mirror of
https://github.com/BenjiTrapp/transportable-detonation-chamber
synced 2026-08-09 12:01:14 +00:00
ETW Browser (new tab): - Multi-channel Windows Event Log viewer with 12 channels (Sysmon, Security, PowerShell, Defender, WMI, BITS, DNS, Firewall, AppLocker, WinRM, Task Scheduler, Application) - Channel availability probe shows ACTIVE/NO DATA status per channel - Auto-refresh (5s polling), keyword filter, configurable event count - Threat classification engine highlights malicious events in red: encoded PowerShell, LOLBin abuse, credential access, persistence, AMSI bypass, C2 indicators, Sysmon IOCs (CreateRemoteThread, LSASS access, suspicious DNS, registry Run keys, process tampering) - Expandable event details with suspicious values highlighted Clickable IOC Flags (PE + ELF analysis): - Each flag now carries an 'evidence' object with matched APIs, detection rule reference list, and explanation text - Click a flag to expand: shows why it triggered, which APIs matched, and what the detection rule watches for (matched APIs highlighted red) Dashboard service count fix: - Now counts all 6 services (was 4, missing detonator + fibratus) - Denominator is dynamic (was hardcoded /5) - Service labels shown inline under the count (green=online, red=offline) Scanner tools fix (install-scanner-tools.ps1): - Retargets ThreatCheck/DefenderCheck to net8.0 SDK-style when .NET Framework 4.8 is unavailable (ARM64 compatibility) - Adds Defender exclusions before build (source contains AMSI code that Defender quarantines) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>