How I Actually Use The Armour Of Light In Production Environments

The Armour Of Light is an open-source behavioral detection and containment toolkit that monitors process chains, network anomalies, and file-system activity in real time. It was originally built by a small team in 2021 after they noticed most endpoint detection tools were still relying heavily on static signatures. The approach shifted toward modeling what normal activity looks like for each host, then flagging deviations. It isn't an EDR replacement. It sits alongside your existing tooling and feeds into it. I usually pull the latest release from the GitHub repository. The installation script handles dependencies automatically on Ubuntu and Debian systems, though I've seen it struggle on minimal containers where libc versions are older than 2.31. Run the installer with the --dry-run flag first. It will show you which kernel modules it needs to load and whether your system's current settings will allow that. Skip that step and you might spend an hour debugging why no telemetry is being collected. After installation, the default configuration file lives at /etc/armour-of-light/config.yaml. The defaults are deliberately conservative. They catch obvious malware patterns but will generate significant noise if you don't tune them for your environment. I adjust the network_threshold variable early on. The default value of 50 connections per minute triggers too often on CI/CD servers that pull packages aggressively. I drop mine to 15 for build nodes and leave it at the default for workstations.

Telemetry goes to a local JSONL file by default. I redirect it to a SIEM collector using the built-in HTTP endpoint. You configure that in the output section of the config file. Make sure your SIEM can handle the volume before you point it there. I learned this the hard way. My Elasticsearch cluster had a 50GB index for a week before I realized the tool was generating roughly 40,000 events per hour across three medium-size servers. I added a sampling filter that keeps only events above a confidence threshold of 0.7, which brought the load down to about 3,000 events per hour. That cut my indexing costs without losing visibility into anything that actually mattered.

What The Tool Does Well And Where It Falls Apart

The strength of The Armour Of Light is in its behavioral models. It learns baselines over a warm-up period, which defaults to seven days. During that window, it records typical process execution trees, common network destinations, and expected file operations. After the baseline is established, it scores activity against it. A process spawning from a temp directory and immediately making outbound connections gets flagged differently than the same process running from /usr/bin. Here's something most people miss when they start using it. More detection rules do not equal better coverage. The tool uses ensemble scoring across multiple detection engines — behavioral deviation, pattern matching, reputation checks, and heuristic evaluation. Adding too many custom rules actually degrades accuracy because the ensemble weights get skewed. I had a team inject twelve custom YARA-style rules into one deployment and watch the false positive rate jump from 4 percent to nearly 30 percent. We removed nine of them and the rate dropped back down. Less is genuinely more with this tool. The biggest limitation I run into is its handling of encrypted traffic analysis. The Armour Of Light can inspect certificate metadata and connection timing patterns, but it cannot decrypt TLS traffic without the private keys. If your environment uses certificate pinning or custom CA setups, you need to configure the tls_inspection block carefully. I've seen deployments where the tool silently dropped TLS inspection for half the monitored hosts because the CA certificate path was wrong in the config. It doesn't log an error about this. It just stops reporting on those connections. Check the inspection status endpoint at localhost:8443/status after any config change. If tls_inspected_connections shows zero, something is misconfigured.

Get the Full Details

The Armour of Light: A Kingsbridge Novel (Audio Download): Ken Follett, John Lee, Macmillan ...
The Armour of Light: A Kingsbridge Novel (Audio Download): Ken Follett, John Lee, Macmillan ...

Another edge case that burned me recently involved containerized workloads. The Armour Of Light runs at the host level and monitors system calls across all processes on the machine. When containers share the host kernel, which is the default on most setups, the tool sees processes from every container running on that host. This means a single config profile has to account for wildly different workloads. A database container and a web frontend container on the same host have completely different baseline behaviors. I solve this by defining per-container-label policies using the cgroup filters in the config. Each workload group gets its own threshold settings and its own exclusion rules. Without that, the tool either flags the database as anomalous because it's making too many disk writes, or it flags the web server because its connection patterns don't match the database baseline. The tool also struggles with legitimate but unusual operations. Scheduled migrations, quarterly compliance scans, and emergency patch deployments all look like anomalous behavior to a behavioral model. I maintain a whitelist system where known operational procedures are pre-approved. The whitelist has an expiration mechanism — entries automatically expire after a set number of days so they don't become permanent blind spots. I've seen teams set expiry to zero, which makes the whitelist useless because entries never expire. Keep it between 30 and 90 days depending on your change frequency.

Integrating The Armour Of Light With Existing Tooling

The tool ships with API endpoints for querying detections, pushing configuration updates, and exporting telemetry. I use the detections endpoint to feed alerts into PagerDuty. The JSON output maps cleanly to PagerDuty's event schema. I also route high-confidence detections into our ticketing system via webhook, which triggers a standardized incident response workflow. Low-confidence items go into a weekly review queue instead of paging anyone. For threat intelligence feeds, The Armour Of Light supports STIX 2.1 imports. I pull from open-source feeds and a commercial feed our team pays for. The import process runs daily and updates the reputation engine. Known-bad indicators get weighted more heavily in the scoring. This is where the tool shows real value during an active investigation. Instead of manually cross-referencing IoCs, the system auto-enriches each detection with threat intel context. One thing worth noting about the update process. The development team pushes frequent updates, sometimes weekly. I test every update in a staging environment before applying it to production. The tool has broken compatibility twice in the last year after minor version bumps. Once it was a config format change that required a migration script. Another time a kernel module update conflicted with a security hardening patch we'd applied months earlier. Neither issue was catastrophic, but both caused downtime while we resolved them. Keep a rollback plan ready. The installer creates a backup of your current config and kernel modules automatically, which has saved me twice.

The documentation is adequate but assumes a certain level of familiarity with endpoint security concepts. If you're new to this space, I'd recommend reading up on behavioral detection fundamentals before diving into the tool. The official docs cover configuration syntax and API reference well, but they skip over the why behind many of the design decisions. Understanding why the ensemble scoring works the way it does will save you from the common pitfall of treating it like a traditional signature-based tool. It's fundamentally different, and approaching it with the wrong mental model leads to frustration and poor results.

The Armour of Light: A Page-turning, Epic Kingsbridge Novel from the Bestselling Author of The ...
The Armour of Light: A Page-turning, Epic Kingsbridge Novel from the Bestselling Author of The ...