Demo · BALLA agent
Deploy the BALLA agent on a machine (or VM), run attacks, and watch the SOC react in real time. Guided install: role profile + SOC broker.
In the downloaded folder. The installer asks for the profile then the broker.
$ tar xzf balla-demo-macos-arm64.tar.gz$ xattr -dr com.apple.quarantine balla-agent install-balla.sh$ chmod +x install-balla.sh$ sudo ./install-balla.sh
Demo: on macOS, clear quarantine (command included); on Windows, if SmartScreen appears, click “More info” → “Run anyway”.
Authenticity (signed by SISKO) + integrity, on the .tar.gz / .zip archive — do this BEFORE extracting it, in the folder holding the archive and the 3 verification files.
# À faire dans le dossier de l'archive, AVANT de l'extraire.
# 1) Récupérer les empreintes signées + la clé publique SISKO
curl -O https://sisko.ml/download/SHA256SUMS.txt
curl -O https://sisko.ml/download/SHA256SUMS.txt.asc
curl -O https://sisko.ml/download/sisko-releases-pubkey.asc
# 2) Importer la clé, PUIS vérifier son empreinte. Ne lui fais confiance QUE si
# elle correspond EXACTEMENT ci-dessous — recoupe-la avec une source
# indépendante (dépôt public, serveur de clés) : une clé prise au même
# endroit que l'archive ne prouve rien si le serveur est compromis.
gpg --import sisko-releases-pubkey.asc
gpg --fingerprint maksissoko07@gmail.com
# Empreinte attendue :
# 7F6D 89BF C337 02BE 035F 00B1 1281 DCB2 2053 70C0
# 3) Authenticité des empreintes (signées par SISKO)
gpg --verify SHA256SUMS.txt.asc SHA256SUMS.txt
# 4) Intégrité de l'archive (.tar.gz / .zip), pas de son contenu
shasum -a 256 -c SHA256SUMS.txt # macOS
sha256sum -c SHA256SUMS.txt # Linuxsisko-releases-pubkey.asc · SHA256SUMS.txt.asc · Canonical key fingerprint
Broker = IP:9092 of your SOC machine (e.g. 192.168.1.20:9092).
These demo packages embed the verification key of THIS SOC. The agent connects to the broker you provide (the machine running the stand, on your network).