Skip to main content

Checks

Each scan runs the checks you choose, in the dashboard's scan dialog or with:

deaconguard scan HOST_ID --checks packages,integrity,malware,config,antivirus

Package vulnerabilities is the default.

CheckIDWhat it doesReads or runs
Package vulnerabilitiespackagesCompares installed packages and the running kernel with the distribution's official advisories (see Supported distributions)./etc/os-release, the DPKG status file or rpm -qa, uname -r
System file integrityintegrityVerifies packaged files against the package manager's checksums. Changed binaries and libraries, a classic rootkit sign, are reported; edited configuration files are counted but not reported.dpkg --verify or rpm -Va
Malware & compromise indicatorsmalwareLooks for crypto-miner processes; programs running from /tmp, /dev/shm, memory or deleted files; programs disguised as kernel threads; /etc/ld.so.preload; hidden executables in temporary directories; and download-and-execute or reverse-shell patterns in cron and systemd. This is not a full antivirus scan./proc, ps, find on temporary directories, cron and systemd files
Security configurationconfigReports SSH root or password login, empty passwords, X11 forwarding; risky services such as Redis, databases, Telnet or the Docker API listening on all interfaces; pending reboots; disabled automatic updates; and, with sudo, a missing host firewall.sshd configuration, ss/netstat, reboot and update settings, firewall rules
Antivirus (ClamAV)antivirusRuns the host's own clamscan at low priority on temporary, home and application directories, and reports detections and signatures older than 7 days. Skipped when ClamAV isn't installed, or when the host has less than about 1.5 GB of free memory and swap, since ClamAV loads its whole signature database into memory.clamscan

Every command is a fixed string in DeaconGuard's source; nothing from the user or the host is inserted into it, and every command only reads.

Running checks with sudo​

Agents run as root and see everything. In local mode and on the server's own host, checks run as the user running DeaconGuard. That user can't see other users' processes, protected files or firewall rules, so those results say they have partial coverage.

Allow sudo to run the same read-only commands through sudo:

  • --allow-sudo when adding the machine or scanning it once;
  • deaconguard host sudo HOST_ID on;
  • or the switch on the host's page.

If sudo needs a password, the dashboard or terminal asks for it once per scan and keeps it in memory only. Declining continues the scan without sudo.

Results you can trust​

  • A skipped, partial or failed check is never shown as clean.
  • Advisory rules DeaconGuard can't evaluate are listed as "not evaluated", not counted as passed.
  • Missing, invalid or stale advisory data is never reported as zero vulnerabilities.