- Sysmon view: added dedicated filter fields for Sysmon Event IDs and
Windows Event IDs (comma-separated, with server-side multi-ID support)
- Graph view: show triggered Sysmon/Windows EIDs and PowerShell commands
in process detail panel
- Tracing view: added search field to filter by process name/file/path
- LitterBox: fixed proxy routing, rewrote results polling to use actual
API endpoints (/files, /api/results/risk), added full inline tab with
upload, scanner status, file table, and analysis controls
- MCP server: 17 tools exposing TDC functionality for Claude Code usage
- Favicon: generated from project icon in multiple sizes
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
ETW Browser (new tab):
- Multi-channel Windows Event Log viewer with 12 channels (Sysmon,
Security, PowerShell, Defender, WMI, BITS, DNS, Firewall, AppLocker,
WinRM, Task Scheduler, Application)
- Channel availability probe shows ACTIVE/NO DATA status per channel
- Auto-refresh (5s polling), keyword filter, configurable event count
- Threat classification engine highlights malicious events in red:
encoded PowerShell, LOLBin abuse, credential access, persistence,
AMSI bypass, C2 indicators, Sysmon IOCs (CreateRemoteThread, LSASS
access, suspicious DNS, registry Run keys, process tampering)
- Expandable event details with suspicious values highlighted
Clickable IOC Flags (PE + ELF analysis):
- Each flag now carries an 'evidence' object with matched APIs,
detection rule reference list, and explanation text
- Click a flag to expand: shows why it triggered, which APIs matched,
and what the detection rule watches for (matched APIs highlighted red)
Dashboard service count fix:
- Now counts all 6 services (was 4, missing detonator + fibratus)
- Denominator is dynamic (was hardcoded /5)
- Service labels shown inline under the count (green=online, red=offline)
Scanner tools fix (install-scanner-tools.ps1):
- Retargets ThreatCheck/DefenderCheck to net8.0 SDK-style when .NET
Framework 4.8 is unavailable (ARM64 compatibility)
- Adds Defender exclusions before build (source contains AMSI code
that Defender quarantines)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The headless QEMU boot of Windows 11 ARM64 ISOs is unreliable, so this
adds a documented and scripted UTM-based path as the recommended setup
for M1-M4 Macs.
New files:
- scripts/setup-macos-utm.sh: Full guided setup (prereqs, file upload,
provisioning via WinRM, ARM64-specific fixes)
- scripts/prepare-vagrant-winrm.ps1: One-time VM bootstrap for WinRM +
vagrant user (run inside the Windows VM)
Fixes in build-box-macos.sh:
- USB controller (qemu-xhci) declared before usb-storage devices
- Locale changed to de-DE for German ISOs
- tar packaging uses portable staging dir instead of BSD -s flag
- Added QEMU monitor socket + boot keystrokes for headless attempts
Other changes:
- webui/app.py: Sysmon service check now tries both Sysmon64a (ARM64)
and Sysmon64 (x86/x64); added platform import for config detection
- scripts/install-sysmon.ps1: Use $sysmonServiceName variable in output
- Makefile: New 'make setup' target for UTM path, updated help text
- README.md: Expanded macOS section with UTM instructions, marked
Vagrant/QEMU path as experimental
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>