Known malware and silent alterations: two defences, one panel.

The WAF stops attacks on the perimeter. But if an infected file is already on the server, or if someone touches an SSH key in the middle of the night, web filtering alone is not enough. Sentinel combines local scans, hash checks and File Integrity Monitoring to reveal what network traffic cannot show.

Quick · Full · CustomClamAV + hashSQLite baseline FIM
The problem

A dangerous file may already be inside the server.

Malware, webshell and unauthorised changes are not always visible by observing only web traffic.

What Sentinel does

Scan files and compare what changes.

ClamAV searches for known threats; the integrity control compares hash, permissions and properties with a baseline.

The result

Get a precise signal and keep control.

Sentinel reports the file and type of variation without automatically deleting important data.

Orchestration from the panel

Start, schedule and monitor scans across the fleet.

From the dashboard choose the server, the type of scan and any custom paths. The agent collects the command, updates the progress and sends the results to the central server.

  • Quick, full or custom on a specific server.
  • Daily, weekly or monthly scheduling, for a server or for the entire fleet.
  • Progress and cancellation of running scans.
  • Infected and false positive files managed in dedicated sections.
Antivirus scans and results in the Sentinel dashboard

Optional hash lookup · VirusTotal

Compare the file fingerprint without uploading the contents.

When integration is configured, the server can consult VirusTotal using a SHA-256, SHA-1 or MD5 hash, never the file: the result contains engines, detections and threat category and is cached to reduce requests.

  • Optional integration: Without API key the external lookup is not executed.
  • Rate limits and daily quotas respected by the server.
  • Manual verification of a single hash directly from the panel.
sentin / antivirus / hash
Check hashOPZIONALE
SHA256 · 9f86d081...2 / 72
Content of the sent fileNO
Cache resultYES

Why AV + FIM on a WAF

Three layers that look at the same server from different angles.

An application firewall is powerful, but only sees requests. Sentinel adds two more eyes: one on the files, one on the changes.

01

WAF protects the perimeter

Coraza with OWASP CRS inspects and blocks hostile traffic before it reaches the application. It is the first line, but acts only on HTTP requests.

02

ClamAV finds known malware

A loaded webshell, a Trojan binary, an EICAR test file: the scan compares the contents with the ClamAV signature database and reports what is already catalogued as a threat.

03

FIM sees what changes

What no signature knows yet is recognised because it has changed: a different hash, unexpected setuid permission, a new systemd unit. The FIM compares with the baseline and raises an alert.

ClamAV Scanning

Stream files for scanning without devouring RAM.

The agent talks to the clamd daemon via a Go client Without CGO: no native library to link, no fragile binding. The protocol is INSTREAM over a Unix socket, and files come streamed in chunks instead of being loaded into memory in full.

  • INSTREAM Protocol over a Unix socket, with health-check PING before each session.
  • Files streamed in chunks: Scanning a large file does not cause the agent's memory use to spike.
  • Limit 100 MB by file: beyond the threshold the file is simply skipped.
  • ClamAV is opt-in: The default scanner is the hash engine (SHA256); ClamAV is activated when you need a real signature scan.
  • Quick, full or custom: quick scan of executables in sensitive paths, full from root with a defined resource budget (up to 2 million files or four hours), custom on the paths you choose.
Sentinel dashboard real screen

File Integrity Monitoring

If something critical changes, you know.

The FIM (opt-in) builds a baseline in SQLite at the first pass trust-on-first-use: what it finds becomes the reference state. At each subsequent cycle, it compares the files again and shows you the differences.

  • Full comparison: hash SHA256, size, permissions (including setuid/setgid/sticky) and file owner.
  • Typed events: created, modified, deleted and type_changed, so you know what It happened, not only that It happened.
  • Polling, not real-time: The control runs at intervals (default ~10 min). It is honest to say it is not an instantaneous inotify watch.
  • File > 50 MB skipped: This keeps the baseline lightweight and scan cycles fast.
  • Monitor what matters: account files (/etc/passwd, /etc/shadow, sudoers), SSH, cron/systemd, preload and Sentinel itself.
Sentinel dashboard real screen

What is detected · what is not

Honest precision, no magical promises.

Two engines with clear boundaries. Know what not makes a tool is part of knowing how to use it well.

What ClamAV detects

  • Malware known and catalogued from the ClamAV signature database.
  • Webshell PHP, Trojan binaries, EICAR test files.
  • Suspicious contents on quick (sensitive path), full (whole root) or custom scans.

What FIM detects

  • File created, modified, deleted or with a changed type.
  • Changes in SHA256, size, permissions (setuid/setgid/sticky) and owner hash.
  • Monitoring of accounts, SSH, cron/systemd, preload and the agent itself.

What it does NOT do

  • No quarantine or automatic removal: detects and reports, does not delete files. The decision remains with you.
  • FIM is polling, not real-time: events arrive at the next cycle, not instantly.
  • Large files skipped: Over 100 MB for AV, over 50 MB for FIM.
  • ClamAV signatures are not managed by Sentinel: Use the database maintained by the operating system.
  • VirusTotal is optional: If enabled, only the file's hash is sent to the external service, not the content.

Fleet and dashboard integration

Every event appears where you can act on it.

When ClamAV finds a threat or FIM detects a change, the agent issues an event malware_detected or fim_change and sends it to the central server via gRPC with mTLS. From there it flows into the dashboard of the fleet and the alerts.

  • One panel for the outcome of the scans and the timeline of the modifications, for individual servers and across the whole fleet.
  • Immediate alerts on ntfy self-hosted and on the Android G Tech app: you know right away when something changes.
  • Secure agent-server channel: events and results travel encrypted and authenticated via mTLS.
Sentinel dashboard real screen

Frequently asked questions

How antivirus and FIM work in practice.

Does Sentinel remove infected files on its own?

No. ClamAV and the FIM detect and report: no automatic quarantine or deletion. Review the event in the dashboard and receive the alert, then decide how to intervene.

Do I need to install ClamAV separately?

The agent connects to the clamd daemon via unix socket with INSTREAM protocol. The default scanner is the hash engine (SHA256); ClamAV is opt-in and uses the DB signatures maintained by the system.

Does the FIM warn in real time?

FIM works in polling, with a default interval of about 10 minutes. It is not an instant watch: deviations from the baseline appear at the next control cycle.

How is the FIM baseline created?

With the trust-on-first-use: The first pass records hash, size, permissions and owners in an SQLite database. From there on, each file is compared to that reference state.

Are there files too large to check?

Yes. Antivirus skips files over 100 MB, while FIM skips files larger than 50 MB. It is a deliberate choice to keep both agent memory use and the baseline lightweight.

How are signatures updated? Is VirusTotal supported?

ClamAV signatures are maintained by the system, not by Sentinel. Alternatively or in addition you can configure the VirusTotal hash lookup: The hash of the file is sent, never its contents, and the integration remains disabled without API key.

Want to see AV and FIM on your servers?

We show you ClamAV scans and File Integrity Monitoring live on your infrastructure, calibrated on the routes that matter to you.