csm

module
v0.0.0-...-2686ee4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: AGPL-3.0

README

CSM (Continuous Security Monitor)

Coverage Go version CodeQL OpenSSF Scorecard Go Reference Release

Local security monitoring and automated response for Linux web servers. First-class coverage for cPanel/WHM shared hosting, with platform-aware checks for Plesk, DirectAdmin, and panel-free hosts.

CSM combines real-time file, authentication, web, mail, and network watchers with scheduled integrity, account, content, and database scans. Content scanning pairs YAML and YARA-X signatures with data-flow analyzers for PHP and JavaScript, and an optional PHP Shield blocks webshell execution at runtime. State stays on the host. CSM exposes a Web UI and API, and can respond through nftables, quarantine, reversible virtual patches, mail controls, and targeted remediation.

Documentation | Installation | Configuration | CLI | Web UI | Releases

What CSM covers

Problem Detection and response
Mailbox takeover and outbound spam Mail log correlation, account attribution, filter and forwarder audit, PHP relay guard, blocking, mail freeze
WordPress and admin login attacks Login flood, XML-RPC, and credential-stuffing detection; bundled ModSecurity rules for exploited CVEs
Webshells, phishing, and injected code YAML and YARA-X signatures, PHP and JavaScript data-flow analysis, PHP Shield runtime blocking, quarantine
Exposed files and vulnerable software Probe-confirmed exposed dumps, backups, and repositories; known-vulnerable plugin inventory; reversible virtual patches
Vulnerability and URL scanners Per-source probe profiling, claimed-bot verification, ASN crawl detection, challenge routing, firewall response
Compromised CMS databases WordPress, Joomla, Drupal, Magento, OpenCart: stored code, hidden links, spam, doorways, rogue admins; reversible cleanup for supported rows and objects
WAF and firewall operations ModSecurity event correlation and per-domain coverage gaps, nftables, GeoIP, subnet escalation, rollback-confirmed changes
Host compromise indicators Process, account, SSH, cron, and package drift, C2 connections, BPF telemetry, hardening audit, CVE mitigations
Fleet observability HTTPS API, SSE findings, incidents, forensic snapshots, Prometheus, audit log, syslog, webhooks, SIEM backfill

Detailed coverage is documented under Real-time detection, Critical checks, Deep checks, and Incidents.

Platform support

Platform Coverage
cPanel/WHM on CloudLinux, AlmaLinux, or Rocky with Apache/LiteSpeed Primary target. Full account, WordPress, Exim, WHM plugin, firewall, PHP Shield (CageFS-aware on CloudLinux), and remediation coverage.
Plesk or DirectAdmin on a supported Linux distribution Panel and web-server paths are detected. Generic host/web checks run; cPanel-only integrations skip.
AlmaLinux, Rocky, RHEL, or CentOS Stream 8+ Generic checks with RPM integrity on Apache, Nginx, LiteSpeed, or hosts without a web server.
Ubuntu 20.04+ or Debian 11+ Generic checks with dpkg/debsums integrity on Apache, Nginx, LiteSpeed, or hosts without a web server.

Packages are published for x86_64 and ARM64; cPanel itself is x86_64-only. Release binaries link YARA-X statically, include journald and BPF support, and need glibc 2.28 or newer.

Quick start

Install from the signed APT or DNF repository described in the installation guide. Packages include the daemon, Web UI, rules, PAM module, systemd unit, and a csm command in /usr/sbin.

sudo vi /etc/csm/csm.yaml
sudo csm validate
sudo systemctl enable --now csm.service
sudo csm baseline
sudo csm doctor

Open https://<server>:9443/login. The package generates an initial admin token in /etc/csm/csm.yaml and a self-signed certificate under the state directory unless explicit TLS paths are configured.

The baseline signs the binary, csm.yaml, and every non-exempt conf.d drop-in. After a later hand edit, run sudo csm rehash before restarting: the daemon refuses a config it did not sign, and csm doctor reports the mismatch while the old daemon is still running. Automation-owned overrides go in /etc/csm/conf.d/*.yaml; see Configuration for merge order, trust, and integrity rules.

How it runs

  • Real-time watchers process filesystem, authentication, access-log, mail, PAM, BPF, and ModSecurity events.
  • Critical checks run every 10 minutes; deeper account, CMS, package, content, and database checks run every 60 minutes by default.
  • Eligible content and exposed-file findings are re-verified every deep-scan cycle. They clear only when the condition is confirmed gone. If flagged content is gone but its file changed, only a replacement proven inert is downgraded; uncertain cases stay open. See Re-verifying findings.
  • Signatures ship with the package: YAML rules cover real-time scanning and finding re-checks; optional YARA-X rules also cover scheduled and email attachment scanning. Remote YAML and optional YARA Forge updates are signature-verified.
  • Platform detection picks the OS, control panel, web server, paths, logs, and applicable checks. Panel-specific checks skip where their panel is absent.
  • State is stored in bbolt with optional retention sweeps, automatic compaction, backup/restore, and audit export.
  • CSM has no required SaaS dependency. External reputation, GeoIP, reporting, and panel integrations are optional.

Safety defaults

  • mode: observe runs detection and alerting without automatic host remediation or integration updates, and refuses a config that still enables a state-changing subsystem. See Observe mode.
  • Auto-response is disabled until explicitly enabled.
  • Automatic IP and subnet blocking starts in dry-run unless auto_response.dry_run: false is explicit. This is a network-response guard, not a universal simulation mode for file cleanup or process actions.
  • Exposed-file virtual patches are off by default. Set manual mode to preview or apply them by hand. Automatic mode also requires auto-response and honors its dry-run setting.
  • BPF enforcement and PHP-relay freezing have their own dry-run controls.
  • Infrastructure, local, allowed, and verified-bot addresses are protected from automatic blocking.
  • Process termination excludes root and recognized system services.
  • Quarantine preserves the original path, ownership, permissions, and mtime for restoration.
  • Firewall configuration can be applied with a confirmation timer and automatic rollback.

Review Auto-response before enabling actions on a production host.

Common commands

csm status [--json]          daemon health, findings, watchers, and rollout state
csm doctor [--json]          config, integrity, daemon, watcher, and store diagnostics
csm privileges [--json]      what CSM does that needs privilege, and the key that stops each one
csm actions [--since 24h]    what CSM did to this host, with before/after digests on file changes
csm selftest                 scan known samples and report what the installed rules catch
csm baseline                 establish known state after first start or an approved reset
csm rehash                   re-sign binary, csm.yaml, and conf.d after an intentional change
csm scan <user> [--full]     scan one account, uncapped with --full
csm scan --all --full        scan every account without the per-account file cap
csm incidents ...            list, show, and update correlated incidents
csm firewall ...             inspect and manage IP, subnet, port, and rollback state
csm virtual-patch [--apply]  preview or apply confirmed exposed-file denies in manual/auto mode
csm harden ...               audit or apply supported host mitigations

See the CLI reference for backup and restore, forensic snapshots, PHP Shield, cleanup, and the full operator command reference.

Development

go build ./...                         # standard build with YARA stubs
go build -tags yara ./cmd/csm/         # local YARA-X build; link the version pinned in go.mod
go test ./... -count=1 -race
go test -run=Fuzz ./...
make lint
make ci

See CONTRIBUTING.md and the development guide. Public releases land on GitHub; packaging and integration tests run through GitLab CI. Each release page leads with highlights and security fixes, and the full record is in CHANGELOG.md.

License

CSM is licensed under AGPL-3.0-or-later. Releases through v2.x remain under the MIT License; v3.0.0 and newer use AGPL-3.0-or-later.

See LICENSE, SECURITY.md, and CHANGELOG.md.

Directories

Path Synopsis
cmd
csm command
internal
actionlog
Package actionlog records what CSM did to a host, as opposed to what it found.
Package actionlog records what CSM did to a host, as opposed to what it found.
atomicio
Package atomicio implements atomic file writes used by state-bearing callers (firewall engine, autoblock tracker, etc.).
Package atomicio implements atomic file writes used by state-bearing callers (firewall engine, autoblock tracker, etc.).
blockdigest
Package blockdigest batches CSM auto-block events into a per-country roll-up so operators learn when IPs from their customers' countries get blocked.
Package blockdigest batches CSM auto-block events into a per-country roll-up so operators learn when IPs from their customers' countries get blocked.
bpf
Package bpf provides the shared scaffolding that BPF-backed live monitors across the daemon use: a common Backend interface, backend-kind constants for operator config, sentinel errors that distinguish "not built" from "kernel unsupported", and a per-feature backend metric.
Package bpf provides the shared scaffolding that BPF-backed live monitors across the daemon use: a common Backend interface, backend-kind constants for operator config, sentinel errors that distinguish "not built" from "kernel unsupported", and a per-feature backend metric.
broadcast
Package broadcast provides a one-to-many publish bus for alert.Finding events.
Package broadcast provides a one-to-many publish bus for alert.Finding events.
checks
HTTP abuse detection.
HTTP abuse detection.
cms
Package cms is the single declaration of the content management systems CSM supports.
Package cms is the single declaration of the content management systems CSM supports.
contenttype
Package contenttype classifies file content shared by the malware scanners.
Package contenttype classifies file content shared by the malware scanners.
control
Package control defines the wire protocol between the CSM daemon and its local command-line client.
Package control defines the wire protocol between the CSM daemon and its local command-line client.
corpusgate
Package corpusgate provisions pinned clean applications for detector tests.
Package corpusgate provisions pinned clean applications for detector tests.
daemon/af_alg_bpfprog
Package af_alg_bpfprog hosts the BPF C source for the AF_ALG (CVE-2026-31431 "Copy Fail") kernel-side deny program and the generated Go bindings produced by bpf2go.
Package af_alg_bpfprog hosts the BPF C source for the AF_ALG (CVE-2026-31431 "Copy Fail") kernel-side deny program and the generated Go bindings produced by bpf2go.
daemon/connection_bpfprog
Package connection_bpfprog hosts the BPF C source for the cgroup/connect outbound-connection tracker and the generated Go bindings produced by bpf2go.
Package connection_bpfprog hosts the BPF C source for the cgroup/connect outbound-connection tracker and the generated Go bindings produced by bpf2go.
daemon/exec_bpfprog
Package exec_bpfprog hosts the BPF C source for the sched/sched_process_exec tracepoint live monitor and the generated Go bindings produced by bpf2go.
Package exec_bpfprog hosts the BPF C source for the sched/sched_process_exec tracepoint live monitor and the generated Go bindings produced by bpf2go.
daemon/sensitive_file_bpfprog
Package sensitive_file_bpfprog hosts the BPF C source for the lsm/file_permission live monitor and the generated Go bindings produced by bpf2go.
Package sensitive_file_bpfprog hosts the BPF C source for the lsm/file_permission live monitor and the generated Go bindings produced by bpf2go.
eximlog
Package eximlog extracts the connecting client from Exim main log lines.
Package eximlog extracts the connecting client from Exim main log lines.
firewall/rollback
Package rollback implements the firewall settings tentative-apply workflow: a save with a deadline that auto-reverts unless the operator confirms before the timer expires.
Package rollback implements the firewall settings tentative-apply workflow: a save with a deadline that auto-reverts unless the operator confirms before the timer expires.
forensic
Package forensic produces evidence archives for incident response.
Package forensic produces evidence archives for incident response.
geoip
Package geoip provides IP geolocation via MaxMind GeoLite2 databases and on-demand RDAP lookups for detailed ISP/org information.
Package geoip provides IP geolocation via MaxMind GeoLite2 databases and on-demand RDAP lookups for detailed ISP/org information.
incident
Package incident groups related security findings into a single "story" with a timeline.
Package incident groups related security findings into a single "story" with a timeline.
integration/webserver
Package webserver auto-installs the CSM challenge webserver glue (Apache / LSWS / Nginx) with a write-validate-reload-or-revert flow.
Package webserver auto-installs the CSM challenge webserver glue (Apache / LSWS / Nginx) with a write-validate-reload-or-revert flow.
jstaint
Package jstaint reports keystroke values that reach a network sink in a JavaScript source file.
Package jstaint reports keystroke values that reach a network sink in a JavaScript source file.
log
Package log provides a structured-logging wrapper around log/slog.
Package log provides a structured-logging wrapper around log/slog.
mailfwd/adapter
Package adapter renders and applies the MTA-native forward-guard rule.
Package adapter renders and applies the MTA-native forward-guard rule.
mailfwd/guard
Package guard glues the operator config to the pure forward-guard policy.
Package guard glues the operator config to the pure forward-guard policy.
mailfwd/intel
Package intel turns exim_mainlog deferral lines into operator-facing reputation signals: which outbound IPs are being throttled, by which mail providers, and for what stated reason.
Package intel turns exim_mainlog deferral lines into operator-facing reputation signals: which outbound IPs are being throttled, by which mail providers, and for what stated reason.
mailfwd/inventory
Package inventory enumerates mail forwarders on a host and classifies their destinations, so operators can see which accounts relay mail off-server and to which providers.
Package inventory enumerates mail forwarders on a host and classifies their destinations, so operators can see which accounts relay mail off-server and to which providers.
mailfwd/policy
Package policy is the single source of truth for the forward-guard hold decision: given the signals observed for a message, should the external forward copy be held? The same Verdict function feeds both the dry-run "would-hold" accounting and (in Phase 2) the generated MTA rule, so the two can never drift apart.
Package policy is the single source of truth for the forward-guard hold decision: given the signals observed for a message, should the external forward copy be held? The same Verdict function feeds both the dry-run "would-hold" accounting and (in Phase 2) the generated MTA rule, so the two can never drift apart.
mailfwd/quarantine
Package quarantine is the CSM-owned Maildir that holds external forward copies the forward-guard decided to withhold.
Package quarantine is the CSM-owned Maildir that holds external forward copies the forward-guard decided to withhold.
maillog
Package maillog reads postfix/dovecot log lines from either a tailed file or systemd-journald, normalizing them into a single Line type so the daemon's mail-brute and PHP-relay parsers don't have to care which source supplied the line.
Package maillog reads postfix/dovecot log lines from either a tailed file or systemd-journald, normalizing them into a single Line type so the daemon's mail-brute and PHP-relay parsers don't have to care which source supplied the line.
mailranges
Package mailranges maintains an atomic in-memory map of mail-provider IP ranges used to exempt shared-source ranges (carrier CGNAT, mail providers) from firewall DoS heuristics.
Package mailranges maintains an atomic in-memory map of mail-provider IP ranges used to exempt shared-source ranges (carrier CGNAT, mail providers) from firewall DoS heuristics.
metrics
Package metrics is CSM's local OpenMetrics implementation.
Package metrics is CSM's local OpenMetrics implementation.
mysqlclient
Package mysqlclient wraps the database/sql + go-sql-driver/mysql pair for the read-only queries CSM issues against host-local MySQL/MariaDB.
Package mysqlclient wraps the database/sql + go-sql-driver/mysql pair for the read-only queries CSM issues against host-local MySQL/MariaDB.
netutil
Package netutil holds the shared public-range guard used to validate operator- and vendor-supplied IP ranges.
Package netutil holds the shared public-range guard used to validate operator- and vendor-supplied IP ranges.
obs
Package obs centralises crash reporting and selective error capture via Sentry.
Package obs centralises crash reporting and selective error capture via Sentry.
phptaint
Package phptaint reports remotely-fetched content that reaches a PHP code-execution sink.
Package phptaint reports remotely-fetched content that reaches a PHP code-execution sink.
phptaintipc
Package phptaintipc defines the wire protocol spoken between the CSM daemon and the supervised `csm phptaint-worker` child process.
Package phptaintipc defines the wire protocol spoken between the CSM daemon and the supervised `csm phptaint-worker` child process.
phptaintworker
Package phptaintworker is the child side of PHP taint analysis.
Package phptaintworker is the child side of PHP taint analysis.
platform
Package platform detects the host OS, control panel, and web server so CSM checks can pick the right config/log paths instead of hardcoding cPanel+Apache layouts.
Package platform detects the host OS, control panel, and web server so CSM checks can pick the right config/log paths instead of hardcoding cPanel+Apache layouts.
privops
Package privops is the inventory of every CSM operation that needs privilege beyond reading its own files, or that writes outside CSM's own directories.
Package privops is the inventory of every CSM operation that needs privilege beyond reading its own files, or that writes outside CSM's own directories.
processctx
Package processctx maintains process context (PID/PPID/UID/account/exe/cmdline) for use enriching real-time security findings.
Package processctx maintains process context (PID/PPID/UID/account/exe/cmdline) for use enriching real-time security findings.
processhandle
Package processhandle signals verified Linux processes through kernel handles.
Package processhandle signals verified Linux processes through kernel handles.
quarantinefs
Package quarantinefs makes recovery copies durable before callers change live files.
Package quarantinefs makes recovery copies durable before callers change live files.
queuehealth
Package queuehealth measures waiting, running and lost work independently of the channel that carries findings about a protection failure.
Package queuehealth measures waiting, running and lost work independently of the channel that carries findings about a protection failure.
redisinfo
Package redisinfo wraps the go-redis client for the few read-only INFO calls CSM needs (memory metrics, keyspace counts).
Package redisinfo wraps the go-redis client for the few read-only INFO calls CSM needs (memory metrics, keyspace counts).
reporting
Package reporting is the node side of CSM abuse reporting (Layer A).
Package reporting is the node side of CSM abuse reporting (Layer A).
responsereplay
Package responsereplay replays recorded finding streams through models of the automatic response admission path, so capacity and fairness changes can be measured against what hosts actually saw.
Package responsereplay replays recorded finding streams through models of the automatic response admission path, so capacity and fairness changes can be measured against what hosts actually saw.
safepath
Package safepath pins directories for operations on tenant-controlled names.
Package safepath pins directories for operations on tenant-controlled names.
sdnotify
Package sdnotify talks to the systemd notification socket.
Package sdnotify talks to the systemd notification socket.
selftest
Package selftest runs CSM's detection over a small bundle of samples whose verdicts are known, so an operator can see what the shipped rules catch without pointing the scanner at a production account.
Package selftest runs CSM's detection over a small bundle of samples whose verdicts are known, so an operator can see what the shipped rules catch without pointing the scanner at a production account.
session
Package session owns browser-session identities and their storage contract.
Package session owns browser-session identities and their storage contract.
sshdconf
Package sshdconf reads the effective sshd_config the way sshd itself does: Include directives are followed, Match blocks are ignored because their directives are connection-scoped, and most keywords keep first-match-wins semantics.
Package sshdconf reads the effective sshd_config the way sshd itself does: Include directives are followed, Match blocks are ignored because their directives are connection-scoped, and most keywords keep first-match-wins semantics.
systemdrun
Package systemdrun builds argv for running a command outside the calling service's systemd sandbox.
Package systemdrun builds argv for running a command outside the calling service's systemd sandbox.
threatintel
Package threatintel -- bot allowlist + verification.
Package threatintel -- bot allowlist + verification.
updatecheck
Package updatecheck polls upstream release channels and tells the daemon whether a newer CSM version is available so the Web UI can surface a banner.
Package updatecheck polls upstream release channels and tells the daemon whether a newer CSM version is available so the Web UI can surface a banner.
verdict
Package verdict implements an HMAC-signed HTTP client for the auto_response.verdict_callback hook.
Package verdict implements an HMAC-signed HTTP client for the auto_response.verdict_callback hook.
yaraipc
Package yaraipc defines the wire protocol spoken between the CSM daemon and the supervised `csm yara-worker` child process.
Package yaraipc defines the wire protocol spoken between the CSM daemon and the supervised `csm yara-worker` child process.
yaraworker
Package yaraworker implements the `csm yara-worker` subcommand: a child process that exists only to host the YARA-X cgo surface and reply to scan requests over a Unix socket.
Package yaraworker implements the `csm yara-worker` subcommand: a child process that exists only to host the YARA-X cgo surface and reply to scan requests over a Unix socket.
scripts
clean-corpus command
correlation-calibrate command
Package main replays a recorded finding stream through the production cross-account correlation so its thresholds can be re-derived against what hosts actually produced, instead of against an assumption.
Package main replays a recorded finding stream through the production cross-account correlation so its thresholds can be re-derived against what hosts actually produced, instead of against an assumption.
finding-stream command
Command finding-stream turns CSM audit logs into an anonymized finding stream for correlation and threshold calibration, optionally joined with the action log and the firewall audit log.
Command finding-stream turns CSM audit logs into an anonymized finding stream for correlation and threshold calibration, optionally joined with the action log and the firewall audit log.
fixturecheck command
fixturecheck rejects non-documentation IPv4 literals in repository fixtures.
fixturecheck rejects non-documentation IPv4 literals in repository fixtures.
queuegate command
queuegate checks reviewed queue ownership and emits required execution tests.
queuegate checks reviewed queue ownership and emits required execution tests.
response-replay command
Command response-replay replays a recorded finding stream through a model of the legacy scan admission path (the hourly block limit, the pending queue and the temporary deny limit) and writes an aggregate report.
Command response-replay replays a recorded finding stream through a model of the legacy scan admission path (the hourly block limit, the pending queue and the temporary deny limit) and writes an aggregate report.
testgate command
testgate records selected tests and verifies that go test executed them.
testgate records selected tests and verifies that go test executed them.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL