Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Aegis-Hunter: AI-Augmented Multi-OS Threat Hunting & Sigma Triage Engine

Lead Analyst: Dominic Nyongesa
Email: dominic.nyongesa@student.moringaschool.com
Operational Role: Junior / Mid SOC Analyst, Threat Hunter & Security Engineer
Institution: Moringa School Cyber Security Full Time
Standards: NIST SP 800-53 Rev. 5 | CIS Controls v8.1 | MITRE ATT&CK Enterprise Matrix v14 | FIRST CVSS v3.1
GitHub: @ngesa-cloud
Base Upstream Toolkits Re-Architected: WithSecureLabs/chainsaw & SigmaHQ/sigma


🛡️ Project Overview & 2026 Motivation

While legacy threat hunting tools such as WithSecure Chainsaw excel at static, offline analysis of Windows .evtx files, modern enterprise environments are intrinsically heterogeneous. Today's security operations teams must monitor Linux servers (Ubuntu/Debian, RedHat), Windows Domain Controllers, and container environments simultaneously.

Aegis-Hunter solves the three core architectural limitations of legacy hunting tools:

  1. Multi-OS Telemetry Ingestion: Natively parses and normalizes Linux auditd logs (/var/log/audit/audit.log), auth.log/syslog, and Windows Security Event Logs (.evtx / JSON).
  2. Dynamic Sigma Rule Engine: Evaluates standard YAML Sigma detection rules with sub-second execution speeds without requiring complex external dependencies.
  3. AI-Driven Incident Triage & Correlation: Automatically groups isolated alert detections into chronological Adversary Attack Chains, computes contextual CVSS v3.1 scores, assigns strict SLA Containment Tiers (P1/P2/P3), and synthesizes production-ready NIST SP 800-53 remediation playbooks.

⚡ Architecture Pipeline

 ┌────────────────────────────────────────────────────────┐
 │           Heterogeneous Telemetry Streams              │
 │  (Linux Auditd / Syslog Auth / Windows Security EVTX)  │
 └───────────────────────────┬────────────────────────────┘
                             │
                             ▼
 ┌────────────────────────────────────────────────────────┐
 │            Event Normalization Engine                  │
 │  (Extracts Image, CommandLine, TargetFile, User, Host) │
 └───────────────────────────┬────────────────────────────┘
                             │
                             ▼
 ┌────────────────────────────────────────────────────────┐
 │            Sigma Rule Detection Engine                 │
 │   (Evaluates YAML Rules, Pattern Modifiers, Conditions)│
 └───────────────────────────┬────────────────────────────┘
                             │
                             ▼
 ┌────────────────────────────────────────────────────────┐
 │         AI Threat Correlator & Triage Engine           │
 │ (Reconstructs Attack Chains, CVSS v3.1, MITRE Mapping) │
 └───────────────────────────┬────────────────────────────┘
                             │
                             ▼
 ┌────────────────────────────────────────────────────────┐
 │             Multi-Format Incident Reporting            │
 │ (Rich ANSI CLI / Interactive HTML Dashboard / JSON/MD) │
 └────────────────────────────────────────────────────────┘

🚀 Quick Start & Usage

1. Requirements

python3 -m pip install pyyaml

2. Run the Live Multi-OS Lab Demonstration

Analyze authentic heterogeneous APT telemetry across an Ubuntu server (10.20.0.11) and Windows Domain Controller (10.20.0.10):

./aegishunt.py --demo

3. Analyze Custom Log Artifacts

# Scan Linux Auditd log against custom Sigma rules
./aegishunt.py --auditd /var/log/audit/audit.log --rules ./aegis/rules/

# Scan multi-OS artifacts and export an interactive HTML dashboard
./aegishunt.py \
  --auditd /var/log/audit/audit.log \
  --evtx ./windows_events.json \
  --output-html ./output/incident_dashboard.html \
  --output-json ./output/incident_report.json

📊 Compliance & Standards Mapping

Standard / Framework Control / Technique ID Operational Implementation in Aegis-Hunter
NIST SP 800-53 Rev. 5 AU-6 Automated audit log review, cross-host correlation, and analysis.
NIST SP 800-53 Rev. 5 IR-4 Automated incident handling and production-ready containment commands.
NIST SP 800-53 Rev. 5 SI-4 Information system monitoring and malicious code behavior detection.
CIS Controls v8.1 Control 8 Audit Log Management (Safeguards 8.2, 8.5, 8.11).
MITRE ATT&CK v14 T1059 Execution: Unix Shell (T1059.004), PowerShell (T1059.001).
MITRE ATT&CK v14 T1003 Credential Access: /etc/shadow (T1003.008), LSASS (T1003.001).
MITRE ATT&CK v14 T1550 Lateral Movement: Pass-The-Hash via SMB Admin Shares (T1550.002).

🧪 Automated Testing

Run the automated test suite to verify ingestors, rule evaluation, and incident scoring:

python3 -m unittest discover -s tests -v

⚖️ License & Ethical Use

Developed for academic research, authorized threat hunting, and defensive security operations within the Moringa School Cyber Security program. Unauthorized scanning or access against external systems is strictly prohibited.

About

Aegis-Hunter: AI-Augmented Multi-OS Threat Hunting & Sigma Triage Engine

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages