Default file: configs/default.yaml.
Override path with the global flag --config /path/to.yaml.
CLI flags override selected keys when both are present (for example --epochs overrides train.epochs).
| Key | Type | Default | Meaning |
|---|---|---|---|
interval_sec |
float | 1.0 |
Sleep target between samples in collect / monitor sampling loop |
max_cores |
int | 16 |
Fixed number of cpu_core_* columns (pad/truncate host cores) |
socket_sample_every |
int | 5 |
Refresh ESTABLISHED/LISTEN counts every N samples (cheaper than every second) |
| Key | Type | Default | Meaning |
|---|---|---|---|
size |
int | 60 |
Rows per window (seconds if interval_sec is 1) |
stride |
int | 5 |
Step between windows in build-dataset and analyze |
CLI --window / --stride on build-dataset override these when set.
| Key | Type | Default | Meaning |
|---|---|---|---|
epochs |
int | 15 |
CNN epochs (overridden by --epochs) |
batch_size |
int | 32 |
DataLoader batch size |
lr |
float | 0.001 |
Adam learning rate |
val_ratio |
float | 0.2 |
Fraction of windows held out for validation when building the dataset |
seed |
int | 42 |
RNG seed for split and training |
cnn_weight |
float | 0.6 |
Weight of CNN anomaly probability in fusion |
iforest_weight |
float | 0.4 |
Weight of Isolation Forest score in fusion |
recall_target |
float | 0.9 |
Validation recall target used to pick the decision threshold |
Fusion is renormalized so the two weights sum to 1.
| Key | Type | Default | Meaning |
|---|---|---|---|
interval_sec |
float | 5 |
Seconds between inferences (CLI --interval) |
cooldown_sec |
float | 60 |
Minimum seconds between alerts (CLI --cooldown) |
top_processes |
int | 3 |
How many processes to list on alert |
| Key | Type | Default | Meaning |
|---|---|---|---|
default_threshold |
float | 0.5 |
Fallback only; trained artifacts/meta.json threshold is used at inference |
See configs/default.yaml and the Russian config doc for full tables. Env: TELEGRAM_BOT_TOKEN, TELEGRAM_CHAT_ID, WEBAPP_URL.
Notable v0.6 keys:
| Section | Key | Default | Meaning |
|---|---|---|---|
load_profile |
lite / full |
lite |
CPU budget (VPS vs VDS) |
runtime |
prefer |
notorch |
notorch | onnx | torch_ml |
response |
mode |
observe |
observe | shield | aggressive |
telegram |
require_console_unlock |
true |
Gate TG + web actions until /unlock |
agent |
mode |
userspace |
userspace or ebpf (attach needs root) |
agent |
require_hmac |
true |
Reject unsigned critical agent rules |
agent |
root_watch |
true |
Unexpected uid=0 via ProcWatcher (ROOT_WATCH.md) |
agent |
root_learn_sec |
300 |
Baseline root PIDs before alert |
root_watch |
enabled |
false |
Python poller — only if agent disabled |
sessions |
enabled |
true |
Unexpected SSH → Kick / Ban |
kirk |
trust |
auto |
Probe IMA+SB/TPM → best-effort | measured |
kirk |
auto_isolate |
false |
CRITICAL kirk → nft ss_kirk (set allow_ssh_cidrs) |
kirk |
auto_isolate_host_risk |
false |
Also isolate when host ML score ≥ threshold |
kirk |
host_risk_threshold |
0.99 |
Host-risk isolate threshold |
kirk |
vmi |
false |
Reserved; live VMI → v1.0 (VMI.md) |
alerts |
sinks |
file jsonl | Fan-out file / syslog / https |
watchdog |
phoenix / kernel_protect |
true / false |
Twin + optional DKMS PID registry |
agent.fim |
enabled / baseline_path |
profile | FIM poll + persisted baseline |
ensemble |
host_weight / agent_weight |
see yaml | Fuse host ML + agent IF → risk |
supply_chain |
enforce |
false |
Verify manifest and minisign signature before model deserialization |
supply_chain |
public_key |
null |
Minisign public key file or key string used when enforcement is enabled |
supply_chain |
manifest_name |
artifacts.manifest.json |
Model manifest filename |
supply_chain |
signature_name |
artifacts.manifest.json.minisig |
Minisign sidecar filename |
- v0.8: supply-chain enforcement is opt-in for compatibility.
configurecan enable it only when a public key is supplied. See SUPPLY_CHAIN.md. - v0.6: agent HMAC + PID allowlist + exe seal; root watch in Rust; Role Lab; feedback. VMI deferred to v1.0.
- Changing
max_coresor feature schema requires rebuilding the dataset and retraining; old artifacts will not match new column layouts.