Checks
Each scan runs the checks you choose, in the dashboard's scan dialog or with:
deaconguard scan HOST_ID --checks packages,integrity,malware,config,antivirus
Package vulnerabilities is the default.
| Check | ID | What it does | Reads or runs |
|---|---|---|---|
| Package vulnerabilities | packages | Compares installed packages and the running kernel with the distribution's official advisories (see Supported distributions). | /etc/os-release, the DPKG status file or rpm -qa, uname -r |
| System file integrity | integrity | Verifies packaged files against the package manager's checksums. Changed binaries and libraries, a classic rootkit sign, are reported; edited configuration files are counted but not reported. | dpkg --verify or rpm -Va |
| Malware & compromise indicators | malware | Looks for crypto-miner processes; programs running from /tmp, /dev/shm, memory or deleted files; programs disguised as kernel threads; /etc/ld.so.preload; hidden executables in temporary directories; and download-and-execute or reverse-shell patterns in cron and systemd. This is not a full antivirus scan. | /proc, ps, find on temporary directories, cron and systemd files |
| Security configuration | config | Reports SSH root or password login, empty passwords, X11 forwarding; risky services such as Redis, databases, Telnet or the Docker API listening on all interfaces; pending reboots; disabled automatic updates; and, with sudo, a missing host firewall. | sshd configuration, ss/netstat, reboot and update settings, firewall rules |
| Antivirus (ClamAV) | antivirus | Runs the host's own clamscan at low priority on temporary, home and application directories, and reports detections and signatures older than 7 days. Skipped when ClamAV isn't installed, or when the host has less than about 1.5 GB of free memory and swap, since ClamAV loads its whole signature database into memory. | clamscan |
Every command is a fixed string in DeaconGuard's source; nothing from the user or the host is inserted into it, and every command only reads.
Running checks with sudo
Agents run as root and see everything. In local mode and on the server's own host, checks run as the user running DeaconGuard. That user can't see other users' processes, protected files or firewall rules, so those results say they have partial coverage.
Allow sudo to run the same read-only commands through sudo:
--allow-sudowhen adding the machine or scanning it once;deaconguard host sudo HOST_ID on;- or the switch on the host's page.
If sudo needs a password, the dashboard or terminal asks for it once per scan and keeps it in memory only. Declining continues the scan without sudo.
Results you can trust
- A skipped, partial or failed check is never shown as clean.
- Advisory rules DeaconGuard can't evaluate are listed as "not evaluated", not counted as passed.
- Missing, invalid or stale advisory data is never reported as zero vulnerabilities.