Documentation
From the first install to running a full security operations centre: everything documented, precise, actionable.
BALLA consists of a lightweight agent on each endpoint, an AI engine and a supervision cockpit. This documentation takes you from install to operations.
Install the agent and connect your first endpoint in minutes.
# Install the SISKO agent
curl -fsSL https://get.sisko.ml/install.sh | sh
# Enroll the endpoint, then start
sisko-agent enroll --tenant <TENANT_ID> --token <ENROLL_TOKEN>
sisko-agent startThe agent observes system events and publishes them in a signed UCEF format. It is configured through a simple YAML file.
# /etc/sisko/agent.yaml
publisher:
mode: kafka
broker: kafka.internal:9092
tls:
enabled: true
collectors:
processes: true
network: true
files: true
auth: true
hardware: true
buffer:
max_events: 100000
encrypt: true # AES-256-GCM offline bufferA REST API secured by Ed25519 JWT exposes the fleet, alerts and events. The real-time stream runs over WebSocket.
# List fleet machines (Ed25519 JWT)
curl https://api.sisko.ml/fleet \
-H "Authorization: Bearer $SISKO_TOKEN"{
"machines": [
{
"equipment_id": "a3f1c9…",
"hostname": "HR-WKS-008",
"status": "online",
"severity": "critical",
"last_seen": "2026-08-12T09:41:00Z"
}
],
"total": 128
}// Real-time alerts over WebSocket
const ws = new WebSocket("wss://api.sisko.ml/alerts/ws?token=" + token);
ws.onmessage = (e) => console.log(JSON.parse(e.data));The cockpit shows the fleet, explained alerts, per-machine and per-user detail, and attack-chain reconstruction.
Deploy everything via Docker Compose, on-premise, down to a fully disconnected air-gapped mode.
# docker-compose.yml (excerpt)
services:
balla:
image: sisko/balla:latest
api:
image: sisko/api:latest
ports: ["8000:8000"]
dashboard:
image: sisko/dashboard:latest
ports: ["3000:3000"]mTLS everywhere, Ed25519-signed commands, a tamper-proof audit log and SHAP explanations for GDPR compliance.
// Every command sent to an endpoint is signed
{
"action": "isolate_machine",
"equipment_id": "a3f1c9…",
"signature": "ed25519:…",
"rollback_token": "b7c2…"
}