Intro

A lightweight web application that is feed a completed Suricata fast.log security alert file (e.g., from an Hospital Network) and renders a network + alert graph with anomaly scoring of security alerts.

Features

Parses full Suricata fast.log once at startup Builds force-directed network graph (hosts + alert signature nodes) Simple z-score based anomaly detection on per-source alert volume Pure FastAPI + D3.js frontend

Built With

Share this project:

Updates