Sensor

Operate, upgrade, and troubleshoot the Imunify sensor on your Linux hosts — systemd commands, upgrade behavior, and recovery.

The Imunify sensor is the small system service that runs on each of your Linux hosts. Once installed, it sits in the kernel and watches the system calls that matter most for security — file reads, process execution, outbound network connections, and file deletion — and runs each one through the policy you defined in the Panel. Depending on the matching rule, the call is allowed, blocked, or held for your approval. See Your first event for the full list of intercepted system calls and what the Panel shows you when the sensor catches one.

The sensor keeps itself up to date through a maintenance-window upgrade flow. When a new release is published and an administrator pushes it to your host, the sensor stops itself, replaces its binary, restarts, and reports back. There is a short enforcement gap during the swap and no action is required from you. See Upgrades for what an upgrade looks like from your side and how to verify the new version is healthy afterwards.

Pages in this section#

Pages in this section

Last updated Jun 17, 2026