{% extends "base.html" %} {% block title %}Threat Monitor - AUTARCH{% endblock %} {% block content %}

Live Threat Dashboard

--
Threat Level
Active Connections--
Failed Logins (5m)--
Suspicious Processes--
Scan Indicators--
Bandwidth (RX/TX)--
ARP Spoof Alerts--
New Listening Ports--
Conn Rate (1m avg)--
DDoS Status--

Network Connections

LocalRemoteStatePIDProcessAction
Click "Load Connections" to view active network connections.

Bandwidth Monitor

ARP Spoof Detection

Click "Scan ARP Table" to check for spoofing.

Listening Port Monitor

First click establishes a baseline. Subsequent clicks detect new listeners.

GeoIP Lookup

Connections + GeoIP

May take a few seconds for API lookups

Connection Rate

Threat Analysis

Click "Generate Report" for a full threat analysis.

Packet Capture

Live packet capture via Scapy. Requires root/admin privileges.

Capture Analysis

DDoS Detection

Top Talkers

Click "Refresh" to load top talkers.

SYN Flood Protection

Status: checking...

Enables SYN cookies (Linux) or SynAttackProtect (Windows) to mitigate SYN floods.

Rate Limiting


Auto-Mitigation





Mitigation History

Click "Refresh" to load history.

Counter-Attack

Active response tools. Use with caution — actions are immediate and may affect network connectivity.

Block IP Address

Kill Process

Block Port



    
    

Persistent Blocklist

Click "Refresh Blocklist" to load.

Details

Loading...

{% endblock %}