v3.0.0 · stable release

Real-time defence for
Pterodactyl host nodes.

SentinelX runs as root on the host and watches your panel, server volumes, database and SSH continuously. Malware, webshells, brute force and connection floods are caught as they happen — not after a customer opens a ticket.

Detection path
inotify / netlink
Modules active
10 / 13
Control plane
Telegram + REST
Revalidation
every 24 h
Protection modules

Everything runs on the host, nothing inside your containers

No Pterodactyl API tokens, no agent image, no cron polling. Every licence unlocks every module — the status badge tells you what the current build actually does, not what a roadmap promises.

Disk Protect

Active
inotify · real time

Watches every Pterodactyl volume with inotify and inspects each new or modified file against malware, ransomware, reverse-shell, webshell and disk-bomb signatures. Dangerous files are quarantined or deleted; ransomware triggers an immediate server suspend.

Content Scan

Active
PHP · Bash

Reads file contents (extension-aware) and matches against obfuscated eval chains, assert/shell_exec execution, PHP stream-wrapper bridges such as php-bridge, destructive SQL and pipe-to-shell payloads.

Panel Integrity

Active
SHA-256 baseline

Hashes every panel PHP file at startup, then watches for changes. Unknown new PHP files, modified files, and critical targets like .env and config/database.php are reported immediately.

DB Guard

Active
MySQL · 5s poll

Detects out-of-band database changes that bypass the panel: admin password resets, unexpected root_admin account creation, and new API keys issued without a matching activity log.

SSH Guard

Active
whitelist · iptables

Any SSH session from an IP outside the whitelist is killed. Repeated failures trigger an automatic iptables ban and push the offending IP to the threat-intel feed.

NetGuard

Active
conntrack netlink

Subscribes to kernel conntrack events for zero-delay flood detection. IPs exceeding the new-connection threshold inside the sliding window are blocked with a configurable TTL.

ProcGuard

Active
CN_PROC · cgroup v1/v2

Sees every process exec as it happens, then reads container CPU/RAM straight from cgroups. Known DDoS tool signatures, cryptominers and ram-bombs are killed and escalated server-side.

Self Guard

Active
chattr +i · watchdog

Locks the binary as immutable, hashes itself plus critical host files, and alerts whenever the binary, config, authorized_keys or cron is touched.

Telegram Bot + REST API

Active
operator control

Owner-only Telegram bot with inline confirm buttons, plus a localhost REST API on 127.0.0.1:7734 for status, SSH whitelist, GeoIP lists, abuse data and emergency lockdown.

Daily Report

Active
Telegram digest

Uptime, SSH bans, NetGuard blocks, top attacker countries, abuse totals and disk usage delivered to the owner on a configurable hour.

GeoIP Intelligence

Partial
IP2Location LITE

Resolves the country behind every SSH failure using a local IP2Location database and labels the alert with it. Currently attribution only: the country is reported, not enforced as a block.

Threat Intel Sharing

Partial
peer feed

Banned SSH brute-force IPs are pushed to peer nodes and their feeds are pulled on an interval. NetGuard-blocked IPs are not shared yet, and a shared IP annotates alerts rather than blocking on the peer.

Abuse Tracker

In development
24h sliding window

Score abuse events per server UUID with severity weights for malware, disk, network, CPU and RAM. The scoring engine is compiled in but is not yet called by any module, so counters stay empty for now.

Activation

From voucher to protected node in under a minute

A licence binds to one node at a time. Moving to a new VPS is a single command on the old node, after which the voucher is free again.

Three wrong attempts delete the daemon binary. The activation prompt allows three tries per boot and then removes the executable. Always verify a code on the Check Licence page first.
# move a licence to a new VPS # (send this from the Telegram bot on the OLD node) /sentinelx deactivate # then start the daemon on the new node and enter the voucher sudo systemctl restart sentinelx

Purchase a voucher

You receive a code shaped like SNTX-XXXX-XXXX-XXXX. The ambiguous characters 0, O, 1 and I are never used so it cannot be misread.

Install the daemon

Clone the repository and run the installer. It detects your distribution, installs dependencies, compiles the binary to /usr/local/bin/sentinelx and registers the systemd unit.

Run the setup wizard

Enter a Telegram bot token and owner chat ID, your panel URL and the volumes path. Everything is written to /etc/sentinelx.conf and can be reloaded with SIGHUP.

Enter the voucher

The daemon prints your machine fingerprint and validates the code against this portal. On success it writes an HMAC-signed licence file to /etc/sentinelx.lic with mode 0600.

It keeps checking itself

Every 24 hours the daemon revalidates against this portal. A revoked or expired licence makes the daemon log the reason and shut down after a 60 second countdown.

Why it catches things

Kernel event paths, not polling loops

inotify for files

Volume writes, panel PHP changes and auth-log lines arrive as events. There is no crawl interval to fall behind.

conntrack netlink

NetGuard subscribes to kernel connection events, so a flood is measured the moment the kernel sees it rather than on the next poll.

process connector

ProcGuard receives exec events before a payload gets going, and reads CPU and memory straight from cgroup files instead of spawning docker stats.

self-protection

The binary is marked immutable, hashed, and watched. Tampering with the config, authorized_keys or cron raises an immediate alert.

Requirements

What your node needs

Operating system
Debian 11+
Ubuntu 20.04+, RHEL 8+
Panel
Pterodactyl 1.x
Wings on the same host
Toolchain
g++ 9 or newer
C++17, libcurl, OpenSSL
Runtime
root, MySQL
mysql client 5.7 or 8.0
The daemon must run on the host node, never inside the Wings container. On Debian 13 install rsyslog so /var/log/auth.log exists, and raise the inotify watch limit on panels with many servers.
Pricing

One licence. Every module.

There are no feature tiers to upgrade through. The binary ships every module, so a licence unlocks all 13 of them — you choose the term and how many nodes may hold it at once.

Questions

Licence questions, answered plainly

How many nodes does one voucher cover?

One node at a time by default. The number of simultaneous bindings is configured per voucher, and the daemon's own model is single-node: to move, release the old node first with /sentinelx deactivate, then activate on the new one.

What happens at the next revalidation?

The daemon revalidates every 24 hours. If the licence has been revoked or has expired, it logs the reason and shuts down after a 60 second countdown. Protection stops; your binary, config and panel are left untouched.

If I revoke a licence, does the node stop immediately?

No. A node that already activated keeps running until its next revalidation, which can be up to 24 hours away, because activation checks the local signed licence file first and does not call the server. If you need an immediate stop, ask the customer to run the deactivate command, or plan revocations with that delay in mind.

What happens after three wrong vouchers?

The daemon clears its own immutable flag, deletes its binary and exits. Nothing else on the host is touched. Reinstall from the repository to continue — this is why verifying the code here first matters.

Which modules are not finished yet?

Being straight about it: GeoIP currently labels alerts with the attacker's country but does not enforce a country block; the abuse tracker does not record events yet; and threat-intel sharing covers SSH brute-force IPs only, and a shared IP annotates alerts on the peer rather than blocking there. Each is marked 2 partial and 1 in development above.

Do I need Pterodactyl API tokens?

No. SentinelX reads the panel database and calls the Docker CLI directly. Database credentials are read from your panel .env, so there is nothing extra to create and nothing extra to leak.

What data does my node send you?

A machine fingerprint, the requesting IP, the voucher code and the outcome of each activation. No panel contents, no game data, no customer files. The full list is in the Privacy Policy.