Intro
A lightweight web application that is feed a completed Suricata fast.log security alert file (e.g., from an Hospital Network) and renders a network + alert graph with anomaly scoring of security alerts.
Features
Parses full Suricata fast.log once at startup Builds force-directed network graph (hosts + alert signature nodes) Simple z-score based anomaly detection on per-source alert volume Pure FastAPI + D3.js frontend
Built With
- css
- fastapi
- html5
- javascript
- python
- uvicorn

Log in or sign up for Devpost to join the conversation.