PrivGuard AI is a real-time, multi-layered privileged access auditing and security threat detection system designed for high-security environments. By fusing deterministic policy rules, robust statistical behavioral profiling, unsupervised machine learning, and post-quantum cryptographic security, PrivGuard AI isolates rogue insiders, account hijackings, and database breaches before exfiltration can occur.
PrivGuard AI features a comprehensive data pipeline, moving from deep endpoint visibility to cryptographic evidence sealing.
graph TD
subgraph Data Collection
Endpoints[Endpoints / Devices]
Wazuh[Wazuh Agents]
Sysmon[Sysmon]
Endpoints -->|General Telemetry| Wazuh
Endpoints -->|Kernel-Level Calls| Sysmon
end
subgraph ELK Stack
Wazuh --> Elasticsearch
Sysmon --> Elasticsearch
Elasticsearch --> Logstash
Logstash --> Kibana[Kibana Visualization]
end
subgraph PrivGuard Core Pipeline
Elasticsearch --> Event[Incoming Telemetry Event]
Event --> Schema[Pydantic Event Schema]
Schema --> Engines[Detection Engines]
subgraph Engines [Detection Layer]
Rule[Rule Detector: Policy rules_config.yaml]
Base[Baseline Engine: Circular Hour, Robust Z-Score]
ML[ML Anomaly: 12-dim Isolation Forest]
end
Base -->|Numerical & Categorical Deviations| Fusion[Risk Fusion Engine]
Rule -->|Triggered Rule Severity| Fusion
ML -->|Normalized Anomaly Score| Fusion
end
subgraph Mitigation & IPFS Sealing
Fusion -->|Risk Decision| Explain[Explainability Layer]
Explain --> Analyst[Analyst Mitigation Hub]
Analyst -->|Account Freeze / Session Block| Pinata[Pinata IPFS]
Pinata -->|Decentralized Hash| PQC[Post-Quantum Cryptography Vault]
end
Capturing system telemetry and security events in real time.
- Wazuh Agents - Collect system telemetry, security logs, and file integrity monitoring (FIM) data from every endpoint.
- Sysmon Integration - Provides kernel-level process execution, registry, and system call visibility.
- ELK Stack Pipeline - Streams events into Elasticsearch, Logstash, and Kibana for indexing, correlation, and visualization.
Building adaptive behavioral baselines for every privileged user.
- MAD-Based Statistics - Detects anomalies using Median Absolute Deviation instead of traditional averages.
- Circular Time Modeling - Correctly compares behaviors across midnight using angular statistics.
- Robust Z-Score Scaling - Converts deviations into standardized anomaly scores.
Enforcing RBAC policies and organizational security rules.
- YAML Rule Engine - Loads RBAC permissions, sensitive resources, regex signatures, and thresholds from
rules_config.yaml. - RBAC Enforcement - Instantly flags commands executed outside an employee's authorized privileges.
AI-powered behavioral analytics for insider threat detection.
- 12-Dimensional Feature Space - Models user behavior using activity, privilege, and peer comparison metrics.
- Isolation Forest Analysis - Converts anomaly scores into normalized risk percentages.
- π Explainable AI - Highlights the features contributing most to each anomaly for analyst transparency.
Combining statistical, policy, and AI signals into a single risk score.
- Weighted Risk Fusion - Combines Rule, Baseline, and ML scores using configurable weights.
- Exponential Time Decay - Gradually reduces historical risk during periods of inactivity.
Automated response with tamper-proof evidence preservation.
- One-Click Response - Freeze accounts, terminate sessions, or force logouts instantly.
- IPFS Audit Sealing - Stores immutable cryptographic hashes via Pinata IPFS.
- Post-Quantum Security - Protects critical audit records using ML-DSA-65 (Dilithium3) signatures and ML-KEM-768 (Kyber) key encapsulation.
Protecting sensitive information beyond authentication.
- Secure File Burner - End-to-end encrypted file sharing with automatic destruction after viewing.
- Intelligent Geofencing - Detects impossible travel and blocks anomalous cross-border access attempts.
Built with React 19 and Tailwind CSS v4, the dashboard offers a fast, dark-mode, information-dense workspace:
- Overview Dashboard: Renders real-time aggregate KPI counters, alert volume over time, and policy trigger frequencies.
- Alert Queue: Provides a list of active alerts with threat level color-coding.
- Alert Detail Panel: Slides in to display plain-English justifications detailing exactly why the engines triggered.
- User Baselines: Compares live deviations against established cohorts, plotting login hours on a circular 24h clock.
βββ backend/
β βββ app/
β β βββ api/ # FastAPI Router endpoints (Events, Alerts, Users)
β β βββ core/ # Scoring engines (baseline.py, rule_detector.py, pqc_vault.py, etc.)
β β βββ models/ # SQLAlchemy Database models (Alert, Session, User, etc.)
β β βββ schemas/ # Pydantic v2 schemas
β β βββ services/ # Seeding pipeline and telemetry data generators
β βββ tests/ # Pytest automated unit tests
β βββ main.py # FastAPI Server bootloader and auto-migrations
β βββ requirements.txt # Python dependencies
β
βββ frontend/
βββ src/
β βββ App.tsx # Main interactive dashboard UI
β βββ main.tsx # React mounting entrypoint
β βββ style.css # Tailwind CSS v4 directives
βββ index.html # Web page wrapper
βββ vite.config.ts # Vite bundler configuration
βββ package.json # Node.js dependencies
Make sure you have Docker Desktop installed and running.
docker compose up --build -d- Frontend Analyst Dashboard:
http://localhost:3001 - Backend API Docs (Swagger):
http://localhost:8001/docs
Make sure you have Python 3.10+ installed.
-
Activate Virtual Environment & Install dependencies: To avoid using a global Python environment (which might contain incompatible library versions like Pydantic v1), run commands within the project's local virtual environment:
- Windows (PowerShell):
.venv\Scripts\Activate.ps1 cd backend pip install -r requirements.txt - macOS / Linux:
source .venv/bin/activate cd backend pip install -r requirements.txt
(Alternatively, you can run directly via the environment's python interpreter from the
backend/folder:..\.venv\Scripts\python main.py) - Windows (PowerShell):
-
Start the FastAPI Server: From inside the
backenddirectory with the virtual environment activated:python main.py
[!NOTE] Database Path Resolution: The application dynamically resolves the SQLite connection string to point to the pre-seeded
privguard.dbdatabase at the workspace root directory. This ensures the dashboard always displays the ~4,670 historical events and baseline profiling data.The server will start at
http://localhost:8000. The OpenAPI docs will be available athttp://localhost:8000/docs.
Make sure you have Node.js 18+ installed.
cd frontend
npm install --legacy-peer-deps
npm run devTo verify statistical calculations, risk fusion algorithms, and cryptographic vaults, run:
$env:PYTHONPATH="."; python -m pytest backend/tests/To generate new real-time administrative telemetry, anomalies, and security threats that stream live to the analyst dashboard:
-
From the project workspace root directory, run:
- Windows (PowerShell):
$env:PYTHONIOENCODING="utf-8" .venv\Scripts\python.exe attack_simulator.py
- macOS / Linux:
PYTHONIOENCODING=utf-8 .venv/bin/python attack_simulator.py
The script will continuously post simulated access logs (such as database queries, bulk downloads, and location anomalies) to the backend API. You will see normal events and real-time alerts outputted directly to your terminal.
- Windows (PowerShell):
|
|
|
|
|
|
- Observability: Wazuh, Sysmon, ELK Stack, and Median Absolute Deviation baselines.
- Control: Role-Based Access Control, Geofencing, and automated session blocking.
- Cryptography: Pinata IPFS immutable hashes and Post-Quantum secure audit vaults (Dilithium/Kyber).