Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Windows Insider Threat Detection and Forensic Evidence Collection System

🎯 Project Overview

This is a consent-based organizational security tool designed to detect malicious or suspicious insider activities, collect forensically sound digital evidence, and generate court-ready incident reports.

⚖️ Legal Notice

IMPORTANT: This tool is designed for legitimate organizational security purposes only.

  • Requires explicit user consent and policy acceptance
  • Must be deployed with proper legal authorization
  • For organizational use only - NOT for illegal surveillance
  • Follows chain of custody and forensic best practices

📁 Project Structure

├── agent/                  # Background Windows agent
│   ├── core/              # Core agent framework
│   ├── monitors/          # Monitoring modules
│   ├── forensics/         # Evidence collection
│   └── analysis/          # Behavior analysis
├── dashboard/             # Admin web dashboard
│   ├── backend/           # Flask API
│   ├── frontend/          # Web UI
│   └── reports/           # Report generation
├── database/              # Database files and schemas
├── logs/                  # Encrypted log storage
├── evidence/              # Evidence repository
├── config/                # Configuration files
├── docs/                  # Documentation
├── tests/                 # Test suite
└── deployment/            # Deployment scripts

🚀 Quick Start

See docs/INSTALLATION.md for detailed setup instructions.

📚 Documentation

🔒 Security Features

  • SHA256 hashing for all evidence
  • Encrypted log storage
  • Anti-tamper detection
  • Chain of custody tracking
  • Immutable audit logs

📋 Key Features

✅ File system monitoring (mass copy/delete/encrypt detection) ✅ USB device tracking with file transfer logs ✅ Process and command monitoring ✅ Deleted file forensics ✅ Behavior-based risk scoring ✅ Secure admin dashboard ✅ Court-ready PDF reports

🎓 Academic Project

This project is developed as a major college project with complete documentation suitable for academic evaluation and viva voce examination.

📄 License

This project is for educational and authorized organizational use only.

About

A consent-based Windows security & digital forensics system designed to detect insider threats, track behavioral anomalies, preserve chain-of-custody evidence, and generate court-ready incident reports.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages