Commit Graph
46 Commits
Author SHA1 Message Date
IgorRachkov ae048ac1c8 Add project resolution for registry submission 2026-06-12 22:46:33 +03:00
IgorRachkov ded569207e Add professional highlights for AWatch-rus 2026-06-12 22:41:35 +03:00
IgorRachkov 55c0d06baa Добавить профессиональные сильные стороны проекта 2026-06-12 22:40:05 +03:00
IgorRachkovandGitHub 3b5fe0c116 Update COMPETITIVE_POSITIONING_RU.md 2026-06-12 22:17:34 +03:00
IgorRachkovandGitHub a2575233b7 Update COMPETITIVE_POSITIONING_RU.md 2026-06-12 22:14:34 +03:00
IgorRachkovandGitHub 02967629ff Update README.md 2026-06-12 15:30:45 +03:00
IgorRachkovandGitHub da84a9a800 Create TASK_016_UEBA_CONFIDENCE_GUARDRAILS.md 2026-06-07 22:18:11 +03:00
IgorRachkovandGitHub 32e1a97877 Create TASK_015_UEBA_CRITICAL_EVIDENCE_REVIEW 2026-06-07 22:03:49 +03:00
IgorRachkovandGitHub c751035374 Create TASK_014_DEPLOYMENT_DRIFT_REMEDIATION.md 2026-06-07 21:48:29 +03:00
IgorRachkovandGitHub ff6d7155cd Create TASK_013_DETMIR_PRODUCTION_VALIDATION.md 2026-06-07 21:25:57 +03:00
IgorRachkovandGitHub 5820de1d85 Add visual conformance smoke testing documentation 2026-06-07 20:25:46 +03:00
IgorRachkovandGitHub 0b34782b8e TASK_009
Added a detailed conformance audit document for DetMir/AWatch roadmap, outlining required checks, goals, and audit areas.
2026-06-07 19:52:03 +03:00
IgorRachkovandGitHub 56134e832a Update TASK_010_PILOT_VALIDATION.md 2026-06-07 19:00:51 +03:00
IgorRachkovandGitHub cb943d1328 Create TASK_010_PILOT_VALIDATION.md 2026-06-07 19:00:16 +03:00
IgorRachkovandGitHub 9fa085a53e Update TASK_009_ENTERPRISE_DEPLOYMENT_GUIDE.md 2026-06-07 17:15:50 +03:00
IgorRachkovandGitHub 7c57bac03c Create TASK_009_ENTERPRISE_DEPLOYMENT_GUIDE.md 2026-06-07 17:14:23 +03:00
IgorRachkovandGitHub 755c8b6f0f Update TASK_008_REGISTRY_READINESS.md 2026-06-07 17:04:42 +03:00
IgorRachkovandGitHub 4c39dd3fb0 Update TASK_007_CUSTOMER_DEMO_PACK.md 2026-06-07 16:45:47 +03:00
IgorRachkovandGitHub 307170b128 Update TASK_006_EXECUTIVE_ACTION_CENTER.md 2026-06-07 16:21:52 +03:00
IgorRachkovandGitHub a734815a63 Create TASK_006_EXECUTIVE_ACTION_CENTER.md 2026-06-07 16:20:27 +03:00
IgorRachkovandGitHub 41e28adbf9 Delete TASK_006_PFSENSE_CONTRACT_LAYER.md 2026-06-07 16:17:15 +03:00
IgorRachkovandGitHub 00ff5e7ddf Update TASK_005_RUST_AGENT_BASELINE.md 2026-06-07 15:50:39 +03:00
IgorRachkovandGitHub 5277097032 Update TASK_004_RISK_NARRATIVE.md 2026-06-07 15:32:18 +03:00
IgorRachkovandGitHub 2fb3271558 Create TASK_003A_PORTAL_HARDENING_CLEANUP.md 2026-06-07 14:17:15 +03:00
IgorRachkovandGitHub 7df665a457 Update TASK_003_EXPLAINABLE_KPI.md 2026-06-07 13:34:33 +03:00
IgorRachkovandGitHub e43c502bcb Update TASK_002_PRODUCTION_HARDENING.md 2026-06-07 13:32:57 +03:00
IgorRachkovandGitHub 77ad99d8a7 Update README.md 2026-06-07 13:28:52 +03:00
IgorRachkovandGitHub 45f9907450 Update PRESENTATION_RU.md 2026-05-15 17:02:18 +03:00
IgorRachkovandGitHub 95bf1edd37 Merge pull request #24 from igor04091968/codex/-e2e-grafana-+-prometheus
Harden Grafana Prometheus e2e readiness
2026-05-09 05:22:16 +03:00
IgorRachkov dc8988e5f7 Harden Grafana Prometheus e2e readiness 2026-05-09 03:58:52 +03:00
IgorRachkovandGitHub 5e5cb30fab Merge pull request #15 from igor04091968/devin/1777897921-print-docname-ansible-innosetup
fix(print): исправление имени документа «Печать документа» + интеграция email collector в деплой
2026-05-07 07:34:42 +03:00
IgorRachkovandGitHub 083b05d096 Merge pull request #19 from igor04091968/codex/-rdp
Fix Windows/RDP collectors startup and make bucket creation idempotent
2026-05-07 07:34:20 +03:00
IgorRachkovandGitHub eb25a230fc Merge pull request #3 from igor04091968/codex/explain-codebase-structure-to-beginner
Add newcomer onboarding guide and link it from README
2026-05-07 07:32:03 +03:00
IgorRachkovandGitHub 96ee17f156 Merge pull request #6 from igor04091968/codex/validate-ansible-playbooks-in-repository
Add install-kit validation tools and add Ansible syntax check to quality gate
2026-05-07 07:31:54 +03:00
IgorRachkovandGitHub 66a8c47319 Merge pull request #7 from igor04091968/codex/find-and-fix-error-in-powershell-dlp-script
Refine detection of masked Cyrillic print titles and normalize printer names
2026-05-07 07:31:50 +03:00
IgorRachkovandGitHub 5a89a79803 Merge pull request #13 from igor04091968/devin/1777839496-strategic-dlp-roadmap
docs: стратегический DLP roadmap — AWatch-rus vs InfoWatch Traffic Monitor
2026-05-07 07:31:44 +03:00
IgorRachkovandGitHub a00bbdee06 Merge pull request #16 from igor04091968/codex/analyze-powershell-scripts-for-functionality
Fix DLP PowerShell collectors: config default, HTTP handling, event cleanup, headless fallback
2026-05-07 07:31:38 +03:00
IgorRachkovandGitHub 9ef09cb892 Merge pull request #18 from igor04091968/codex/review-dlp-related-code
Add print-job dedupe, improve clipboard guards and add polling error logs
2026-05-07 07:31:33 +03:00
IgorRachkov b2a1a6289c Fix Windows RDP collectors startup 2026-05-06 17:23:47 +03:00
IgorRachkov 945efd203f Harden DLP endpoint collector error handling and print dedupe 2026-05-05 07:55:03 +03:00
IgorRachkov d88ef78184 Fix DLP collector defaults, HTTP error handling, and cleanup 2026-05-04 21:47:03 +03:00
IgorRachkovGitHubFashion LisaDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
eea851141f feat(dlp): enforcement + email outbound collector (#14)
* feat(dlp): add enforcement — USB write-block, print cancel, clipboard clear

Phase 2.5: when DLP policy rule has action="block", the collector
now actively prevents the action instead of just logging:

- USB: Set-Disk -IsReadOnly via Get-Partition/Get-Disk pipeline
- Print: Remove-CimInstance Win32_PrintJob for matching jobs
- Clipboard: Set-Clipboard -Value $null to clear sensitive content

Each enforcement adds enforced=true/false to incident telemetry.
Windows balloon notification shown to user on every block action.
Backward-compatible: existing action="alert" rules unchanged.

Co-Authored-By: Fashion Lisa <igor04091968@gmail.com>

* feat(dlp): add email outbound collector — Outlook COM + SMTP monitor

Two collection modes:
- outlook: polls Sent Items via COM, extracts metadata (subject hash,
  recipients hash, attachment names, body length)
- smtp: monitors SMTP connections (25/587/465/2525) via Get-NetTCPConnection

DLP policy rules: endpoint.email[] with regex matching on subject,
recipients, sender, attachments, externalOnly flag.

Enforcement: action=block moves mail to Drafts (Outlook mode).
Privacy: subject/recipients stored as SHA256, body never read.
Co-Authored-By: Fashion Lisa <igor04091968@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-04 00:23:06 +03:00
IgorRachkovGitHubDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
36e4255ad9 fix: handle undefined bucket filters in AQL query rewriter (#12)
The network patch that intercepts /api/0/query/ requests only handled
'unknown' hostnames in bucket IDs. When the WebUI activity store has
uninitialized bucket IDs (e.g. browser watcher not installed on a host),
find_bucket("undefined") or query_bucket("undefined") calls reach the
server and fail with BucketQueryError.

Extend rewriteUnknownCategoryBuilderQueryBody to:
- Replace query_bucket(find_bucket("undefined")) and flood() wrappers
  with empty arrays ([]) so the query continues without missing data.
- Rewrite aw-watcher-{window,afk}_undefined to the preferred host,
  matching the existing 'unknown' hostname logic.

Applied to both aw-server/ and install-kit copies of aw-ru-patch.js.

Fixes: BucketЗапросError on Trends page for host SHARKON2025

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-03 22:27:50 +03:00
IgorRachkov 8f10bef904 Limit print title fallback to masked Russian document names 2026-05-01 15:50:02 +03:00
IgorRachkov aca42caf0a Add install-kit to repo drift checker 2026-04-30 20:59:40 +03:00
IgorRachkov 9bdf28ed2b Add newcomer onboarding guide for repository structure 2026-04-29 13:09:23 +03:00