21 Commits
Author SHA1 Message Date
Der BenjiandClaude Opus 4.6 d5323ea4f7 Add Sysmon EID filters, LitterBox integration, MCP server, and favicon
- Sysmon view: added dedicated filter fields for Sysmon Event IDs and
  Windows Event IDs (comma-separated, with server-side multi-ID support)
- Graph view: show triggered Sysmon/Windows EIDs and PowerShell commands
  in process detail panel
- Tracing view: added search field to filter by process name/file/path
- LitterBox: fixed proxy routing, rewrote results polling to use actual
  API endpoints (/files, /api/results/risk), added full inline tab with
  upload, scanner status, file table, and analysis controls
- MCP server: 17 tools exposing TDC functionality for Claude Code usage
- Favicon: generated from project icon in multiple sizes

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-27 15:16:54 +02:00
Der BenjiandClaude Opus 4.6 9a777e61b2 Add ETW Browser, clickable IOC flags, and service status fixes
ETW Browser (new tab):
- Multi-channel Windows Event Log viewer with 12 channels (Sysmon,
  Security, PowerShell, Defender, WMI, BITS, DNS, Firewall, AppLocker,
  WinRM, Task Scheduler, Application)
- Channel availability probe shows ACTIVE/NO DATA status per channel
- Auto-refresh (5s polling), keyword filter, configurable event count
- Threat classification engine highlights malicious events in red:
  encoded PowerShell, LOLBin abuse, credential access, persistence,
  AMSI bypass, C2 indicators, Sysmon IOCs (CreateRemoteThread, LSASS
  access, suspicious DNS, registry Run keys, process tampering)
- Expandable event details with suspicious values highlighted

Clickable IOC Flags (PE + ELF analysis):
- Each flag now carries an 'evidence' object with matched APIs,
  detection rule reference list, and explanation text
- Click a flag to expand: shows why it triggered, which APIs matched,
  and what the detection rule watches for (matched APIs highlighted red)

Dashboard service count fix:
- Now counts all 6 services (was 4, missing detonator + fibratus)
- Denominator is dynamic (was hardcoded /5)
- Service labels shown inline under the count (green=online, red=offline)

Scanner tools fix (install-scanner-tools.ps1):
- Retargets ThreatCheck/DefenderCheck to net8.0 SDK-style when .NET
  Framework 4.8 is unavailable (ARM64 compatibility)
- Adds Defender exclusions before build (source contains AMSI code
  that Defender quarantines)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-14 17:21:30 +02:00
Der BenjiandClaude Opus 4.6 9c05b1b4c6 Add macOS Apple Silicon setup via UTM with automated provisioning
The headless QEMU boot of Windows 11 ARM64 ISOs is unreliable, so this
adds a documented and scripted UTM-based path as the recommended setup
for M1-M4 Macs.

New files:
- scripts/setup-macos-utm.sh: Full guided setup (prereqs, file upload,
  provisioning via WinRM, ARM64-specific fixes)
- scripts/prepare-vagrant-winrm.ps1: One-time VM bootstrap for WinRM +
  vagrant user (run inside the Windows VM)

Fixes in build-box-macos.sh:
- USB controller (qemu-xhci) declared before usb-storage devices
- Locale changed to de-DE for German ISOs
- tar packaging uses portable staging dir instead of BSD -s flag
- Added QEMU monitor socket + boot keystrokes for headless attempts

Other changes:
- webui/app.py: Sysmon service check now tries both Sysmon64a (ARM64)
  and Sysmon64 (x86/x64); added platform import for config detection
- scripts/install-sysmon.ps1: Use $sysmonServiceName variable in output
- Makefile: New 'make setup' target for UTM path, updated help text
- README.md: Expanded macOS section with UTM instructions, marked
  Vagrant/QEMU path as experimental

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-14 14:37:11 +02:00
Der Benji 8bba74d1cc added better screenshots and README 2026-06-14 16:39:19 +02:00
Der Benji ea41c6daa1 Made UI more stable 2026-06-14 16:00:00 +02:00
Der Benji e916aab8a2 Added Packer view on Hex editor 2026-06-14 11:40:12 +02:00
Der Benji 1cf6de25d0 Merge branch 'main' of https://github.com/BenjiTrapp/transportable-detonation-chamber 2026-06-13 22:59:39 +02:00
Der Benji d035aae74f Reworked a little and some screenshots 2026-06-13 22:59:29 +02:00
Benjamin-Yves Trapp f336c7aadd Delete image.jpeg 2026-06-13 21:18:58 +02:00
Der Benji 73cf212d37 Reworked MacOS 2026-06-13 20:07:22 +02:00
Der Benji fa159be161 update makefile 2026-06-12 10:54:30 +02:00
Der Benji d58b7e1abc Some rework for vagrant 2026-06-12 09:23:55 +02:00
Der Benji 0f78f77775 Refresh 2026-06-11 11:47:19 +02:00
Der Benji d2f4253c65 Added hunt sleeping beacons 2026-06-11 10:55:52 +02:00
Der Benji 44365c280e The zoo added 2026-06-10 17:56:54 +02:00
Der Benji 30c47d8507 Provisioning 2026-06-10 13:47:16 +02:00
Der Benji d134bcc8bb Refresh and added some more features 2026-06-09 18:26:57 +02:00
Der Benji 778dfe9a11 Pimped the UI 2026-06-09 17:21:01 +02:00
Der Benji 8589857b86 Refresh 2026-06-09 14:17:19 +02:00
Der Benji cf85adb6a9 Initial commit 2026-06-08 17:18:29 +02:00
Benjamin-Yves Trapp b60bb222ba Create README.md 2026-06-08 09:16:43 +02:00