Sentinel Active Protection
Sentinel is the automatic protection module for Security Center. It can intercept an ordinary attack and give you time to react, even while you are logged out.
Publisher
Vesper Signal is the fictional publisher of this application. The publisher button in the App Store opens its company website in Interwebs. You can also find the company through Elgoog. Its operations server is part of the game world and runs active defenses. Investigating it can uncover internal correspondence and further leads.
Activation and payment
You need an active Security Center subscription. Sentinel initially costs an additional $5,000 in-game money per week, per server, initially $7,000 for both modules. The App Store shows your binding price and payment account. Adding it during a paid week only charges for the remaining part of that shared week.
Download both applications and explicitly start Sentinel in Security Center. Keep the matching defense software running too. Stopping Sentinel releases its resources but does not cancel its subscription. You can cancel the add-on separately for the end of the paid week.
Which defense protects against what?
| Attack | Running defense |
|---|---|
| Brute force using a cracker | Hasher |
| FTP or SSH exploit | Firewall |
| Ordinary virus installation | Antivirus |
A stronger matching defense compared with the attack improves your interception chance. Equal versions give a 25% chance; the maximum is 60%. Without the matching running program, there is no interception attempt. Never rely on Sentinel alone.
A successful interception pauses the attack for 60 seconds and raises an alarm. An intercepted virus installation does not become effective during this pause. Use the time to start lockdown or actively defend your nodes.
There is at most one interception attempt per attack. Reloading or restarting Sentinel does not grant another attempt. Replacing an attack against the same server cannot bypass an existing pause for that attacker.
Limits and resources
Sentinel initially reserves 5% CPU and 32 MB RAM. An active lockdown needs additional resources. Task Manager shows current usage.
Sentinel does not check DDoS attacks, bank or wallet access, Doom actions or control-node intrusions. It does not remove existing access or infections. Losing your Control node ends existing Sentinel pauses and suppresses Sentinel and lockdown for two minutes.
An expired subscription prevents new interceptions, but an already triggered pause may finish. During emergency reboot the service is offline.
Alarms and optional email
A successful interception raises an in-game alarm. Under Settings → Notifications, you can also enable email alerts. Your email address must be verified. This option is off by default.
Email identifies the affected server and detected attack type. Additional interceptions within ten minutes are grouped. Alerts never reveal unknown attacker addresses or software versions.
Console
| Action | Kali | PowerShell | Simple mode |
|---|---|---|---|
| Start | rebels security start | Start-TRSentinel | security start |
| Stop | rebels security stop | Stop-TRSentinel | security stop |
| Events | rebels security events | Get-TRSecurityEvent | security events |