Requires Linux kernel 5.8 or newer check first
The engine's event channel is the BPF ring buffer, introduced in Linux
5.8 — on an older kernel the agent does not run,
and both scripts below stop with the reason before writing anything to
the server. The kernel also needs BTF
(CONFIG_DEBUG_INFO_BTF) and BPF LSM
(CONFIG_BPF_LSM), plus unified cgroup v2
for process-freeze containment. That is the default on the generic
cloud images of Ubuntu, Debian, RHEL and derivatives.
Check yours in one line:
uname -r; stat -fc %T /sys/fs/cgroup; ls /sys/kernel/btf/vmlinux
— you want 5.8 or higher, cgroup2fs,
and the BTF file listed.
Your 15-day licence is ready
Issued for and bound to the HWID you supplied. Expires . Copy both values now — this box lives in this browser tab only and is gone when you close it.
Write the PIN down now. The installer asks you to choose a 6-digit PIN for the Argos dashboard — use this one, or pick your own. We do not store it and cannot show it to you again: only a hash of the PIN ever exists, and it exists only on your server.
Activate your licence and get your JWT
Three steps: identify the account that paid, bind the token to one server, and collect it. Nothing is stored in this browser beyond the tab you have open.
- Server details
- Your JWT
Your licence is active
The token below is bound to the HWID you supplied and to no other machine.
- Account
- Company
- Bound HWID
- Expires
Copy it now. This panel lives in this browser tab only and is gone when you close it.
Renewal tutorial Same server
The agent is already installed on this HWID. Do not reinstall
and do not run prepare_kernel.sh again —
renewing is one command, and it does not interrupt enforcement.
Nothing renews automatically. Every renewal is a new licence purchased on this site, which issues a new JWT for this same HWID. You then extend the licence in place with the command below.
Extend the licence in place
$ sudo ghostshield renew
> Enter New License Token (JWT): [invisible]
> Expiration Date Updated: 2027-08-31.
The prompt uses blind input — nothing is
echoed while you paste. Your terminal is not frozen. Paste once
and press Enter. renew refuses a token that does
not actually extend the licence, so a stale paste cannot
shorten it.
Confirm the new expiry
$ sudo ghostshield status
> License ....................... ACTIVE
> All services running - GhostShield is armed and defending.
status reads the services straight from systemd,
never from a state file.
New installation tutorial New server
Three steps. Step 1 prepares the kernel — it edits the
boot configuration and reboots the machine
unless BPF LSM is already enabled; step 2 downloads the package
and checks its sha256; step 3 installs the agent,
verifies the token and runs a self-test. Run step 1 in a
maintenance window.
Server requirements — checked before anything is
written. Linux kernel 5.8 or newer
(the engine's event channel is the BPF ring buffer, introduced
in that version); kernel built with BTF
(CONFIG_DEBUG_INFO_BTF) and BPF LSM
(CONFIG_BPF_LSM) — the default in the generic
cloud images of Ubuntu, Debian, RHEL and derivatives; and
unified cgroup v2 for the process-freeze
containment. Both scripts below stop with the reason if a
requirement is missing, and leave no files on the server.
Servers still on cgroup v1. Telemetry and the
kernel-level defenses work, but process-freeze
containment is not available there — it depends
on a control-group feature that exists only in cgroup v2.
Installing on such a host requires an explicit confirmation
(--force-audit-legacy), and the freeze stays off.
You can check yours with
stat -fc %T /sys/fs/cgroup —
cgroup2fs is what you want.
Step 1 — prepare the kernel (reboots this machine)
$ curl -fsSL -O https://bastioncyber.online/downloads/prepare_kernel.sh
$ chmod +x prepare_kernel.sh
$ sudo ./prepare_kernel.sh # reboots if 'bpf' is missing
GhostShield runs in the kernel through BPF LSM.
If bpf is already active the script changes nothing
and does not reboot. Otherwise it writes a GRUB
drop-in that appends — your serial console
survives — proves the new command line won in the
generated grub.cfg, and reboots after a 10-second
Ctrl-C window. --no-reboot leaves the reboot to
you; --check only diagnoses.
Step 2 — download and verify the package
$ curl -fsSL -O https://bastioncyber.online/downloads/ghostshield_v3.3.3.tar.gz
$ curl -fsSL -O https://bastioncyber.online/downloads/ghostshield_v3.3.3.tar.gz.sha256
$ sha256sum -c ghostshield_v3.3.3.tar.gz.sha256
> ghostshield_v3.3.3.tar.gz: OK
Do not extract anything that did not print
OK. You are about to run an installer as
root; the checksum is what tells a truncated or altered download
apart from a good one, and it costs one command. The expected
digest for the package published right now is:
b12728398ad5818e4d3dc846278ec5da81505ceb9812bf315c8ba07ac22a5d48
> ghostshield_v3.3.3.tar.gz
Prefer sha256sum -c over reading the two strings
side by side: comparing 64 hex characters by eye is exactly the
check people convince themselves they did.
Step 3 — install the agent
$ tar -xzf ghostshield_v3.3.3.tar.gz && cd ghostshield_v3.3.3
$ sudo ./install_ghostshield_v3.sh --license --pin
> HWID for this machine:
> Enter License Token (JWT): [invisible]
> Set the Argos panel PIN (6 digits): [invisible]
> licence OK - GhostShield V3.0 is armed and defending.
The token and PIN prompts are invisible on purpose.
The token is verified against the issuer public key shipped
inside the package (RS256) and is never written to
disk — not on the command line, not in your shell
history. Of the PIN, only a pbkdf2_sha256 hash is
stored, and only on your server.
Verify the host is protected
$ sudo ghostshield status
> [UP] Ring 0 Engine (Solon) ...... active
> [UP] Jailer Containment ......... active
> [UP] Argos Backend .............. active
> panel ...................... http://<this-host-ip>:3333
The Argos panel listens on 3333/tcp behind the 6-digit PIN you set at install time. It is a reader and nothing else: stopping it does not change enforcement.
Fire test — prove the kernel side really attached
$ sudo journalctl -u solon.service -n 40 --no-pager | grep -E 'hooks attached|NOT attached'
> hooks attached: [ ... ]
This is the check that matters, and it is the one people
skip. A service can report active while the
kernel has refused the programs it was supposed to load —
the agent would be running and defending nothing. One line
starting with hooks attached and no line
containing NOT attached is the proof that
the engine is really in place on your kernel. If you do see a
NOT attached line, send us that exact output before
doing anything else — it is the single most useful thing
you can put in a support message.
Running this later, on a server that has been up for a
while? Drop the -n 40. That window holds
the last 40 journal lines, and on a busy host the attach line
has long scrolled past it — you would get empty output and
read it as a failure. The line is written once, when the engine
starts, so search the whole unit journal instead:
$ sudo journalctl -u solon.service --no-pager | grep -E 'hooks attached|NOT attached' | tail -3
Day-to-day commands Every server
These work on any licensed host, whatever version it was
installed from — they go through the ghostshield
binary, not through the package folder.
What happens after you install First 72 h
GhostShield V3.0 “Despertar” installs in Shadow Mode and arms itself — there is no config file for you to edit and nothing to switch on by hand.
The engine attaches 12 kernel-level defense programs (11 LSM hooks + 1 syscall probe). A watchdog in user space (Hidra) covers rule-unloading attempts, so a defense-in-depth kernel hook we could not attach cleanly on every kernel was intentionally left out — the protection it guarded is still covered.
- Hours 0–24 — Calibration (audit only). Every defense runs, but nothing is blocked yet: the engine only measures what it would have stopped, so a false positive from your own stack can never take a process down on day one. The Argos panel on 3333/tcp shows a live countdown and flags anything that would have been blocked.
- At 24 h — Auto-arm. The active defenses
go live automatically (Ring 0 enforcement, self-defense,
kernel-map shield). Zero config: you do not run
a command, you do not edit
solon_vip.conf. - 24–72 h — Armed & guided. The panel keeps a banner up so you can see it went live; after 72 h the banner disappears and the panel returns to its normal layout.
Self-healing. A watchdog (Hidra) resurrects the
engine if a process tries to kill it — you do not stop
GhostShield by killing a PID. To stop it cleanly, use
sudo ghostshield uninstall or the packaged
./stop_solon.sh; both signal a graceful exit so the
watchdog stands down. Rescue / panic: if the host
ever needs the engine to stand down at next boot, create the file
/etc/ghostshield_bypass and reboot — systemd
skips the engine, no restart loop.
Saw a false positive during calibration? That is
exactly what the first 24 h are for. Run
sudo ghostshield uninstall and email
contact@bastioncyber.online
— we tune a whitelabel profile for your stack before you
arm in production.
Is the host protected?
$ sudo ghostshield status
> [UP] Ring 0 Engine (Solon) ...... active
> [UP] Jailer Containment ......... active
> [UP] Argos Backend .............. active
> License ....................... ACTIVE
Read straight from systemd, never from a state file — a service that died cannot report itself as up.
Prove the evidence was not touched
$ sudo ghostshield audit
> Trail SEALED append-only (chattr +a)
> Chain OK - 13169 tamper-evident records verified.
$ sudo ghostshield audit --archive # also the rotated half
Every line of the trail carries
SHA‑256(previous hash + this line),
so editing or deleting any line in the middle breaks the chain at
that point and this command says where. The file itself is
sealed append‑only on the inode:
truncate, rename and rm
return Operation not permitted to every process on the
machine, root included, so a log rotation or a cleanup script
cannot quietly cut your evidence. The panel on
3333/tcp shows a live window of the most recent
1000 events; the trail on disk keeps
all of them.
Whitelist a noisy legitimate service (VIP)
$ sudo ghostshield vip add docker.service
> Argos PIN: ******
> VIP added: docker.service
> solon.service restarted - the VIP exemption is now active.
If a legitimate, heavy workload trips a defense during calibration — a container runtime or a busy web tier generating file or network activity in the thousands — exempt that service instead of turning a whole defense off. The unit and its entire cgroup subtree are placed on the VIP list, exempt from the lethal defenses. The command is gated by the Argos PIN you set at install, adds only, and applies immediately. The choice persists across reinstalls.
Remove the agent
$ sudo ghostshield uninstall # keeps the audit trail
$ sudo ghostshield uninstall --purge # deletes it too
The default keeps
/var/log/ghostshield: the trail is your forensic
evidence, not installation leftovers.
--purge deletes the trail, its compressed
archive and the chain anchor, and there is no copy anywhere
else — GhostShield never sends anything off your
host, so nothing can be restored from our side.