Virtnosis Docs
Virtnosis is a read-only libvirt security analysis and diagnosis toolset.
It is built for operators, responders, and automation that need to inspect libvirt-exposed infrastructure without mutating host or guest state. Public binaries:
virtnosis-agent— the local control-plane daemonvnactl— the operator and automation client
Use it only on systems you own or are explicitly authorized to assess.
Operating model#
Virtnosis is:
- local-first and UNIX-socket-first,
- read-only by default,
- bounded in memory, output size, and scan timing,
- explicit about partial and unavailable scan stages,
- designed to emit stable machine-consumable output.
The control plane is local UNIX sockets only. Remote transports are not part of the public product surface.
Quick start#
Assume virtnosis-agent and vnactl are installed and available on your PATH.
virtnosis-agent --verbose
vnactl status
vnactl scan --deep --confirm-xml --redact
Recommended reading path#
- Getting Started
- Install and Package
- Operator Guide
- Deployment Guide
- Systemd Guide
vnactlvirtnosis-agent- Scan Analysis
- Architecture
- Repository Documents
- Man pages
Docs map#
- Guides — build, install, deployment, systemd, operator workflows, and automation.
- CLI — the exact public surface of
vnactlandvirtnosis-agent. - Reference — product model, scan semantics, architecture, contributor docs, and the repository documentation map.
- Man pages —
virtnosis-agent(1),vnactl(1),virtnosis(7),virtnosis-agent-protocol(7), andvirtnosis-scan-report(7).
Source repository · Edit this page · View Markdown