Start / Virtnosis Docs

Virtnosis Docs

Virtnosis is a read-only libvirt security analysis and diagnosis toolset.

It is built for operators, responders, and automation that need to inspect libvirt-exposed infrastructure without mutating host or guest state. Public binaries:

Use it only on systems you own or are explicitly authorized to assess.

Operating model#

Virtnosis is:

  • local-first and UNIX-socket-first,
  • read-only by default,
  • bounded in memory, output size, and scan timing,
  • explicit about partial and unavailable scan stages,
  • designed to emit stable machine-consumable output.

The control plane is local UNIX sockets only. Remote transports are not part of the public product surface.

Quick start#

Assume virtnosis-agent and vnactl are installed and available on your PATH.

virtnosis-agent --verbose
vnactl status
vnactl scan --deep --confirm-xml --redact
  1. Getting Started
  2. Install and Package
  3. Operator Guide
  4. Deployment Guide
  5. Systemd Guide
  6. vnactl
  7. virtnosis-agent
  8. Scan Analysis
  9. Architecture
  10. Repository Documents
  11. Man pages

Docs map#

Source repository · Edit this page · View Markdown