Skip to main content

CLI reference

Run deaconguard help for this list on your machine, and deaconguard version for the installed version.

Scanning​

CommandDoes
deaconguard host add [--allow-sudo]Register this machine (Linux).
deaconguard host listList hosts.
deaconguard host sudo HOST_ID on|offAllow or stop the deeper checks using sudo.
deaconguard host remove HOST_IDRemove a host; for an agent host, also revoke its agent.
deaconguard scan HOST_ID [--checks LIST] [--json]Scan a host. LIST is a comma-separated choice of packages,integrity,malware,config,antivirus.
deaconguard scan --local [--allow-sudo] [--checks LIST] [--json]Scan this machine without registering it.
deaconguard report REPORT_ID [--json]Show a saved report.

Setup​

Run as root after installing the package; the install script runs these for you.

CommandDoes
deaconguard setup server [--listen ADDRESS:PORT] [--tls-cert FILE --tls-key FILE] [--admin-user NAME] [--admin-password-file FILE]Create the first account and start the server service.
deaconguard setup agent [--token-file FILE] [--force]Enroll (asks for the token unless given) and start the agent service.

Server and dashboard​

CommandDoes
deaconguard serveLocal dashboard at http://127.0.0.1:7480, no sign-in.
deaconguard serve --listen 0.0.0.0:8443 [--tls-cert FILE --tls-key FILE]Server: HTTPS dashboard with sign-in; agents can enroll.
deaconguard user add|passwd USERNAME [--password-stdin]Create an account, or change its password.
deaconguard user listList accounts.
deaconguard user remove USERNAMERemove an account and sign it out.
deaconguard token create --server-url https://HOST:8443Create a single-use enrollment token, valid for 24 hours, and print the install command.

On a server installed as a service, run user and token commands as the service user: sudo -u deaconguard deaconguard ….

Agent​

CommandDoes
deaconguard agent enroll TOKEN [--force]Enroll with the server that made the token.
deaconguard agent runWait for scans; this is what the deaconguard-agent service runs.
deaconguard agent statusShow where this machine is enrolled.