Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

2 Commits
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ Network-based SIEM Monitor (NETGUARD)

Enterprise Threat Telemetry, Behavioral Detection & SOC Dashboard

Build Status Security Scan Safety Notice Node.js License

Overview β€’ Features β€’ Architecture β€’ Simulators β€’ Installation β€’ API Docs


πŸ“Œ Executive Summary

NETGUARD is a next-generation SOC management and threat analysis platform. Building upon low-level honeypot and simulation logic, NETGUARD integrates continuous stream ingestion, automated MITRE ATT&CK mapping, heuristic threat scoring, and real-time incident visualization into a single control plane[cite: 1].


⚑ Key Features

  • Live Telemetry Engine: Event handling powered by WebSockets (Socket.IO) for low-latency incident streaming[cite: 1].
  • Integrated Attack Simulator Suite: Embedded simulation engines to generate controlled attack patterns (Brute Force, Port Scans, DNS Tunneling) for testing SOC responsiveness[cite: 1].
  • MITRE ATT&CK Mapping Engine: Automated correlation between raw event signatures and standard TTP frameworks[cite: 1].
  • Multi-Tier SOC Policy Model: Granular severity triage Matrix with designated SLAs for incident handling[cite: 1].
  • Real-Time Visual Control Plane: Custom dark-mode web application providing threat graphs, metric indicators, and incident log filtering[cite: 1].

πŸ— System Architecture

About

Enterprise Real-Time Network Threat Detection, Behavioral Telemetry & Live SOC Dashboard Engine.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors