Skip to content
BastionCyber

Requires Linux kernel 5.8 or newer check first

The engine's event channel is the BPF ring buffer, introduced in Linux 5.8 — on an older kernel the agent does not run, and both scripts below stop with the reason before writing anything to the server. The kernel also needs BTF (CONFIG_DEBUG_INFO_BTF) and BPF LSM (CONFIG_BPF_LSM), plus unified cgroup v2 for process-freeze containment. That is the default on the generic cloud images of Ubuntu, Debian, RHEL and derivatives.

Check yours in one line: uname -r; stat -fc %T /sys/fs/cgroup; ls /sys/kernel/btf/vmlinux — you want 5.8 or higher, cgroup2fs, and the BTF file listed.

License activation

Activate your licence and get your JWT

Three steps: identify the account that paid, bind the token to one server, and collect it. Nothing is stored in this browser beyond the tab you have open.

  1. Email
  2. Server details
  3. Your JWT

Step 1 — Email address

Use the address you paid with. We check it against your subscription; if you have activated before, we reuse what we already hold and only ask about the server.

Use the address the licence was purchased with.

Step 2 — Server HWID

Welcome back, customer. The token is bound to one machine, so we need the HWID of the server you are installing on.

Run this on the Linux server you want to protect. It prints one line, installs nothing and changes nothing:

curl -sL https://bastioncyber.online/get-hwid.sh | sudo bash

50a644b7d38340e1a5caab476cce7513 — that is the HWID. Paste it below.

Read the script first if you would rather see it before piping it into a root shell.

Step 2 — New account details

This is the first activation on that subscription. Three fields and you are done.

Run this on the Linux server you want to protect. It prints one line, installs nothing and changes nothing:

curl -sL https://bastioncyber.online/get-hwid.sh | sudo bash

50a644b7d38340e1a5caab476cce7513 — that is the HWID. Paste it below.

Read the script first if you would rather see it before piping it into a root shell.

Token issued

Your licence is active

The token below is bound to the HWID you supplied and to no other machine.

  • Account
  • Company
  • Bound HWID
  • Expires
License token (JWT)

Copy it now. This panel lives in this browser tab only and is gone when you close it.

Day-to-day commands Every server

These work on any licensed host, whatever version it was installed from — they go through the ghostshield binary, not through the package folder.

What happens after you install First 72 h

GhostShield V3.0 “Despertar” installs in Shadow Mode and arms itself — there is no config file for you to edit and nothing to switch on by hand.

The engine attaches 12 kernel-level defense programs (11 LSM hooks + 1 syscall probe). A watchdog in user space (Hidra) covers rule-unloading attempts, so a defense-in-depth kernel hook we could not attach cleanly on every kernel was intentionally left out — the protection it guarded is still covered.

  1. Hours 0–24 — Calibration (audit only). Every defense runs, but nothing is blocked yet: the engine only measures what it would have stopped, so a false positive from your own stack can never take a process down on day one. The Argos panel on 3333/tcp shows a live countdown and flags anything that would have been blocked.
  2. At 24 h — Auto-arm. The active defenses go live automatically (Ring 0 enforcement, self-defense, kernel-map shield). Zero config: you do not run a command, you do not edit solon_vip.conf.
  3. 24–72 h — Armed & guided. The panel keeps a banner up so you can see it went live; after 72 h the banner disappears and the panel returns to its normal layout.

Self-healing. A watchdog (Hidra) resurrects the engine if a process tries to kill it — you do not stop GhostShield by killing a PID. To stop it cleanly, use sudo ghostshield uninstall or the packaged ./stop_solon.sh; both signal a graceful exit so the watchdog stands down. Rescue / panic: if the host ever needs the engine to stand down at next boot, create the file /etc/ghostshield_bypass and reboot — systemd skips the engine, no restart loop.

Saw a false positive during calibration? That is exactly what the first 24 h are for. Run sudo ghostshield uninstall and email contact@bastioncyber.online — we tune a whitelabel profile for your stack before you arm in production.

Is the host protected?
$ sudo ghostshield status
> [UP]   Ring 0 Engine (Solon) ...... active
> [UP]   Jailer Containment ......... active
> [UP]   Argos Backend .............. active
> License ....................... ACTIVE

Read straight from systemd, never from a state file — a service that died cannot report itself as up.

Prove the evidence was not touched
$ sudo ghostshield audit
> Trail SEALED append-only (chattr +a)
> Chain OK - 13169 tamper-evident records verified.
$ sudo ghostshield audit --archive  # also the rotated half

Every line of the trail carries SHA‑256(previous hash + this line), so editing or deleting any line in the middle breaks the chain at that point and this command says where. The file itself is sealed append‑only on the inode: truncate, rename and rm return Operation not permitted to every process on the machine, root included, so a log rotation or a cleanup script cannot quietly cut your evidence. The panel on 3333/tcp shows a live window of the most recent 1000 events; the trail on disk keeps all of them.

Whitelist a noisy legitimate service (VIP)
$ sudo ghostshield vip add docker.service
> Argos PIN: ******
> VIP added: docker.service
> solon.service restarted - the VIP exemption is now active.

If a legitimate, heavy workload trips a defense during calibration — a container runtime or a busy web tier generating file or network activity in the thousands — exempt that service instead of turning a whole defense off. The unit and its entire cgroup subtree are placed on the VIP list, exempt from the lethal defenses. The command is gated by the Argos PIN you set at install, adds only, and applies immediately. The choice persists across reinstalls.

Remove the agent
$ sudo ghostshield uninstall          # keeps the audit trail
$ sudo ghostshield uninstall --purge  # deletes it too

The default keeps /var/log/ghostshield: the trail is your forensic evidence, not installation leftovers. --purge deletes the trail, its compressed archive and the chain anchor, and there is no copy anywhere else — GhostShield never sends anything off your host, so nothing can be restored from our side.

Need help? For JWT recovery or technical assistance, contact contact@bastioncyber.online (up to 24h SLA).