The condensed version lives here. The full reference — every flag, every config key — ships in the repo under docs/.
Install in trial (observation-only) mode:
Check status, then move to production when ready:
| Flag | Used with | Purpose |
|---|---|---|
| --key | install.sh | Your API key (required) |
| --iface | install.sh | Network interface to attach to (auto-detected if omitted) |
| --mode | install.sh | trial (default) or production |
| --api-base | both | Point at a self-hosted Detection API instead of api.prosentriq.com |
| --state-dir / --log-dir | both | Override /etc/prosentriq / /var/log/prosentriq (mainly for testing) |
| --dry-run | install.sh | Validate everything, make zero system changes |
Base URL: https://api.prosentriq.com (or your self-hosted instance).
| Route | Method | Purpose |
|---|---|---|
| /v1/signup | POST | Create an account, get an API key |
| /v1/account/status | GET | Confirm a key and its tier/enforcement permission |
| /v1/account/recover | POST | Rotate a lost key (emailed, not returned in the response, when SMTP is configured) |
| /v1/reputation/check | POST | Score a source IP |
| /v1/events/correlate | POST | Feed an observed event into threat correlation |
| /v1/rules/recommend | POST | Get a genetic-algorithm-recommended rule for an IP |
| /v1/rules/evolve | POST | Run a generation of rule evolution |
Every account gets a rate limit appropriate to its tier; requests over the limit get a 429 with a Retry-After header, never a silent drop.
The kernel agent (eBPF probes, behavioral policy, genetic algorithm, honeypot, prosentriq-ctl) runs on your host and enforces locally. The Detection API (accounts, reputation scoring, Threat Hub, compliance reports) is a separate control-plane service — self-hostable, not a requirement for the agent's core loop to keep running.
Full component-by-component detail lives in docs/ARCHITECTURE.md in the repository, including how AccountManager reconciles the two.