Skip to content

Latest commit

Β 

History

15 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

⚑ ABYSSAL WATCHER (v1.04-HARDENED) ⚑

Enterprise Host-Based Intrusion Detection (HIDS) & Endpoint Detection and Response (EDR)

Rust 2021 React 18 Docker MITRE ATT&CK Security Hardened

A mission-critical endpoint defense hypervisor fusing low-level assembly anti-analysis traps, in-memory SHA-256 cryptographic verification, pure-Rust YARA/Sigma correlation, dynamic rotating KMS envelopes, and real-time WebSocket telemetry.


πŸ›‘οΈ 1. Executive Summary

Abyssal Watcher is an industrial-grade, defense-in-depth Host-Based Intrusion Detection System (HIDS) and Endpoint Detection and Response (EDR) engine. Engineered for operation in untrusted, hostile, or contested host environments, it actively denies reverse-engineering attempts, identifies complex memory injections and process hollowing, correlates parent-child telemetry via Sigma rules, and streams structured alerts mapped to the MITRE ATT&CK matrix directly to Security Operations Centers (SOC).

 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚                      ABYSSAL WATCHER MULTI-VECTOR ARCHITECTURE                         β”‚
 β”‚                                                                                        β”‚
 β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    MemoryGuard / ASM Traps   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
 β”‚  β”‚ Hardware & OS Layer       β”‚ ───────────────────────────► β”‚ Low-Level Defenses    β”‚  β”‚
 β”‚  β”‚ (x86_64 CPUID / ptrace)   β”‚ ◄─────────────────────────── β”‚ (TF / RDTSC / Anti-VM)β”‚  β”‚
 β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                              β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
 β”‚                β”‚                                                                       β”‚
 β”‚                β–Ό                                                                       β”‚
 β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    Pure-Rust YARA & Sigma    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
 β”‚  β”‚ Multi-Vector Threat Engineβ”‚ ───────────────────────────► β”‚ MITRE ATT&CK Taxonomy β”‚  β”‚
 β”‚  β”‚ (Shannon Entropy / Heur)  β”‚                              β”‚ (T1055, T1059, T1027) β”‚  β”‚
 β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                              β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
 β”‚                β”‚                                                                       β”‚
 β”‚                β–Ό                                                                       β”‚
 β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    Tokio / Actix-Web / AES   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
 β”‚  β”‚ Telemetry & KMS Layer     β”‚ ───────────────────────────► β”‚ SIEM / SOC Dashboard  β”‚  β”‚
 β”‚  β”‚ (45s Key Rotation / Log)  β”‚                              β”‚ (CEF / ECS / WS Live) β”‚  β”‚
 β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                              β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β”‚
 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ—οΈ 2. Architecture & Defense-in-Depth

The platform is structured into four distinct, hardened architectural tiers:

πŸ”Ή Phase 1: Low-Level Engine & Anti-Analysis Hardening

  • NASM Assembly Modules:
    • anti_vm.asm: Interrogates CPUID leaf 1 (bit 31) and leaf 0x40000000 hypervisor vendor signatures (KVM, VMware, Hyper-V, Xen).
    • hook_detect.asm: Fast opcode scanner identifying prologue hooks, 0xE9 (JMP rel32), 0xEB (JMP rel8), 0xFF 0x25 (JMP indirect), 0x48 0xB8 (MOV RAX; JMP RAX), and 0x68 ... 0xC3 (PUSH/RET) trampolines.
    • anti_debug_ultra.asm: Direct CPU register polling (RFLAGS.TF), RDTSC timing latency delta thresholds, and memory INT3 scans.
  • MemoryGuard Integrity Engine: core/memory_guard.rs calculates standalone SHA-256 checksums over .text code segments to detect unauthorized runtime patching. Includes a Shannon entropy calculator ($0.0 - 8.0$) to flag encrypted/packed payloads ($>7.0$).
  • Zero-Exposure Mode (ZE_MODE): defense/ze_mode.rs enforces atomic lockdown and memory zeroization stubs using write_volatile.

πŸ”Ή Phase 2: Detection Engine Overhaul

  • Pure-Rust YARA Engine: analyzer/yara_engine.rs evaluates multi-string patterns and hex signatures without native C bindings or external dependencies.
  • Sigma Event Correlation: analyzer/sigma_parser.rs inspects process spawn trees (e.g. w3wp.exe $\rightarrow$ powershell.exe) and command-line arguments (-enc, bypass, iex).
  • MITRE ATT&CK Matrix Resolver: analyzer/mitre_matrix.rs enriches all detections with standard Enterprise Tactics (TA0001 - TA0040) and Technique IDs (T1055.001, T1055.012, T1027.002, T1059.001, T1003.001, T1622).
  • Adaptive Threat Cache: analyzer/threat_cache.rs provides a thread-safe LRU cache with temporal exponential decay ($e^{-\lambda t}$) and sliding hit counters.

πŸ”Ή Phase 3: Backend & Telemetry Maturation

  • Dynamic Ephemeral KMS: infra/secure_kms.rs automatically rotates 256-bit AES keys every 45 seconds (epoch_id) and immediately scrubs retired keys from memory.
  • Tamper-Evident Hash-Chained Logging: infra/secure_logger.rs wraps log records in authenticated AES-256-GCM AEAD envelopes bound via sequential SHA-256 chain hashes: $$\text{ChainHash}n = \text{SHA-256}(\text{EpochID} \mathbin{\Vert} \text{Nonce} \mathbin{\Vert} \text{ChainHash}{n-1} \mathbin{\Vert} \text{Ciphertext})$$
  • Non-Blocking Asynchronous EventBus: infra/event_bus.rs uses Tokio broadcast channels with a 2,048-message buffer for zero-lag alert dissemination.
  • SIEM Forwarding Pipeline: infra/siem_exporter.rs formats structured events for Splunk, Elastic Common Schema (ECS) JSON, and ArcSight Common Event Format (CEF:0).

πŸ”Ή Phase 4: UI/UX Operations Console & Deployment Packaging

  • React 18 SOC Dashboard: frontend/src/App.jsx built with TailwindCSS, dark cybersecurity styling, live WebSocket event consumption, interactive threat injection simulator, and host quarantine controls.
  • Hardened Docker Distribution: Multi-stage Dockerfile running an unprivileged system daemon on minimal attack surface Debian Bookworm Slim with Link-Time Optimization (LTO).
  • Linux Sandboxing Service: infra/systemd/abyssal_watcher.service with ProtectSystem=strict, NoNewPrivileges=true, and strict cgroup resource constraints.

🧰 3. Prerequisites & Toolchain

Component Minimum Version Purpose
Rust Toolchain 1.75+ (2021 Edition) Core binary compilation (cargo, rustc)
Node.js / npm v18.0.0+ React 18 Frontend Console (vite, tailwindcss)
NASM 2.15+ x86_64 Assembly Traps Compiler
Docker & Compose 24.0+ / v2.20+ Containerized Multi-Stage Cluster Deployment

πŸš€ 4. Execution & Deployment Guide

A. Run the Standalone Security Scanner

Inspects system integrity, executes anti-debug/anti-VM traps, and runs multi-vector heuristic evaluation:

cargo run --bin abyssal_entrypoint

B. Run the Telemetry & EDR Backend Daemon

Launches the Actix-Web REST API server and WebSocket broadcast engine on 0.0.0.0:8080:

cargo run --bin abyssal_watcher

C. Spin Up the React SOC Console (Development)

cd frontend
npm install
npm run dev
# Operations console available at http://localhost:3000

D. Production Container Cluster (One-Command Deployment)

Builds optimized binaries, bundles the frontend, and deploys the hardened EDR container:

docker-compose up -d --build
# REST API & Console exposed on http://localhost:8080

E. Run Full Integration Verification Suite

cargo test --test integration_test -- --nocapture

πŸ“‘ 5. API & SIEM Integration

Core REST Endpoints

Method Endpoint Description Sample Output
GET /api/status Host engine health & defense status {"system":"Abyssal Watcher","ze_mode_enabled":true,"memory_guard_status":"SEALED"}
POST /api/heartbeat Ingests agent telemetry heartbeat {"status":"ACK","acknowledged_at":1723224000000}
GET /api/alerts Paginated threat alerts (?page=1&limit=20) {"total":1,"items":[{"id":1,"assessment":{...}}]}
POST /api/threats Submits memory buffer/process for scan Returns full normalized ThreatAssessment JSON

Live WebSocket Stream

  • Endpoint: ws://localhost:8080/ws/telemetry
  • Protocol: JSON event frames pushed over low-latency Tokio broadcast channels.
  • Payload Structure:
{
  "topic": "threat.detection",
  "level": "CRITICAL",
  "timestamp": 1723224150000,
  "payload": "{\"composite_score\":85,\"confidence_level\":\"CRITICAL\",\"mitre_techniques\":[{\"id\":\"T1055.001\",\"name\":\"DLL Injection\"}]}"
}

SIEM Formats

# ArcSight Common Event Format (CEF:0)
CEF:0|AbyssalWatcher|EDR|1.04|THREAT_DETECTED|Abyssal_Reflective_DLL_Loader|10|dhost=endpoint.corp cs1Label=MITRE cs1=T1055.001:DLL Injection cn1Label=CompositeScore cn1=85 cs2Label=Confidence cs2=CRITICAL

πŸ“„ 6. Repository Layout

abyssal_watcher/
β”œβ”€β”€ analyzer/                 # Threat evaluation, YARA, Sigma, and MITRE resolution
β”‚   β”œβ”€β”€ mitre_matrix.rs       # MITRE ATT&CK taxonomy dictionary & lookup
β”‚   β”œβ”€β”€ ml_analyzer.rs        # Behavioral keyword & n-gram heuristics
β”‚   β”œβ”€β”€ sigma_parser.rs       # AST-based Sigma process correlation engine
β”‚   β”œβ”€β”€ threat_cache.rs       # High-speed LRU cache with exponential score decay
β”‚   └── yara_engine.rs        # Pure-Rust regex/bytecode YARA evaluator
β”œβ”€β”€ core/                     # Low-level systems primitives and integrity seals
β”‚   β”œβ”€β”€ asm_module/           # Assembly anti-analysis traps
β”‚   β”‚   β”œβ”€β”€ anti_debug.asm    # 16-bit Trap Flag inspector
β”‚   β”‚   β”œβ”€β”€ anti_debug_ultra.asm # 64-bit TF, RDTSC timing, and INT3 traps
β”‚   β”‚   β”œβ”€β”€ anti_vm.asm       # CPUID hypervisor bit & artifact checks
β”‚   β”‚   └── hook_detect.asm   # JMP/CALL/Trampoline prologue hook scanner
β”‚   └── memory_guard.rs       # SHA-256 .text hashing & Shannon entropy engine
β”œβ”€β”€ defense/                  # Runtime host defenses and sandbox reduction
β”‚   β”œβ”€β”€ anti_debug.rs         # TracerPid, wchan, and PTRACE_TRACEME detection
β”‚   β”œβ”€β”€ anti_vm.rs            # CPUID intrinsics & Linux DMI table inspection
β”‚   └── ze_mode.rs            # Zero-Exposure Mode & volatile memory zeroization
β”œβ”€β”€ engine/                   # Multi-vector threat aggregation
β”‚   └── threat_detector.rs    # Unified composite score (0-100) calculation
β”œβ”€β”€ entrypoint/               # Standalone verification scanner binary
β”‚   └── main.rs
β”œβ”€β”€ frontend/                 # React 18 + TailwindCSS SOC Console
β”‚   β”œβ”€β”€ src/
β”‚   β”‚   β”œβ”€β”€ components/       # ThreatMatrix, LiveTelemetry, DefenseStatus
β”‚   β”‚   β”œβ”€β”€ App.jsx           # Master operations dashboard & simulator
β”‚   β”‚   └── main.jsx
β”‚   β”œβ”€β”€ package.json
β”‚   └── vite.config.js
β”œβ”€β”€ infra/                    # Telemetry, cryptographic KMS, and SIEM pipeline
β”‚   β”œβ”€β”€ event_bus.rs          # Async Tokio broadcast event bus
β”‚   β”œβ”€β”€ secure_kms.rs         # 45s Ephemeral key rotation & zeroization
β”‚   β”œβ”€β”€ secure_logger.rs      # Tamper-evident hash-chained AES-256-GCM logging
β”‚   β”œβ”€β”€ siem_exporter.rs      # CEF:0 and Elastic Common Schema (ECS) exporter
β”‚   └── systemd/              # Hardened Linux service unit
β”œβ”€β”€ data/rules/               # Curated EDR detection rulesets
β”‚   β”œβ”€β”€ sigma/process_creation.yml
β”‚   └── yara/edr_signatures.yar
β”œβ”€β”€ src/                      # Library & Actix-Web API Server
β”‚   β”œβ”€β”€ api.rs                # REST router & alert store
β”‚   β”œβ”€β”€ lib.rs                # Crate root definitions
β”‚   β”œβ”€β”€ main.rs               # Backend server entrypoint
β”‚   └── ws.rs                 # WebSocket streaming actor
β”œβ”€β”€ tests/                    # Comprehensive integration verification
β”‚   └── integration_test.rs
β”œβ”€β”€ Cargo.toml                # Rust project manifest
β”œβ”€β”€ Dockerfile                # Production multi-stage build container
└── docker-compose.yml        # Turnkey cluster orchestration

Abyssal Watcher β€” Fortified Endpoint Defense for the Modern Threat Landscape.
Developed & Maintained under CNO Architecture Directives.

About

> Abyssal Watcher is a military-grade, hardened surveillance and cyber defense framework built in Rust. Designed for behavioral threat analysis, adaptive system defense, and deep memory inspection, it enables resilient real-time monitoring in highly hostile environments.

Resources

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages