In Progress
- Publish completed Argus findings to the shared Sentinel Operations Graph (SOG)
- Update entity security posture from high-confidence Argus decisions
- Preserve local Argus operation when shared platform services are unavailable
- Normalize Argus security events for Sentinel's cross-agent orchestration
- Correlate Argus threats with Phoenix failure and recovery evidence
- Surface cross-domain incident chains and fleet risk in Sentinel
Related repositories: Sentinel, Phoenix, and Sentinel Platform.
Complete
OrbStack VMs, k3s, Cilium eBPF networking, Hubble flow observability, namespace setup.
Complete
Falco runtime detection via eBPF, Kyverno admission control with three enforced policies, CiliumNetworkPolicies for zero-trust namespace segmentation.
Complete
Prometheus metrics collection, Grafana dashboards (25 default K8s dashboards + 4 custom Argus security views), Loki log aggregation with Promtail DaemonSet, Falco JSON pipeline into Loki.
Complete
Falco webhook receiver, context enricher (kubectl + Loki + Hubble + Kyverno), OpenAI Responses API reasoning with structured decision output, action router (LOG / NOTIFY / ISOLATE / KILL / HUMAN_REQUIRED), audit logger, and containerized deployment with RBAC.
In Progress
- Command center — live KPIs, detection pipeline flow, cluster node health
- Threat feed — real-time incident cards with detail panel, recommended actions, inline chat
- Attack chains — correlated multi-stage attack paths
- Cluster map — visual node/pod topology with threat status overlay
- Security posture — incident summary, secret scanning, CVE exposure, compliance signals
- Approval queue — human review workflow for low-confidence automated actions
- Agent chat — conversational queries about current cluster security state
- OpenAI-powered incident summaries, threat hunting, forecasting, and operator chat
- Infrastructure observability — node metrics and resource usage
- React + TypeScript + Tailwind
- Recharts for metrics visualization
- FastAPI backend shared with the detection agent
Planned
- Deeper kernel-level instrumentation for syscall patterns
- Process lineage tracking across container restarts
- Memory-based threat detection (fileless execution patterns)
Planned
- Attack chain detection — correlate sequences of events from the same pod or namespace
- Suppression learning — recognize recurring false positives and reduce noise automatically
- Image reputation scoring — Trivy CVE scan integrated into threat confidence score
- Composite severity scoring — combines namespace risk, blast radius, recurrence, and image age
Planned
- SPIFFE/SPIRE workload identity
- Image signing verification at admission
- SBOM generation and dependency tracking
Planned
- Behavioral baseline dashboards — deviation from normal traffic patterns
- Attack chain timeline view — visual sequence of correlated events
- Expanded cluster topology map with real-time flow overlays