Skip to content

Findings: detect scans, password guessing, lateral movement, unusual uploads, floods - #16

Merged
githubflyideas merged 1 commit into
mainfrom
findings
Oct 2, 2026
Merged

githubflyideas merged 1 commit into
mainfrom
findings

Conversation

@githubflyideas

Copy link
Copy Markdown
Owner

New Findings page: detection rules over the flows every 5 minutes, designed for sampled data. Demo includes an attack through 1:4096 sFlow; tests check every step is found once and a day of normal traffic is quiet. Also fixes host counting on details pages and RTL value rendering. README in 13 languages, CHANGELOG 0.2.0.

🤖 Generated with Claude Code

https://claude.ai/code/session_01XEUxFQp8ivofZLm1o6KiXm


Generated by Claude Code

…uploads, floods

- internal/detect: rules over the last 10 minutes of flows every 5
  minutes, built for sampled sFlow/NetFlow (observed counts plus a
  "one probe per sample" condition); learns usual admin services and
  upload destinations; findings merged per incident, "not a problem"
  suppresses for good
- demo: an attack through the 1:4096 switch (sweep, port scan, RDP
  guessing, SMB lateral movement, upload to C2) and a UDP flood
- tests: every step found once at the right severity; a day of normal
  traffic gives only the internet scanner (low)
- web: Findings page, overview panel, findings on host details, badge;
  13 languages
- fix: internal hosts counted on both sides of internal conversations
- fix: RTL ports read backwards and names ran into addresses
- README (13 languages), screenshots, CHANGELOG 0.2.0

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XEUxFQp8ivofZLm1o6KiXm
@githubflyideas
githubflyideas merged commit 5e69fbd into main Oct 2, 2026
9 checks passed
@github-actions
github-actions Bot deleted the findings branch October 2, 2026 04:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants