A mission-critical endpoint defense hypervisor fusing low-level assembly anti-analysis traps, in-memory SHA-256 cryptographic verification, pure-Rust YARA/Sigma correlation, dynamic rotating KMS envelopes, and real-time WebSocket telemetry.
Abyssal Watcher is an industrial-grade, defense-in-depth Host-Based Intrusion Detection System (HIDS) and Endpoint Detection and Response (EDR) engine. Engineered for operation in untrusted, hostile, or contested host environments, it actively denies reverse-engineering attempts, identifies complex memory injections and process hollowing, correlates parent-child telemetry via Sigma rules, and streams structured alerts mapped to the MITRE ATT&CK matrix directly to Security Operations Centers (SOC).
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β ABYSSAL WATCHER MULTI-VECTOR ARCHITECTURE β
β β
β βββββββββββββββββββββββββββββ MemoryGuard / ASM Traps βββββββββββββββββββββββββ β
β β Hardware & OS Layer β ββββββββββββββββββββββββββββΊ β Low-Level Defenses β β
β β (x86_64 CPUID / ptrace) β ββββββββββββββββββββββββββββ β (TF / RDTSC / Anti-VM)β β
β βββββββββββββββ¬ββββββββββββββ βββββββββββββββββββββββββ β
β β β
β βΌ β
β βββββββββββββββββββββββββββββ Pure-Rust YARA & Sigma βββββββββββββββββββββββββ β
β β Multi-Vector Threat Engineβ ββββββββββββββββββββββββββββΊ β MITRE ATT&CK Taxonomy β β
β β (Shannon Entropy / Heur) β β (T1055, T1059, T1027) β β
β βββββββββββββββ¬ββββββββββββββ βββββββββββββββββββββββββ β
β β β
β βΌ β
β βββββββββββββββββββββββββββββ Tokio / Actix-Web / AES βββββββββββββββββββββββββ β
β β Telemetry & KMS Layer β ββββββββββββββββββββββββββββΊ β SIEM / SOC Dashboard β β
β β (45s Key Rotation / Log) β β (CEF / ECS / WS Live) β β
β βββββββββββββββββββββββββββββ βββββββββββββββββββββββββ β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
The platform is structured into four distinct, hardened architectural tiers:
-
NASM Assembly Modules:
-
anti_vm.asm: Interrogates CPUID leaf 1 (bit 31) and leaf0x40000000hypervisor vendor signatures (KVM, VMware, Hyper-V, Xen). -
hook_detect.asm: Fast opcode scanner identifying prologue hooks,0xE9(JMP rel32),0xEB(JMP rel8),0xFF 0x25(JMP indirect),0x48 0xB8(MOV RAX; JMP RAX), and0x68 ... 0xC3(PUSH/RET) trampolines. -
anti_debug_ultra.asm: Direct CPU register polling (RFLAGS.TF), RDTSC timing latency delta thresholds, and memory INT3 scans.
-
-
MemoryGuard Integrity Engine:
core/memory_guard.rscalculates standalone SHA-256 checksums over.textcode segments to detect unauthorized runtime patching. Includes a Shannon entropy calculator ($0.0 - 8.0$ ) to flag encrypted/packed payloads ($>7.0$ ). -
Zero-Exposure Mode (
ZE_MODE):defense/ze_mode.rsenforces atomic lockdown and memory zeroization stubs usingwrite_volatile.
-
Pure-Rust YARA Engine:
analyzer/yara_engine.rsevaluates multi-string patterns and hex signatures without native C bindings or external dependencies.-
Ruleset:
data/rules/yara/edr_signatures.yar(Reflective DLL loaders, process hollowing API chains, XOR shellcode loops).
-
Ruleset:
-
Sigma Event Correlation:
analyzer/sigma_parser.rsinspects process spawn trees (e.g.w3wp.exe$\rightarrow$ powershell.exe) and command-line arguments (-enc,bypass,iex).-
Ruleset:
data/rules/sigma/process_creation.yml.
-
Ruleset:
-
MITRE ATT&CK Matrix Resolver:
analyzer/mitre_matrix.rsenriches all detections with standard Enterprise Tactics (TA0001 - TA0040) and Technique IDs (T1055.001,T1055.012,T1027.002,T1059.001,T1003.001,T1622). -
Adaptive Threat Cache:
analyzer/threat_cache.rsprovides a thread-safe LRU cache with temporal exponential decay ($e^{-\lambda t}$ ) and sliding hit counters.
-
Dynamic Ephemeral KMS:
infra/secure_kms.rsautomatically rotates 256-bit AES keys every 45 seconds (epoch_id) and immediately scrubs retired keys from memory. -
Tamper-Evident Hash-Chained Logging:
infra/secure_logger.rswraps log records in authenticated AES-256-GCM AEAD envelopes bound via sequential SHA-256 chain hashes: $$\text{ChainHash}n = \text{SHA-256}(\text{EpochID} \mathbin{\Vert} \text{Nonce} \mathbin{\Vert} \text{ChainHash}{n-1} \mathbin{\Vert} \text{Ciphertext})$$ -
Non-Blocking Asynchronous EventBus:
infra/event_bus.rsuses Tokio broadcast channels with a 2,048-message buffer for zero-lag alert dissemination. -
SIEM Forwarding Pipeline:
infra/siem_exporter.rsformats structured events for Splunk, Elastic Common Schema (ECS) JSON, and ArcSight Common Event Format (CEF:0).
- React 18 SOC Dashboard:
frontend/src/App.jsxbuilt with TailwindCSS, dark cybersecurity styling, live WebSocket event consumption, interactive threat injection simulator, and host quarantine controls. - Hardened Docker Distribution: Multi-stage
Dockerfilerunning an unprivileged system daemon on minimal attack surface Debian Bookworm Slim with Link-Time Optimization (LTO). - Linux Sandboxing Service:
infra/systemd/abyssal_watcher.servicewithProtectSystem=strict,NoNewPrivileges=true, and strict cgroup resource constraints.
| Component | Minimum Version | Purpose |
|---|---|---|
| Rust Toolchain | 1.75+ (2021 Edition) |
Core binary compilation (cargo, rustc) |
| Node.js / npm | v18.0.0+ |
React 18 Frontend Console (vite, tailwindcss) |
| NASM | 2.15+ |
x86_64 Assembly Traps Compiler |
| Docker & Compose | 24.0+ / v2.20+ |
Containerized Multi-Stage Cluster Deployment |
Inspects system integrity, executes anti-debug/anti-VM traps, and runs multi-vector heuristic evaluation:
cargo run --bin abyssal_entrypointLaunches the Actix-Web REST API server and WebSocket broadcast engine on 0.0.0.0:8080:
cargo run --bin abyssal_watchercd frontend
npm install
npm run dev
# Operations console available at http://localhost:3000Builds optimized binaries, bundles the frontend, and deploys the hardened EDR container:
docker-compose up -d --build
# REST API & Console exposed on http://localhost:8080cargo test --test integration_test -- --nocapture| Method | Endpoint | Description | Sample Output |
|---|---|---|---|
GET |
/api/status |
Host engine health & defense status | {"system":"Abyssal Watcher","ze_mode_enabled":true,"memory_guard_status":"SEALED"} |
POST |
/api/heartbeat |
Ingests agent telemetry heartbeat | {"status":"ACK","acknowledged_at":1723224000000} |
GET |
/api/alerts |
Paginated threat alerts (?page=1&limit=20) |
{"total":1,"items":[{"id":1,"assessment":{...}}]} |
POST |
/api/threats |
Submits memory buffer/process for scan | Returns full normalized ThreatAssessment JSON |
- Endpoint:
ws://localhost:8080/ws/telemetry - Protocol: JSON event frames pushed over low-latency Tokio broadcast channels.
- Payload Structure:
{
"topic": "threat.detection",
"level": "CRITICAL",
"timestamp": 1723224150000,
"payload": "{\"composite_score\":85,\"confidence_level\":\"CRITICAL\",\"mitre_techniques\":[{\"id\":\"T1055.001\",\"name\":\"DLL Injection\"}]}"
}# ArcSight Common Event Format (CEF:0)
CEF:0|AbyssalWatcher|EDR|1.04|THREAT_DETECTED|Abyssal_Reflective_DLL_Loader|10|dhost=endpoint.corp cs1Label=MITRE cs1=T1055.001:DLL Injection cn1Label=CompositeScore cn1=85 cs2Label=Confidence cs2=CRITICAL
abyssal_watcher/
βββ analyzer/ # Threat evaluation, YARA, Sigma, and MITRE resolution
β βββ mitre_matrix.rs # MITRE ATT&CK taxonomy dictionary & lookup
β βββ ml_analyzer.rs # Behavioral keyword & n-gram heuristics
β βββ sigma_parser.rs # AST-based Sigma process correlation engine
β βββ threat_cache.rs # High-speed LRU cache with exponential score decay
β βββ yara_engine.rs # Pure-Rust regex/bytecode YARA evaluator
βββ core/ # Low-level systems primitives and integrity seals
β βββ asm_module/ # Assembly anti-analysis traps
β β βββ anti_debug.asm # 16-bit Trap Flag inspector
β β βββ anti_debug_ultra.asm # 64-bit TF, RDTSC timing, and INT3 traps
β β βββ anti_vm.asm # CPUID hypervisor bit & artifact checks
β β βββ hook_detect.asm # JMP/CALL/Trampoline prologue hook scanner
β βββ memory_guard.rs # SHA-256 .text hashing & Shannon entropy engine
βββ defense/ # Runtime host defenses and sandbox reduction
β βββ anti_debug.rs # TracerPid, wchan, and PTRACE_TRACEME detection
β βββ anti_vm.rs # CPUID intrinsics & Linux DMI table inspection
β βββ ze_mode.rs # Zero-Exposure Mode & volatile memory zeroization
βββ engine/ # Multi-vector threat aggregation
β βββ threat_detector.rs # Unified composite score (0-100) calculation
βββ entrypoint/ # Standalone verification scanner binary
β βββ main.rs
βββ frontend/ # React 18 + TailwindCSS SOC Console
β βββ src/
β β βββ components/ # ThreatMatrix, LiveTelemetry, DefenseStatus
β β βββ App.jsx # Master operations dashboard & simulator
β β βββ main.jsx
β βββ package.json
β βββ vite.config.js
βββ infra/ # Telemetry, cryptographic KMS, and SIEM pipeline
β βββ event_bus.rs # Async Tokio broadcast event bus
β βββ secure_kms.rs # 45s Ephemeral key rotation & zeroization
β βββ secure_logger.rs # Tamper-evident hash-chained AES-256-GCM logging
β βββ siem_exporter.rs # CEF:0 and Elastic Common Schema (ECS) exporter
β βββ systemd/ # Hardened Linux service unit
βββ data/rules/ # Curated EDR detection rulesets
β βββ sigma/process_creation.yml
β βββ yara/edr_signatures.yar
βββ src/ # Library & Actix-Web API Server
β βββ api.rs # REST router & alert store
β βββ lib.rs # Crate root definitions
β βββ main.rs # Backend server entrypoint
β βββ ws.rs # WebSocket streaming actor
βββ tests/ # Comprehensive integration verification
β βββ integration_test.rs
βββ Cargo.toml # Rust project manifest
βββ Dockerfile # Production multi-stage build container
βββ docker-compose.yml # Turnkey cluster orchestration
Abyssal Watcher β Fortified Endpoint Defense for the Modern Threat Landscape.
Developed & Maintained under CNO Architecture Directives.