ThreatHunter/README.md

73 lines
1.6 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters!

This file contains ambiguous Unicode characters that may be confused with others in your current locale. If your use case is intentional and legitimate, you can safely ignore this warning. Use the Escape button to highlight these characters.

# ThreatHunter
ThreatHunter is a **SIEMlite security visibility tool** built for small and midsized businesses.
It focuses on one simple question:
> *“What suspicious outbound connections are my computers making?”*
Without:
- Heavy agents
- Constant data streaming
- Enterprise SIEM complexity
---
## What ThreatHunter Does
- Collects Windows Firewall / WFP connection events
- Detects connections to knownbad IPs using reputation data
- Processes data **locally on the endpoint**
- Uploads only confirmed security hits
- Automatically creates **Security alerts in Syncro**
- Provides a clean web UI for technicians and customers
---
## Why It Exists
Most SMBs:
- Have no visibility into outbound traffic
- Cant justify a full SIEM or EDR
- Still want to *see the crazy stuff* touching their machines
ThreatHunter is designed to be:
- Free or lowcost
- Easy to deploy via Syncro
- Useful as both a security tool and an educational aid
---
## Architecture Overview
**Endpoint**
- PowerShell script
- Runs on a schedule via Syncro
- Buffers and correlates locally
- Hashes executables only on suspicious hits
**Server**
- VPShosted API + database
- Receives hit data
- Creates Syncro Security tickets
- Hosts ThreatHunter web portal
---
## Status
🚧 Early development / v1 build phase
See `project.md` for full technical and architectural details.
---
## Disclaimer
ThreatHunter is **not** a replacement for:
- EDR
- Full SIEM
- IDS/IPS
It is a **visibility and awareness tool** designed to surface suspicious behavior early and guide next steps.