Hostname: Work SHiREVault: /mnt/shirevault-network //192.168.1.1/volume(sda2) cifs Continuing evidence folder: /SHiREVault/Backup/OSBackups/SHIRE-SENTINEL-HOST-PROTECTION-20260801T100913Z === CURRENT PROTECTION STATE === auditd.service enabled=enabled active=active fail2ban.service enabled=enabled active=active clamav-freshclam.service enabled=enabled active=active clamav-daemon.service enabled=enabled active=active clamav-daemon.socket enabled=enabled active=active === INSTALLING MISSING CLAMAV SCAN CLIENT === Reading package lists... Building dependency tree... Reading state information... Suggested packages: clamav-doc The following NEW packages will be installed: clamdscan 0 upgraded, 1 newly installed, 0 to remove and 2 not upgraded. Need to get 60.6 kB of archives. After this operation, 238 kB of additional disk space will be used. Get:1 https://ubuntu.mirror.serversaustralia.com.au/ubuntu noble-updates/main amd64 clamdscan amd64 1.5.3+dfsg-0ubuntu0.24.04.1 [60.6 kB] Fetched 60.6 kB in 0s (141 kB/s) Selecting previously unselected package clamdscan. (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 628128 files and directories currently installed.) Preparing to unpack .../clamdscan_1.5.3+dfsg-0ubuntu0.24.04.1_amd64.deb ... Unpacking clamdscan (1.5.3+dfsg-0ubuntu0.24.04.1) ... Setting up clamdscan (1.5.3+dfsg-0ubuntu0.24.04.1) ... Processing triggers for man-db (2.12.0-4build2) ... Running kernel seems to be up-to-date. The processor microcode seems to be up-to-date. No services need to be restarted. No containers need to be restarted. No user sessions are running outdated binaries. No VM guests are running outdated hypervisor (qemu) binaries on this host. PASS: clamdscan package installed: 1.5.3+dfsg-0ubuntu0.24.04.1 /usr/bin/clamdscan === VERIFYING CLAMAV SIGNATURE DATABASES === bytecode.cvd 281702 bytes daily.cvd 23422181 bytes main.cvd 89072577 bytes PASS: ClamAV database count: 3 === ENSURING CLAMAV SERVICES ARE ACTIVE === Synchronizing state of clamav-freshclam.service with SysV service script with /usr/lib/systemd/systemd-sysv-install. Executing: /usr/lib/systemd/systemd-sysv-install enable clamav-freshclam Synchronizing state of clamav-daemon.service with SysV service script with /usr/lib/systemd/systemd-sysv-install. Executing: /usr/lib/systemd/systemd-sysv-install enable clamav-daemon /tmp/shire-sentinel-clamav-fix.OOoMdL/shire-sentinel-clean-test.txt: OK ----------- SCAN SUMMARY ----------- Infected files: 0 Time: 0.011 sec (0 m 0 s) Start Date: 2026:08:01 18:13:31 End Date: 2026:08:01 18:13:31 PASS: ClamAV daemon completed a clean-file scan. === VERIFYING AUDITD === enabled 1 failure 1 pid 553927 rate_limit 0 backlog_limit 8192 lost 0 backlog 0 backlog_wait_time 60000 backlog_wait_time_actual 0 loginuid_immutable 0 unlocked -w /etc/passwd -p wa -k identity_changes -w /etc/group -p wa -k identity_changes -w /etc/shadow -p wa -k identity_changes -w /etc/gshadow -p wa -k identity_changes -w /etc/sudoers -p wa -k privilege_changes -w /etc/sudoers.d -p wa -k privilege_changes -w /etc/ssh/sshd_config -p wa -k ssh_configuration -w /etc/ssh/sshd_config.d -p wa -k ssh_configuration -w /etc/systemd/system -p wa -k service_configuration -w /home/shire3d/ARMOR/modules/sentinel.py -p wa -k sentinel_code -w /home/shire3d/ARMOR/services/security_service.py -p wa -k sentinel_code -w /home/shire3d/ARMOR/sentinel -p wa -k sentinel_configuration PASS: Auditd and Sentinel audit watches are active. === VERIFYING FAIL2BAN === Server replied: pong Status for the jail: sshd |- Filter | |- Currently failed: 0 | |- Total failed: 0 | `- Journal matches: _SYSTEMD_UNIT=sshd.service + _COMM=sshd `- Actions |- Currently banned: 0 |- Total banned: 0 `- Banned IP list: PASS: Fail2ban SSH protection is active. === VERIFYING AUTOMATIC SECURITY UPDATES === NEXT LEFT LAST PASSED UNIT ACTIVATES Sat 2026-08-01 18:24:52 AWST 11min Sat 2026-08-01 09:45:56 AWST 8h ago apt-daily.timer apt-daily.service Sun 2026-08-02 06:04:02 AWST 11h Sat 2026-08-01 06:45:34 AWST 11h ago apt-daily-upgrade.timer apt-daily-upgrade.service 2 timers listed. Pass --all to see loaded but inactive timers, too. === FINAL SERVICE VERIFICATION === SERVICE ENABLED ACTIVE ------- ------- ------ auditd.service enabled active fail2ban.service enabled active clamav-freshclam.service enabled active clamav-daemon.service enabled active clamav-daemon.socket enabled active === CONFIRMING NETWORK CONTROLS REMAIN UNCHANGED === Status: inactive Suricata enabled: disabled Suricata active: inactive PASS: UFW was not enabled by this recovery. PASS: Suricata remains dormant. === EVIDENCE INTEGRITY === dd1c4524d53a7ad10c908000b9ce858103c094b420a120846c561e91ea412f4d /SHiREVault/Backup/OSBackups/SHIRE-SENTINEL-HOST-PROTECTION-20260801T100913Z/recovery-files.sha256 ============================================================ SHiRE SENTINEL HOST PROTECTION COMPLETE ============================================================ Evidence: /SHiREVault/Backup/OSBackups/SHIRE-SENTINEL-HOST-PROTECTION-20260801T100913Z Auditd: active Fail2ban SSH jail: active ClamAV signatures: installed ClamAV updater: active ClamAV daemon and socket: active ClamAV clean-file scan: passed Automatic security-update timers: active UFW: unchanged Suricata: still dormant DNS and router settings: unchanged