentinelcore \
sentinelcore-v1.2.0-linux-x86_64.ova \
~/vmware/sentinelcore
# start headless (VMware Workstation Pro)
vmrun start ~/vmware/sentinelcore/sentinelcore.vmx nogui
# get IP
vmrun getGuestIPAddress ~/vmware/sentinelcore/sentinelcore.vmx
After import, verify the NIC is set to Bridged in VM Settings → Network Adapter.
Log in and change the password
First boot takes ~2 minutes. Open https://<vm-ip> in a browser on the same LAN (self-signed certificate warning is expected). The initial credentials are:
Username: microcyber
Password: Admin2026!!
SSH root: SentinelCore1st!
⚠ Change all three passwords on first login.
Commands below target Proxmox VE. Adapt the VM ID (900) and storage pool name (local-lvm) to your environment. The disk uses the virtio bus — do not attach it as scsi or sata.
Download and verify
Download the qcow2 from ProtonDrive (browser required), copy it to the Proxmox host, then verify:
→ sentinelcore-v1.2.0-linux-x86_64.qcow2 (702 MB) SHA256
cd /tmp wget https://dognet-technologies.online/downloads/sentinelcore-v1.2.0-linux-x86_64.sha256 sha256sum -c --ignore-missing sentinelcore-v1.2.0-linux-x86_64.sha256
Create the VM and import the disk
# adjust VM ID (900) and bridge (vmbr0) as needed qm create 900 --name sentinelcore \ --memory 4096 --cores 4 \ --net0 virtio,bridge=vmbr0 # import qcow2 into storage (replace local-lvm with your pool name) qm importdisk 900 \ /tmp/sentinelcore-v1.2.0-linux-x86_64.qcow2 local-lvm
Attach disk and set boot order
After import the disk appears as unused0 in the VM config. Read the exact ID before attaching.
# read the disk ID assigned by Proxmox DISK=$(qm config 900 | grep '^unused0:' | cut -d' ' -f2-) # attach as virtio (required — not scsi/sata) and set boot qm set 900 --virtio0 "$DISK" --boot order=virtio0
Start — Proxmox VE
First boot takes ~2 minutes. Check the IP from the Proxmox console or your router's DHCP leases.
qm start 900
Alternative — KVM / virt-manager
For bare KVM with virt-install or the virt-manager GUI.
sudo cp sentinelcore-v1.2.0-linux-x86_64.qcow2 \
/var/lib/libvirt/images/sentinelcore.qcow2
sudo virt-install \
--name sentinelcore \
--memory 4096 --vcpus 4 \
--disk /var/lib/libvirt/images/sentinelcore.qcow2,bus=virtio \
--network bridge=br0,model=virtio \
--os-variant debian12 \
--boot hd \
--import --noautoconsole
virt-manager GUI: File → New Virtual Machine → Import existing disk image → select the qcow2 → set RAM to 4096 MB, CPU to 4 → Network: bridge (br0 or your LAN bridge).
Log in and change the password
Open https://<vm-ip> in a browser on the same LAN (self-signed certificate warning is expected). The initial credentials are:
Username: microcyber
Password: Admin2026!!
SSH root: SentinelCore1st!
⚠ Change all three passwords on first login.
Already running SentinelCore?
Every release ships an in-place upgrade script that backs up your database with pg_dump, swaps the binary and frontend, applies any pending schema changes, and restarts the service — no data loss, no reinstall. It works the same way regardless of how your current instance was installed: tar.gz, OVA, or qcow2 all converge to the same layout once running.
Covered versions
- v1.0.1-beta → v1.2.0
- Use the procedure below as-is · no extra steps
Download the new package and checksum
On the server or VM that already runs SentinelCore — this is not a fresh install.
wget https://dognet-technologies.online/downloads/sentinelcore-v1.2.0-linux-x86_64.tar.gz wget https://dognet-technologies.online/downloads/sentinelcore-v1.2.0-linux-x86_64.tar.gz.sha256 sha256sum -c sentinelcore-v1.2.0-linux-x86_64.tar.gz.sha256
Extract and run the upgrade script as root
upgrade.sh — not install.sh — detects the existing installation automatically.
tar -xzf sentinelcore-v1.2.0-linux-x86_64.tar.gz cd sentinelcore-v1.2.0-linux-x86_64 sudo ./upgrade.sh
What happens automatically
In order: database backup (pg_dump, saved locally for manual restore if ever needed), stop the service, back up the current binary and frontend, install the new ones, apply pending migrations, restart, and verify /api/health. If the migration step fails, the previous binary and frontend are restored and the service is restarted — the database itself is never modified until migrations are confirmed to succeed.
Versione installata: 1.0.1-beta → Nuova: 1.2.0
✅ Migration applicate con successo (91 totali incorporate).
✅ Aggiornamento completato: 1.0.1-beta → 1.2.0
Backup DB pre-upgrade: /opt/sentinelsuite/sentinelcore/backups/pre-upgrade-*.dump