3765d4d476
Add optional auto logoff of stuck sessions on RDG flap and direct RDP failure. Hide the RDS break button on old flap 302 when the user later reconnects or the workstation session is closed. Co-authored-by: Cursor <cursoragent@cursor.com>
2.2 KiB
2.2 KiB
Security Alert Center (SAC)
Self-hosted hub for security events from Linux and Windows agents: ingest, correlation, UI, notifications, host management.
Русский: README.md
Repositories
| Repository | Role |
|---|---|
| ssh-monitor | Linux agent |
| RDP-login-monitor | Windows agent |
| security-alert-center | SAC server (Ubuntu 24.04) |
| seaca | Android client |
Version: 0.4.10 · Deploy: sudo /opt/sac-deploy.sh
Features
- Ingest from agents (contract): SSH/sudo/logind, RDP/RDG/WinRM/SMB, heartbeat, reports, inventory
- Problems — auto-correlation (incl. RDG 302→303 flap within 1–10 s)
- Notifications — Telegram, email, webhook, FCM (Seaca)
- Web UI — events, hosts, problems, reports, dashboard (SSE), settings (admin)
- RDG flap — badge on 302/303 events, qwinsta/logoff via WinRM to client PC (domain admin required); optional auto-disconnect of stuck sessions
- Hosts — agent status, inventory, agent updates (SSH/WinRM); WinRM RDP: SAC fetches from git, client downloads zip from SAC, runs local
Deploy-LoginMonitor.ps1(no git on PC) - Mobile — enrollment, devices, push; Seaca: ack/resolve, qwinsta/logoff via SAC API
- Roles —
admin/monitor
Documentation
| Document | Description |
|---|---|
| docs/agent-integration.md | Agents, UseSAC, event types |
| docs/agent-control-plane.md | RDG flap, qwinsta, agent updates |
| docs/install-ubuntu-24.04-native.md | Native install |
| docs/deployment.md | Operations |
Quick start
git clone https://git.kalinamall.ru/PapaTramp/security-alert-center.git /opt/security-alert-center
# deploy/env.native.example -> config/sac-api.env
cd /opt/security-alert-center/backend && python3 -m venv .venv
.venv/bin/pip install -r requirements.txt && .venv/bin/alembic upgrade head
License
MIT — LICENSE.