Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

33 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ ZENTRIX

Local-First Security Operations Center (SOC) Platform

Enterprise-grade Cybersecurity Command Center built for Security Analysts, SOC Teams, Researchers, and Security Enthusiasts.


πŸš€ Vision

Traditional SOC platforms are often cloud-dependent, expensive, and difficult to deploy in isolated environments.

ZENTRIX delivers a powerful Local-First Security Operations Center that provides real-time telemetry, threat monitoring, malware analysis, phishing detection, honeypot monitoring, automated reporting, and alerting from a single unified platform.

✨ Key Features

πŸ“Š Executive Security Dashboard

  • Real-time CPU Monitoring
  • Memory Utilization Tracking
  • Disk Health Monitoring
  • Network Throughput Analytics
  • Process Visibility
  • System Uptime Metrics
  • Live WebSocket Telemetry

πŸ” Security Information & Event Management (SIEM)

  • Live System Log Ingestion
  • Authentication Log Monitoring
  • Security Event Correlation
  • Event Timeline Visualization
  • Alert Generation Engine
  • Real-Time Log Streaming

Supported Sources

  • Linux Syslog
  • Authentication Logs
  • Custom Security Events
  • Simulated Events (Fallback Mode)

πŸ–₯️ Endpoint Detection & Response (EDR)

Monitor endpoint activities in real-time.

Capabilities

  • Running Process Monitoring
  • Suspicious Process Detection
  • Network Connection Tracking
  • File Activity Monitoring
  • Threat Indicator Detection

Threat Indicators

  • Netcat
  • Mimikatz
  • XMRig
  • Unauthorized Processes

🌐 Intrusion Detection System (IDS)

Gain visibility into network activity.

Features

  • Protocol Statistics
  • Bandwidth Analytics
  • Source/Destination Tracking
  • Packet Monitoring
  • Suricata Integration Support

🍯 Honeypot Monitoring

Capture and analyze unauthorized activities.

Features

  • Port Scan Detection
  • Unauthorized Connection Logging
  • Attack Visualization
  • Lightweight Built-in Honeypot
  • Cowrie Integration Support
  • OpenCanary Integration Support

🦠 Malware Analysis Engine

Upload and analyze suspicious files.

Analysis Capabilities

  • MD5 Hash Generation
  • SHA1 Hash Generation
  • SHA256 Hash Generation
  • Entropy Analysis
  • Metadata Extraction
  • String Extraction
  • VirusTotal Lookups
  • YARA Rule Matching
  • Sigma Rule Matching

File Limits

Maximum Upload Size: 500 MB

🎣 Phishing Detection Engine

Analyze suspicious emails and headers.

Features

  • EML Parsing
  • Email Header Analysis
  • SPF Validation
  • DKIM Validation
  • DMARC Validation
  • URL Reputation Analysis
  • Credential Harvesting Detection
  • Confidence Scoring

πŸ“„ Automated Security Reporting

Generate professional reports automatically.

Supported Formats

  • PDF
  • CSV
  • JSON

Report Types

  • Executive Reports
  • Security Reports
  • Audit Reports

πŸ“± Alert Delivery System

Receive alerts directly through:

  • WhatsApp
  • Email
  • Scheduled Reports
  • Incident Notifications

Additional Features

  • Delivery Logging
  • Retry Mechanism
  • Alert History
  • Delivery Tracking

πŸ—οΈ Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                ZENTRIX                  β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ React + TypeScript Frontend             β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Express.js API Layer                    β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ WebSocket Event Streaming               β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ SIEM β”‚ EDR β”‚ IDS β”‚ Honeypot β”‚ Reports   β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ MongoDB / JSON Fallback Storage         β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Local Operating System Telemetry        β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

🧠 Local-First Architecture

Primary Database

mongodb://localhost:27017/zentrix

Automatic Fallback Database

backend/data/

If MongoDB is unavailable, ZENTRIX automatically switches to JSON-based storage.


πŸ‘€ Profile-Based Authentication

Unlike traditional SOC platforms, ZENTRIX uses a streamlined single-user registration model.

Registration Fields

  • Full Name
  • Email Address
  • WhatsApp Number
  • Profile Photo

Benefits

βœ… No Password Required

βœ… No OAuth Dependency

βœ… Instant Future Access

βœ… Simplified User Experience


πŸ“ Storage Structure

storage/
β”‚
β”œβ”€β”€ uploads/
β”œβ”€β”€ reports/
β”œβ”€β”€ malware/
β”œβ”€β”€ phishing/
β”œβ”€β”€ logs/
└── backups/

πŸ› οΈ Technology Stack

Frontend

  • React
  • TypeScript
  • Redux Toolkit
  • React Router
  • Socket.IO Client

Backend

  • Node.js
  • Express.js
  • Socket.IO
  • System Information

Database

  • MongoDB
  • JSON File Storage

Security Technologies

  • YARA
  • Sigma Rules
  • VirusTotal API
  • SPF Validation
  • DKIM Validation
  • DMARC Validation

Reporting

  • PDFKit
  • Node Cron

Notifications

  • Twilio WhatsApp API
  • WhatsApp Business Cloud API
  • SMTP Email

⚑ Real-Time Telemetry

Telemetry updates every:

2 Seconds

Monitored Metrics

  • CPU Usage
  • RAM Usage
  • Disk Utilization
  • Network Throughput
  • Active Connections
  • Process Count
  • System Uptime

πŸ” Security Principles

  • Local-First Architecture
  • Privacy-Focused Design
  • Offline Capability
  • Least Privilege Approach
  • Secure Report Generation
  • Comprehensive Audit Logging

πŸ“ˆ Development Roadmap

Phase 1 β€” Foundation

  • Architecture Planning
  • ZENTRIX Rebranding
  • Authentication Redesign

Phase 2 β€” Core Monitoring

  • Real-Time Telemetry
  • SIEM Integration
  • EDR Monitoring
  • IDS Monitoring

Phase 3 β€” Threat Analysis

  • Malware Analysis Engine
  • Phishing Detection Engine
  • Honeypot Monitoring

Phase 4 β€” Automation

  • Automated Reporting
  • WhatsApp Integration
  • Email Alerting

Phase 5 β€” Production Release

  • Stable Release
  • Documentation
  • Installer Packaging

🎯 Target Audience

  • SOC Analysts
  • Security Engineers
  • Blue Team Operators
  • Incident Responders
  • Security Researchers
  • Cybersecurity Students
  • Enterprise Security Teams

πŸ“Έ Screenshots

Coming Soon...

🀝 Contributing

Contributions, feature suggestions, and security improvements are welcome.

  1. Fork the repository
  2. Create a feature branch
  3. Commit your changes
  4. Open a Pull Request

πŸ“œ License

MIT License

πŸ›‘οΈ Built With Security In Mind

ZENTRIX is designed to bring enterprise-grade visibility, monitoring, detection, and response capabilities directly to local environments while maintaining simplicity, performance, and operational control.


⚑ Observe. Detect. Analyze. Defend.

πŸ”₯ ZENTRIX β€” Your Local Cyber Defense Command Center.

About

ZENTRIX is a Local-First Security Operations Center (SOC) designed to unify real-time telemetry, threat monitoring, and automated reporting into a single platform. It supports malware analysis, phishing detection, and honeypot tracking to enhance localized security capabilities.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages