Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
83 changes: 46 additions & 37 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# DetLab

DetLab is an advanced detection engineering platform for validating, translating, scoring, packaging, distributing, verifying, and serving behavioral detections across multiple security backends.
DetLab is an advanced detection engineering platform for validating, translating, scoring, packaging, distributing, verifying, serving, and visualizing behavioral detections across multiple security backends.

## Platform Capabilities

Expand All @@ -15,73 +15,80 @@ DetLab is an advanced detection engineering platform for validating, translating
- Pack trust verification
- Docker deployment support
- FastAPI service layer
- Next.js dashboard foundation
- GHCR publishing workflows
- Governance reporting
- CI/CD integration

## FastAPI Service Layer
## Web Dashboard

DetLab now supports API-backed execution using FastAPI.
DetLab now supports a Next.js-based dashboard foundation.

## Install API Dependencies
## Dashboard Stack

```bash
pip install -r requirements-api.txt
```
| Layer | Technology |
|---|---|
| Frontend | Next.js |
| API | FastAPI |
| Runtime | Docker Compose |
| Deployment | Container-native |

## Start API Server
## Frontend Setup

```bash
uvicorn detlab.api:app --host 0.0.0.0 --port 8000
cd web
npm install
npm run dev
```

## Example Endpoints

### Health Check
Frontend URL:

```text
GET /health
http://localhost:3000
```

### Validate Detections
## API Server

```text
GET /validate
```bash
uvicorn detlab.api:app --host 0.0.0.0 --port 8000
```

### Generate Analytics
API URL:

```text
GET /analytics
http://localhost:8000
```

### Generate Detection Scores
## Docker Compose Stack

```text
GET /score
```bash
docker compose up --build
```

## Docker Deployment

### Build Local Image
Supports:
- frontend dashboard
- FastAPI backend
- containerized local development
- platform orchestration

```bash
docker build -t detlab .
```
## Dashboard Features

### Run Validation
Current dashboard foundation includes:

```bash
docker run --rm \
-v "$PWD:/workspace" \
detlab validate detections
```
- API health monitoring
- platform capability overview
- frontend/API integration foundation
- governance dashboard groundwork

## GitHub Container Registry
## Planned Dashboard Features

```text
ghcr.io/egrexsec/detlab:latest
```
- ATT&CK heatmaps
- detection score visualizations
- maturity distributions
- pack browsing
- trust verification status
- governance analytics
- behavioral detection timelines

## Detection Pack Trust Verification

Expand Down Expand Up @@ -146,6 +153,7 @@ sequence:
- Pack integrity verification
- Reproducible container execution
- API-backed workflows
- Frontend platform foundations

## Long-Term Vision

Expand All @@ -158,6 +166,7 @@ DetLab is evolving toward:
- portable detection engineering platforms
- container-native detection engineering
- API-driven detection operations
- full detection engineering platform ecosystems

## License

Expand Down
15 changes: 15 additions & 0 deletions docker-compose.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
version: '3.9'

services:
api:
build: .
command: uvicorn detlab.api:app --host 0.0.0.0 --port 8000

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Run uvicorn outside the CLI entrypoint

When the documented Docker Compose stack is used, this service builds the existing root Dockerfile, whose ENTRYPOINT is ['detlab'] and whose install step does not include requirements-api.txt. The Compose command is therefore passed as arguments to the detlab CLI instead of replacing the entrypoint, so the API container starts as detlab uvicorn ... and exits before /health is available. Use an API-specific image/install path and override entrypoint (or change the Dockerfile entrypoint) before relying on this stack.

Useful? React with 👍 / 👎.

ports:
- '8000:8000'

web:
build: ./web

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Add a Dockerfile for the web build context

With the documented docker compose up --build flow, build: ./web makes web/ the build context and Compose expects a Dockerfile there unless one is specified. I checked the new web tree and it only contains package.json and app/page.tsx, so the web service build fails before the dashboard can start. Add web/Dockerfile, point dockerfile: at an existing file, or use a prebuilt image.

Useful? React with 👍 / 👎.

ports:
- '3000:3000'
depends_on:
- api
39 changes: 39 additions & 0 deletions web/app/page.tsx
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
async function getHealth() {
try {
const response = await fetch('http://localhost:8000/health', {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Point the server-side fetch at the Compose service

In the Compose deployment, this page is rendered on the Next.js server inside the web container, so localhost:8000 refers to the web container rather than the api service. Once the containers build, the dashboard will still report the API as offline under the documented Docker Compose stack even while the API container is healthy. Use the Compose service name such as http://api:8000 or an environment-configured base URL for server-side fetches.

Useful? React with 👍 / 👎.

cache: 'no-store'
})

return response.json()
} catch {
return { status: 'offline' }
}
}

export default async function HomePage() {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Provide the required App Router root layout

This adds an App Router page under web/app, but the app has no web/app/layout.tsx. Next.js 14 requires a root layout in the app directory that defines the document shell, so npm run dev/npm run build for the new dashboard fails before serving this page. Add a minimal root layout with <html> and <body> around children.

Useful? React with 👍 / 👎.

const health = await getHealth()

return (
<main style={{ padding: '2rem', fontFamily: 'Arial' }}>
<h1>DetLab Dashboard</h1>

<div style={{ marginTop: '2rem' }}>
<h2>Platform Status</h2>
<p>API Status: {health.status}</p>
</div>

<div style={{ marginTop: '2rem' }}>
<h2>Capabilities</h2>

<ul>
<li>ATT&CK Analytics</li>
<li>Detection Scoring</li>
<li>Behavioral Sequences</li>
<li>Pack Registry</li>
<li>Trust Verification</li>
<li>Governance Reporting</li>
</ul>
</div>
</main>
)
}
15 changes: 15 additions & 0 deletions web/package.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
{
"name": "detlab-web",
"private": true,
"version": "0.1.0",
"scripts": {
"dev": "next dev",
"build": "next build",
"start": "next start"
},
"dependencies": {
"next": "14.2.5",
"react": "18.3.1",
"react-dom": "18.3.1"
}
}
Loading