Commit Graph
70 Commits
Author SHA1 Message Date
igor04091968 f7114bde03 feat(1c): add company intelligence forecasting layer 2026-05-22 10:11:53 +03:00
igor04091968 172d113536 docs(1c): add production deployment guide 2026-05-22 09:06:39 +03:00
igor04091968 04b45ecf03 feat(1c): add file-based analytics stack scaffold 2026-05-21 23:34:55 +03:00
igor04091968 0c88b519ee feat(hayabusa): add auto-case scoring and 6h automation 2026-05-21 20:47:49 +03:00
igor04091968 dc2240d635 fix(hayabusa): close phase17 live production validation 2026-05-21 16:02:23 +03:00
igor04091968 63f00587a6 docs(runbook): add phase17 hayabusa validation path 2026-05-21 15:24:24 +03:00
igor04091968 99143b108b feat(aw-rus): sync deploy stack, install kit, and health checks 2026-05-21 15:16:23 +03:00
IgorRachkovandGitHub 45f9907450 Update PRESENTATION_RU.md 2026-05-15 17:02:18 +03:00
igor04091968 77e073c20c docs(presentation): refresh AW-rus DLP review screenshot 2026-05-15 09:56:15 +03:00
igor04091968 9b22f6f3fb docs(presentation): add per-user worktime report screenshot 2026-05-15 09:52:01 +03:00
igor04091968 4f11094081 fix(grafana): make DLP overview use live influx data 2026-05-15 09:45:13 +03:00
igor04091968 25c3ac3d2d docs(presentation): refresh DLP overview screenshot 2026-05-15 09:37:33 +03:00
igor04091968 4fb1c9335e docs(grafana): add dashboard import playbook and presentation assets 2026-05-15 09:20:02 +03:00
igor04091968 15941e48cb docs(sales): add russian sales overview and switch calendar day start 2026-05-15 07:16:24 +03:00
igor04091968 0cce6fd08e feat(dfir): add hayabusa forensic workflow integration 2026-05-14 15:04:07 +03:00
igor04091968 91c3b46f16 fix(ops): sync verified production baseline for AW-Rus DLP 2026-05-13 22:50:42 +03:00
igor04091968 b69f4d83cc docs(security): add implemented DLP functional profile for infosec 2026-05-13 07:35:22 +03:00
igor04091968 eb09251118 DLP 2026-05-13 07:22:27 +03:00
igor04091968 fd2e9ac59d feat(dlp): implement SIEM/SOAR integrations (CEF, webhook, syslog, systemd timers) 2026-05-13 02:30:52 +03:00
igor04091968 c624db5dd7 feat(dlp-policy): add approval workflow, full audit trail, and CRUD documentation 2026-05-12 01:11:01 +03:00
igor04091968 9342e8b907 feat(ops): extend aw health check with dlp transport freshness 2026-05-11 22:36:52 +03:00
igor04091968 5d7137379c docs(runbook): add deterministic WAL failover test for windows collectors 2026-05-11 22:32:58 +03:00
igor04091968 e0561bf865 fix(windows): disable outlook popup and enforce smtp-only email monitoring 2026-05-11 20:46:39 +03:00
igor04091968 4b5c75bdbb feat(dlp): deploy hayabusa IOC refresh on aw-server with post-deploy checks 2026-05-10 03:13:28 +03:00
igor04091968 c43f9b8708 feat(dlp): add hayabusa sigma IOC extraction pipeline 2026-05-09 17:02:31 +03:00
igor04091968 e80272a55f docs(installer): document standalone service mode and minimal host/port setup 2026-05-08 00:44:48 +03:00
igor04091968 6f5e5eb751 Revert "merge: apply windows standalone service installer and awHostname hardening"
This reverts commit e643576aa9, reversing
changes made to 669501f20a.
2026-05-08 00:41:00 +03:00
igor04091968 f3c5e9ea53 feat(dlp-hardening): secure inventory and extend aggregator sources 2026-05-07 23:38:20 +03:00
igor04091968 0c5069c255 chore(ops): harden rollout gates and sanitize generated artifacts 2026-05-07 19:50:02 +03:00
IgorRachkovandGitHub eb25a230fc Merge pull request #3 from igor04091968/codex/explain-codebase-structure-to-beginner
Add newcomer onboarding guide and link it from README
2026-05-07 07:32:03 +03:00
IgorRachkovandGitHub 5a89a79803 Merge pull request #13 from igor04091968/devin/1777839496-strategic-dlp-roadmap
docs: стратегический DLP roadmap — AWatch-rus vs InfoWatch Traffic Monitor
2026-05-07 07:31:44 +03:00
igor04091968andDevin <158243242+devin-ai-integration[bot]@users.noreply.github.com> eb83a8b08f docs(wiki): add GitHub wiki pages for documentation
- Home page with navigation and quick start
- Architecture overview with layers and data flows
- Components documentation for all system parts
- Interactive map guide with usage instructions
- DLP Endpoint Monitoring detailed guide
- Browser Domains Monitoring guide
- WebUI Russian Patches documentation
- Windows Installation guide
- Server Setup guide
- Monitoring Setup with Prometheus/Grafana

Generated with [Devin](https://cli.devin.ai/docs)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:56:30 +03:00
igor04091968andDevin <158243242+devin-ai-integration[bot]@users.noreply.github.com> 7a89f33e3b docs(diagrams): add interactive architecture map HTML
- Interactive component map with visual connections
- Click to see component details and data flows
- Search functionality for quick component lookup
- Connection highlighting when selecting components
- Responsive design with color-coded layers
- Component information panel with ports, protocols, flows

Generated with [Devin](https://cli.devin.ai/docs)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:51:25 +03:00
igor04091968andDevin <158243242+devin-ai-integration[bot]@users.noreply.github.com> d8320799e6 docs(diagrams): add component-level architecture diagrams
- DLP Endpoint Monitoring diagram with data flows
- Browser Domains Monitoring with categorization
- WebUI Russian Localization patches structure
- DLP Events Aggregation pipeline
- Prometheus Metrics Exporter architecture
- System overview with all components and connections

Generated with [Devin](https://cli.devin.ai/docs)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:49:55 +03:00
igor04091968andDevin <158243242+devin-ai-integration[bot]@users.noreply.github.com> db1998c428 docs(architecture): add readable architecture diagrams
- Add Mermaid diagram for high-level architecture
- Add simple ASCII architecture for quick understanding
- Document data flows for all monitoring scenarios
- Include deployment steps and port mappings
- Add quick start guide and key scenarios

Generated with [Devin](https://cli.devin.ai/docs)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:46:50 +03:00
igor04091968andDevin <158243242+devin-ai-integration[bot]@users.noreply.github.com> f6074facf5 docs(graphify): add detailed knowledge graph documentation for wiki
- Explain what knowledge graph is and why it's useful
- Document all 27 communities with purposes
- Describe key components: DLP monitoring, WebUI patches, collectors
- Provide usage guide for interactive visualization
- Include statistics and architecture recommendations

Generated with [Devin](https://cli.devin.ai/docs)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-05 01:45:32 +03:00
igor04091968andDevin <158243242+devin-ai-integration[bot]@users.noreply.github.com> 9e5cb144d4 fix(windows): standardize config paths to AWatch-rus and add bucket hostname filter
- Replace default config paths from C:\ProgramData\ActivityWatch to C:\ProgramData\AWatch-rus
  in dlp-endpoint-signals-collector.ps1 and email-outbound-collector.ps1
- Add isLikelyClientHost() function to reject IP/localhost as valid hostname
  for bucket selection in aw-ru-patch.js
- Add docs/dlp-reliability-roadmap.md and docs/powershell-analysis.md
- Update README.md with links to new documentation

Generated with [Devin](https://cli.devin.ai/docs)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-04 23:24:49 +03:00
igor04091968 e2b2f805fb Merge remote-tracking branch 'origin/devin/1777752962-file-collector-bucket' 2026-05-04 06:05:39 +03:00
IgorRachkovGitHubFashion LisaDevin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
eea851141f feat(dlp): enforcement + email outbound collector (#14)
* feat(dlp): add enforcement — USB write-block, print cancel, clipboard clear

Phase 2.5: when DLP policy rule has action="block", the collector
now actively prevents the action instead of just logging:

- USB: Set-Disk -IsReadOnly via Get-Partition/Get-Disk pipeline
- Print: Remove-CimInstance Win32_PrintJob for matching jobs
- Clipboard: Set-Clipboard -Value $null to clear sensitive content

Each enforcement adds enforced=true/false to incident telemetry.
Windows balloon notification shown to user on every block action.
Backward-compatible: existing action="alert" rules unchanged.

Co-Authored-By: Fashion Lisa <igor04091968@gmail.com>

* feat(dlp): add email outbound collector — Outlook COM + SMTP monitor

Two collection modes:
- outlook: polls Sent Items via COM, extracts metadata (subject hash,
  recipients hash, attachment names, body length)
- smtp: monitors SMTP connections (25/587/465/2525) via Get-NetTCPConnection

DLP policy rules: endpoint.email[] with regex matching on subject,
recipients, sender, attachments, externalOnly flag.

Enforcement: action=block moves mail to Drafts (Outlook mode).
Privacy: subject/recipients stored as SHA256, body never read.
Co-Authored-By: Fashion Lisa <igor04091968@gmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-05-04 00:23:06 +03:00
igor04091968 ff548a5840 Merge PR #14: feat(dlp) enforcement + email outbound collector 2026-05-03 23:41:00 +03:00
Devin AIandFashion Lisa f916764d53 feat(dlp): add email outbound collector — Outlook COM + SMTP monitor
Two collection modes:
- outlook: polls Sent Items via COM, extracts metadata (subject hash,
  recipients hash, attachment names, body length)
- smtp: monitors SMTP connections (25/587/465/2525) via Get-NetTCPConnection

DLP policy rules: endpoint.email[] with regex matching on subject,
recipients, sender, attachments, externalOnly flag.

Enforcement: action=block moves mail to Drafts (Outlook mode).
Privacy: subject/recipients stored as SHA256, body never read.
Co-Authored-By: Fashion Lisa <igor04091968@gmail.com>
2026-05-03 20:30:18 +00:00
Devin AIandFashion Lisa 2bab84f9f9 feat(dlp): add enforcement — USB write-block, print cancel, clipboard clear
Phase 2.5: when DLP policy rule has action="block", the collector
now actively prevents the action instead of just logging:

- USB: Set-Disk -IsReadOnly via Get-Partition/Get-Disk pipeline
- Print: Remove-CimInstance Win32_PrintJob for matching jobs
- Clipboard: Set-Clipboard -Value $null to clear sensitive content

Each enforcement adds enforced=true/false to incident telemetry.
Windows balloon notification shown to user on every block action.
Backward-compatible: existing action="alert" rules unchanged.

Co-Authored-By: Fashion Lisa <igor04091968@gmail.com>
2026-05-03 20:21:39 +00:00
Devin AIandFashion Lisa 6640299a48 docs: add strategic DLP roadmap vs InfoWatch Traffic Monitor
Co-Authored-By: Fashion Lisa <igor04091968@gmail.com>
2026-05-03 20:18:19 +00:00
Devin AI 5a4064dc0f Add DLP incident aggregation prototype 2026-05-02 20:55:44 +00:00
Devin AI 2e49310023 Добавить безопасную миграцию prod в AWatch-rus 2026-05-02 11:58:28 +00:00
Devin AI 2ec90b05ae Унифицировать Windows пути AWatch-rus 2026-05-02 09:44:27 +00:00
Devin AI 21f0184115 Согласовать Windows пути с InnoSetup 2026-05-02 09:20:28 +00:00
igor04091968 f7cf5556a0 Ofline install InnoSetup 2026-05-02 10:01:39 +03:00
igor04091968 65da55be7a Patch files Innosetup 2026-05-02 04:12:14 +03:00
igor04091968 8278d51840 feat(worktime): add linux remote worker and pve headless tracking 2026-04-30 15:48:09 +03:00