Troubleshooting
dsp: command not found
Activate the repository virtual environment or reinstall the editable package:
<repo>/.venv/bin to PATH when the environment exists.
Menu opens without the graphical TUI
Installwhiptail:
low profile behaves like normal
This is expected in the current v1.4.0 runtime. low is a legacy alias and is normalized to normal.
Use only:
Target network wider than /24 is rejected
This is a safety guardrail. Supply both an explicit large-target override and a host cap:
Menu reports stale normal profile volumes
The current menu contains a preflight check that protects against stale checkouts/editable installs.
Choose Update latest patch, then refresh the editable install if necessary:
release/v1.4.0 branch.
Webshell family and URL do not match
Check the extension:Webshell run cannot write remote artifacts
Confirm that--remote-work-dir points to a writable location on the remote host. The Linux-validated default is:
HTTPS webshell certificate issue
When certificate validation is required, use:Run completes but no alert is visible
DSP execution success and vendor alert success are different layers. Check in this order:traffic_summary.json— was the intended activity generated?events.db/events.jsonl— were DSP events recorded?validation.json— did DSP’s own validation pass?- time window and source/destination addresses in the security platform
- sensor/collector visibility and policy scope
- vendor detection/rule configuration