Back to Work/SentinelLite AI
Cybersecurity CLI2026

SentinelLite AI

A beta-stage defensive Linux endpoint observation and report-review CLI that generates local JSON alert reports and static dashboard views for security learning.

PythonLinuxCybersecurityBlue TeamCLIJSON ReportsStatic DashboardRule-Based DetectionRisk Scoring
Overview

What is this project?

SentinelLite AI is a beta-stage defensive Linux endpoint observation and report-review CLI that generates local JSON alert reports and static dashboard views for security learning. The v1.2.0-beta release adds the local static dashboard milestone, package artifacts, validation workflow, and stronger documentation around safe local usage.

Project Type

Cybersecurity CLI

Year

2026

Status

v1.2.0-beta

My Role

I designed, developed, tested, validated, and released the entire project independently — including the CLI architecture, detection pipeline, scoring engine, report system, static dashboard export, package artifacts, CI/CD workflows, cross-platform validation, and public GitHub pre-release.

The Challenge

What made this difficult?

The main challenge was building a transparent, deterministic detection and scoring pipeline that produces meaningful security insights without relying on external services, cloud APIs, or AI/LLM models. Every detection rule, risk score calculation, and report output needed to be fully explainable and reproducible locally. The v1.2.0-beta release added static dashboard generation and package artifact workflows while preserving this deterministic foundation.

Pipeline

Detection Pipeline

Observe
Normalize
Detect
Score
Explain
Report
Review
Dashboard
Features

What I Built

Local on-demand Linux endpoint observation CLI

Authentication log analysis

Process and active network connection observation

Selected file integrity checks

Baseline-backed file integrity comparison

Rule-based detection and deterministic risk scoring

Local JSON alert reports

Local report history and review workflow

Deterministic local alert explanations

Static local dashboard export

TOML config/module gating

Package artifacts with SHA256 hashes

GitHub Actions CI with Python 3.11 and 3.14 validation

652 automated tests passed

Validation

Testing & Validation

652 automated tests passed
Ruff linting passed
pip check passed
GitHub Actions CI passed
Python 3.11 and Python 3.14 CI validation
macOS Apple Silicon validation
Ubuntu ARM64 validation
Package artifacts rebuilt and validated
SHA-256 checksums generated
Public GitHub pre-release v1.2.0-beta
Distribution

v1.2.0-beta • Public GitHub Pre-release

Not yet published to PyPI. Install from GitHub release artifacts.

Transparency

Safety Boundaries & Limitations

SentinelLite AI is beta-stage software for local defensive security learning. It is not a production EDR, antivirus, SIEM/SOC platform, malware remover, real AI/LLM-powered system, public scanner, background monitor, exploit tool, or automatic remediation tool.

Not a production EDR, antivirus, malware remover, SIEM, SOC platform, or enterprise-ready product
Not real AI/LLM-powered
Not PyPI-published yet
Not an automatic protection system
Does not run as a daemon or background service
Does not perform active network scanning or probing
Does not send packets or exploit systems
Does not perform automatic remediation
Does not terminate processes, block IPs, modify firewall rules, or delete/repair files
Does not send external notifications
Gallery

Project Screenshots

SentinelLite AI project journey from v0.1.0-alpha to v1.2.0-beta

Project Journey — Alpha to v1.2.0-beta

SentinelLite AI v1.2.0-beta validation — 652 tests passed, CI success

v1.2.0-beta Validation Summary

SentinelLite AI static dashboard export workflow

Static Dashboard Export Workflow

Outcome

What I Learned

SentinelLite AI reached its v1.2.0-beta public pre-release with 652 automated tests passing, full CI/CD validation on Python 3.11 and Python 3.14, static dashboard export, package artifacts with SHA-256 checksums, and a clean GitHub pre-release. It demonstrates practical defensive security engineering concepts, detection pipeline design, static dashboard generation, and disciplined software release practices.