This is a consent-based organizational security tool designed to detect malicious or suspicious insider activities, collect forensically sound digital evidence, and generate court-ready incident reports.
IMPORTANT: This tool is designed for legitimate organizational security purposes only.
- Requires explicit user consent and policy acceptance
- Must be deployed with proper legal authorization
- For organizational use only - NOT for illegal surveillance
- Follows chain of custody and forensic best practices
├── agent/ # Background Windows agent
│ ├── core/ # Core agent framework
│ ├── monitors/ # Monitoring modules
│ ├── forensics/ # Evidence collection
│ └── analysis/ # Behavior analysis
├── dashboard/ # Admin web dashboard
│ ├── backend/ # Flask API
│ ├── frontend/ # Web UI
│ └── reports/ # Report generation
├── database/ # Database files and schemas
├── logs/ # Encrypted log storage
├── evidence/ # Evidence repository
├── config/ # Configuration files
├── docs/ # Documentation
├── tests/ # Test suite
└── deployment/ # Deployment scripts
See docs/INSTALLATION.md for detailed setup instructions.
- SHA256 hashing for all evidence
- Encrypted log storage
- Anti-tamper detection
- Chain of custody tracking
- Immutable audit logs
✅ File system monitoring (mass copy/delete/encrypt detection) ✅ USB device tracking with file transfer logs ✅ Process and command monitoring ✅ Deleted file forensics ✅ Behavior-based risk scoring ✅ Secure admin dashboard ✅ Court-ready PDF reports
This project is developed as a major college project with complete documentation suitable for academic evaluation and viva voce examination.
This project is for educational and authorized organizational use only.