Network security monitoring · College capstone

AutoDefender

AutoDefender started as my capstone project in my senior year of college (fall 2025), and I still maintain it. It monitors Suricata network logs in real time or analyzes historical log files, maps each threat to MITRE ATT&CK, explains it in plain English with a local AI model through Ollama, and recommends responses, including firewall rules that only run after a person approves them.

Screenshots

Screenshots use AutoDefender's built-in demo data, which is synthetic: documentation and private IP ranges, documentation AS numbers and fictional organizations. Click a screenshot to open it full size. Use the arrows, or select the gallery and press ← →.

How it works

  1. Read the logs: tail one or more Suricata eve.json files in real time, handling log rotation and partial lines, or batch-analyze historical logs.
  2. Detect and enrich: rate each event's severity, detect port scans and suspicious patterns, tag threats with MITRE ATT&CK techniques, and optionally add location data from offline MaxMind GeoLite2 databases.
  3. Explain: HIGH and CRITICAL threats go to a local Ollama model for a plain-English explanation, on a small worker pool with a per-minute call budget.
  4. Respond: playbooks bundle a drop rule, a log entry and a webhook notification into one approval. Rules are backed up before every change and can be unblocked or set to expire.
  5. Review: in the Streamlit web console (dashboard, incidents, threat analysis, actions, IP lists, playbooks, audit log) or the terminal UI.

Security decisions