8a451a0c49877e66eb10fbfab90febb502c41a65
Security Alert Center (SAC)
Self-hosted hub for security events from Linux and Windows agents: ingest, correlation, UI, notifications, host management.
Русский: README.md
Repositories
| Repository | Role |
|---|---|
| ssh-monitor | Linux agent |
| RDP-login-monitor | Windows agent |
| security-alert-center | SAC server (Ubuntu 24.04) |
| seaca | Android client |
Version: 0.20.18 · Deploy: sudo /opt/sac-deploy.sh
Features
- Ingest from agents (contract): SSH/sudo/logind, RDP/RDG/WinRM/SMB, heartbeat, reports, inventory
- Problems — auto-correlation (incl. RDG 302→303 flap within 1–10 s)
- Notifications — Telegram, email, webhook, FCM (Seaca)
- Web UI — events, hosts, problems, reports, dashboard (SSE), settings (admin)
- RDG flap — badge on 302/303 events, qwinsta/logoff via WinRM to client PC (domain admin required)
- Hosts — agent status, inventory, agent updates (SSH/WinRM); WinRM RDP: SAC fetches from git, client downloads zip from SAC, runs local
Deploy-LoginMonitor.ps1(no git on PC) - Mobile — enrollment, devices, push; Seaca: ack/resolve, qwinsta/logoff via SAC API
- Roles —
admin/monitor
Documentation
| Document | Description |
|---|---|
| docs/agent-integration.md | Agents, UseSAC, event types |
| docs/agent-control-plane.md | RDG flap, qwinsta, agent updates |
| docs/install-ubuntu-24.04-native.md | Native install |
| docs/deployment.md | Operations |
Quick start
git clone https://git.kalinamall.ru/PapaTramp/security-alert-center.git /opt/security-alert-center
# deploy/env.native.example -> config/sac-api.env
cd /opt/security-alert-center/backend && python3 -m venv .venv
.venv/bin/pip install -r requirements.txt && .venv/bin/alembic upgrade head
License
MIT — LICENSE.
Description
Languages
Python
73%
Vue
19.1%
TypeScript
5.8%
Shell
1.3%
CSS
0.6%
Other
0.1%