Commit Graph

47 Commits

Author SHA1 Message Date
Will Schroeder 3628bf18d7 Merge branch 'main' into llm_chat_over_data 2025-11-07 13:22:16 -08:00
Lee Chagolla-Christensen 562a4e71ca Optimize observability stack and workflow throughput
Performance and configuration improvements:
- Tune OpenTelemetry Collector with batching, queuing, and memory limits
- Optimize Jaeger for write-heavy workloads with consistency disabled
- Add Prometheus scraping for OTel Collector internal metrics
- Increase document conversion prefetch count from 1 to 5
- Add CPU limit (2 cores) for document-conversion service
- Disable Tesseract OCR in default Tika config for faster processing

Workflow tracking enhancements:
- Add WorkflowTrackingService for centralized workflow state management
- Implement finalize_workflow activities for both services
- Track enrichment success/failure per workflow instance
- Support updating workflow status by object_id for subscriptions

Code improvements:
- Refactor PDF analyzer with modular extraction functions
- Add Unicode surrogate sanitization to prevent JSONB errors
- Update PII analyzer with improved error handling
- Add documentation links to Tika and Tesseract configuration

Frontend:
- Update StatsOverview component for workflow metrics display
2025-11-07 00:58:58 -08:00
harmj0y 672fbb3550 Initial Chatbot commit
- Initial Chatbot commit
2025-11-06 18:30:11 -08:00
Lee Chagolla-Christensen 58dd461532 Refactor document conversion service into Dapr workflow
- Restructure document_conversion to match into workflow structure
- PDF analyzer: use PyMuPDF and extract extensive metadata
- Add PDF test suite with encrypted/unencrypted fixtures
- Add Tika Tesseract OCR configuration support example
- Update Dapr configurations for new document_conversion component
- Remove deprecated helpers from common lib
- Update queue constants and workflow setup
2025-11-06 01:30:10 -08:00
Lee Chagolla-Christensen 6ec0a3b61a Workflow performance improvements (#87)
* upgrade to dapr postgresv2 statestore

* actually make it v2

* dapr state table name, cleanup subscriptions/globals

* proper exceptions

* formatting/lint

* Refactor workflow tracking and improve activity input handling

- Extract workflow tracking logic into dedicated WorkflowTrackingService
- Simplify activity signatures to accept specific parameters instead of generic dicts
- Remove unused asyncio event loop references from enrichment modules
- Update YaraRuleManager initialization and method names

* re-added workflow tracking in the DB

* update uvicorn prod options

* enrichment work parallelism, convert queues from broadcast to task queues

* Refactor pubsub and improve workflow parallelism

- Split Dapr pubsub Dapr yaml components into topic-specific queues (alerting, dotnet, dpapi, files, noseyparker, workflow_monitor)
- Update all Dapr volume mounts to reference new topic-specific pubsub components
- Converted queues to task queues
- Use YAML anchors to reduce duplication for file-enrichment replicas
- Pass asyncpg pool to enrichment modules instead of creating connections
- Add asyncpg_pool parameter throughout chromium and enrichment module analyzers
- Update VSCode workspace (removed InspectAssembly, renamed dotnet_api to dotnet_service)
- Added curl commands for Jaeger API to performance docs to help with perf troubleshooting
- Created common.queues module to centralize pubsub/topic names (eases
  future refactoring)

* worker mods

* Workflow performance tuning, fix pubsub config, CLI arg changes

- Fix pubsub deleteWhenUnused typo (deletedWhenUnused)
- Add LOG_LEVEL environment variable support across services
- CLI: Rename --repeat to --times, add --max-files option
- Increase files pubsub prefetchCount from 25 to 50
- Add MAX_PARALLEL_WORKFLOWS configuration
- Fix DotNetAssemblyAnalysis null handling with field validators
- Update dashboard to show cumulative files/findings over time
- Add RUST_LOG environment variable support to noseyparker
- Update CHANGELOG for 2.1.4 release notes

* Dapr 1.16.2 and use db transactions

- Upgrade all Dapr containers from 1.16.1 to 1.16.2
- Reduce enrichment parallelism default from 25 to 5 workflows
- Reduce healthcheck intervals from 10s to 5s for alerting and document conversion
- Fixed DPAPI eventing to use new pubsubs
- Refactor file_linking database operations to use atomic upserts and avoid deadlocks
- Add WriteOnceViolationError handling in DPAPI masterkey analyzer
- Wrap database operations in transactions for enrichment storage and plaintext indexing
- Fix postgres notification handler closure variable capture

* remove unused start_time

* Scheduler persistence, workflow concurrency tuning, and config cleanup

- Add volume for Dapr scheduler and init service
- Add scheduler dependency to file enrichment service
- Add async workflow client libraries
- Format and cleanup compose.yaml (spacing, indentation, empty lines)

* Migrate file_enrichment to async Dapr client and optimize Dockerfile

- Use async DaprClient where possible in file_enrichment
- Improve Dockerfile caching
- Add asyncpg connection pool helper and fix typo in secret store name
- Include VS Code debug configuration for document_conversion
- Remove unused dapr_client from DpapiBlobAnalyzer
- Clean up activity return types and better handle exceptions

* Enrichment tracking for NoseyParker and logging cleanup

- Add workflow_id to NoseyParkerInput and NoseyParkerOutput models
- Remove workflow lookup query in noseyparker subscription handler
- Adjust jaeger_perf_stats.sh output formatting and precision
- Add type hints for async functions

* noseyparker scanner perf, tracing for update_enrichment_results

---------

Co-authored-by: Lee Chagolla-Christensen <lee@localhost>
2025-11-04 14:06:59 -08:00
harmj0y 09915c7bf3 Impacket and Cryptography bump
- Impacket and Cryptography bump
2025-11-03 11:32:46 -08:00
Will Schroeder d4049fe199 Dependabot updates 03 11 25 (#84)
* starlette fixes

starlette fixes

* pypdf fixes

pypdf fixes

* bump urllib3

bump urllib3

* vite bump

vite bump

* Bump requests

Bump requests

* Replaced pypdf2 with pypdf

-Replaced pypdf2 with pypdf
2025-11-03 10:42:51 -08:00
harmj0y 129f7752c2 Added manual Chromium ABE key submission
- Added manual Chromium ABE key submission (w/ retroactive chromium data decryption)
2025-10-31 15:22:28 -07:00
harmj0y dc26e4959f Fixed container extraction status updates
- Fixed container extraction status updates
2025-10-28 11:18:36 -07:00
Lee Chagolla-Christensen 790541fe8e disable bulk re-run for now 2025-10-27 12:58:31 -07:00
Lee Chagolla-Christensen b9d0b818b6 strong types 2025-10-27 12:43:59 -07:00
Lee Chagolla-Christensen 14785ca8ca adjust uvicorn workers to 1 2025-10-26 20:43:03 -07:00
Lee Chagolla-Christensen a56eb844dd fix View Raw triggering download 2025-10-25 10:41:20 -07:00
Lee Chagolla-Christensen 91a3ce12d2 improve submit pooling/stats, remove bucket checks 2025-10-24 15:47:58 -07:00
harmj0y 815138ce32 Host reporting tweaks
- Changed reporting prompt
- changed up some of the displayed reporting stats
2025-10-23 14:00:41 -07:00
harmj0y 056308ab99 Fixes for the reporting agent and report generation
-Fixes for the reporting agent and report generation
2025-10-22 16:59:58 -07:00
harmj0y 15fad59b70 Fix for some agent blocking
- Fix for agent API blocking until agent execution completes (except for finding triage)
2025-10-22 14:28:31 -07:00
harmj0y aa8a745ecd Initial pass on system/host reporting
-Initial pass on system/host reporting
-still need to fully test the agent implementation
2025-10-21 16:02:52 -07:00
Lee Chagolla-Christensen c2dac2e8a7 Change DB access and update alerting
- Switch from using POSTGRES_CONNECTION_STRING to
  POSTGRES_USER/POSTGRES_PASSWORD/POSTGRES_DATABASE/etc.
- When no apprise URL is configured, use the test echo'ing endpoint
2025-10-18 21:36:27 -07:00
Lee Chagolla-Christensen 3527df6f6a windows path normalization, get_drive docs 2025-10-16 02:38:47 -07:00
Lee Chagolla-Christensen 1072eadf8f fix web API warnings 2025-10-15 14:27:05 -07:00
Lee Chagolla-Christensen acc788c425 fix lint errors 2025-10-15 14:21:30 -07:00
Lee Chagolla-Christensen d40cdcb655 use UTC in web API timestamps 2025-10-15 14:20:00 -07:00
Lee Chagolla-Christensen be115d1808 update to use common.logger 2025-10-15 14:09:29 -07:00
Lee Chagolla-Christensen b63813e300 Standardize path handling and centralize database connection management
- Add centralized PostgreSQL connection string helper in common/db.py
- Replace ntpath with posixpath
- Add get_drive_from_path() helper for extracting drive letters from paths
- Update all modules to use centralized DB connection helper instead of individual Dapr client calls
- Improve path normalization across Chromium, DPAPI, and file enrichment modules
- Added dependencies to local libraries
- Expand file linking tests with comprehensive rule engine test cases
- Refactor masterkey path construction to use posixpath.normpath for proper path joining
- Update state helpers and API models to use centralized connection
- Updated web API to use strongly typed models instead of dicts
  internally
- Improve DPAPI core functionality with better error handling and path normalization
2025-10-15 13:48:50 -07:00
Lee Chagolla-Christensen bbbdc5b4d8 update to dapr 1.16 2025-10-10 18:50:37 -07:00
Lee Chagolla-Christensen 6099a6515b update dapr to 1.16.1 2025-10-10 17:32:12 -07:00
Lee Chagolla-Christensen a22218fcef fix ruff/tests in project, install venv script, local state link to user masterkey, masterkey type from path 2025-10-10 14:16:52 -07:00
Lee Chagolla-Christensen 747c38771e normalize upload file paths, UI file caching, partial user masterkey file link, simplify hive report 2025-10-10 00:18:09 -07:00
harmj0y 0748f5abbc Added "Text Translator" agent
-Added "Text Translator" agent
2025-10-02 21:05:07 +09:00
Lee Chagolla-Christensen 0d3307bf71 update deps, fixate dapr version 2025-09-24 16:03:02 -07:00
Lee Chagolla-Christensen f22b0da27b update deps 2025-09-24 15:39:00 -07:00
Lee Chagolla-Christensen 0bc41c9c3f fix web API deps, formatting/linting 2025-09-08 12:25:00 -07:00
Lee Chagolla-Christensen f0b77ae648 refactor routes 2025-09-03 23:03:50 -07:00
Lee Chagolla-Christensen 4d2fb1b94a add shared models to common 2025-09-03 22:02:19 -07:00
Lee Chagolla-Christensen f0df91c0cf add dpapi credentials route, standardize dapr port 2025-09-03 21:19:15 -07:00
Lee Chagolla-Christensen ace1b9b79b linting 2025-09-03 19:24:05 -07:00
Lee Chagolla-Christensen b4813843fe more lint 2025-09-03 19:19:11 -07:00
harmj0y 14fd179421 Redid certificate enrichment module
-Redid `certificate` enrichment module
-Some linting
2025-09-01 16:35:55 -07:00
harmj0y 414788be38 Added "Containers" documentation
- Added "Containers" documentation
- Linting for web_api/large_containers.py
2025-08-29 16:17:19 -07:00
harmj0y 40902d9d8f Version 2.1.3
- See CHANGELOG.md for summary of changes
2025-08-29 15:24:32 -07:00
Lee Chagolla-Christensen 1ce9dde651 doc updates 2025-06-26 14:02:38 -07:00
Lee Chagolla-Christensen 166878f4e9 formatting 2025-06-25 02:19:25 -07:00
Lee Chagolla-Christensen 4bf93faa34 reduce uvicorn workers 2025-06-16 15:29:05 -07:00
Lee Chagolla-Christensen b796025e8d fix aiohttp/protbuf dependabot complaints 2025-06-16 13:04:45 -07:00
Lee Chagolla-Christensen 73c3556f1a fix dependabot 2025-06-16 12:58:05 -07:00
Lee Christensen 8035a6a168 add code 2025-06-13 11:33:07 +02:00