Нема описа

index.html 45KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809
  1. <!doctype html>
  2. <html lang="en">
  3. <head>
  4. <meta charset="UTF-8" />
  5. <meta name="viewport" content="width=device-width, initial-scale=1.0" />
  6. <title>SOC Integrator Admin</title>
  7. <script src="https://cdn.tailwindcss.com"></script>
  8. <script defer src="https://cdn.jsdelivr.net/npm/alpinejs@3.x.x/dist/cdn.min.js"></script>
  9. <link rel="stylesheet" href="/ui/assets/styles.css?v=20260303-17" />
  10. <script src="/ui/assets/app.js?v=20260303-17"></script>
  11. </head>
  12. <body class="bg-slate-100 text-slate-800" x-data="socUi()" x-init="init()">
  13. <div class="mx-auto w-full max-w-none px-3 py-4 md:px-5 md:py-6">
  14. <header class="admin-card mb-4">
  15. <div class="flex flex-col gap-3 md:flex-row md:items-center md:justify-between">
  16. <div>
  17. <h1 class="text-2xl font-bold tracking-tight">SOC Integrator Admin Console</h1>
  18. <p class="mt-1 text-sm text-slate-500">Internal operations UI for monitoring, IOC, IRIS, Shuffle, Wazuh, and MVP workflows.</p>
  19. </div>
  20. <div class="flex flex-wrap items-center gap-2 text-sm">
  21. <span class="status-pill" :class="overview.health ? 'status-ok' : 'status-warn'" x-text="overview.health ? 'API reachable' : 'API not checked'"></span>
  22. <a class="link-chip" href="/docs" target="_blank" rel="noreferrer">Swagger</a>
  23. <a class="link-chip" href="/openapi.json" target="_blank" rel="noreferrer">OpenAPI</a>
  24. <a class="link-chip" href="/health" target="_blank" rel="noreferrer">Health</a>
  25. </div>
  26. </div>
  27. </header>
  28. <section class="admin-card mb-4">
  29. <h2 class="panel-title">Connection</h2>
  30. <div class="grid gap-3 md:grid-cols-3">
  31. <label class="text-sm md:col-span-1">
  32. <span class="input-label">API Base URL</span>
  33. <input x-model="apiBase" class="input" />
  34. </label>
  35. <label class="text-sm md:col-span-2">
  36. <span class="input-label">Internal API Key (memory only)</span>
  37. <input x-model="internalApiKey" type="password" placeholder="dev-internal-key" class="input" />
  38. </label>
  39. </div>
  40. </section>
  41. <section x-show="errorMessage" x-cloak class="mb-4 rounded-lg border border-rose-200 bg-rose-50 p-3 text-sm text-rose-700">
  42. <strong>Error:</strong> <span x-text="errorMessage"></span>
  43. </section>
  44. <div class="grid gap-4 lg:grid-cols-[200px,minmax(0,1fr)]">
  45. <aside class="admin-card h-fit p-2">
  46. <nav class="flex flex-row gap-2 overflow-x-auto md:flex-col md:overflow-visible">
  47. <template x-for="item in tabs" :key="item.key">
  48. <button class="tab-btn" :class="tabClass(item.key)" @click="activeTab = item.key" x-text="item.label"></button>
  49. </template>
  50. </nav>
  51. </aside>
  52. <main class="min-w-0 space-y-4">
  53. <section x-show="activeTab === 'overview'" x-cloak class="admin-card">
  54. <div class="action-row">
  55. <button class="btn btn-primary" @click="loadHealth()">Refresh Health</button>
  56. <button class="btn btn-neutral" @click="loadAutoSync()">Refresh Auto Sync</button>
  57. </div>
  58. <div class="grid gap-4 lg:grid-cols-2">
  59. <div class="panel-block">
  60. <h3 class="panel-subtitle">Health</h3>
  61. <pre class="json-box" x-text="pretty(overview.health)"></pre>
  62. <div class="table-wrap mt-2" x-show="keyValueRows(overview.health).length">
  63. <table class="data-table">
  64. <thead><tr><th>Field</th><th>Value</th></tr></thead>
  65. <tbody>
  66. <template x-for="row in keyValueRows(overview.health)" :key="row.key">
  67. <tr><td x-text="row.key"></td><td x-text="row.value"></td></tr>
  68. </template>
  69. </tbody>
  70. </table>
  71. </div>
  72. </div>
  73. <div class="panel-block">
  74. <h3 class="panel-subtitle">Auto Sync</h3>
  75. <pre class="json-box" x-text="pretty(overview.autoSync)"></pre>
  76. <div class="table-wrap mt-2" x-show="keyValueRows(overview.autoSync).length">
  77. <table class="data-table">
  78. <thead><tr><th>Field</th><th>Value</th></tr></thead>
  79. <tbody>
  80. <template x-for="row in keyValueRows(overview.autoSync)" :key="row.key">
  81. <tr><td x-text="row.key"></td><td x-text="row.value"></td></tr>
  82. </template>
  83. </tbody>
  84. </table>
  85. </div>
  86. </div>
  87. </div>
  88. </section>
  89. <section x-show="activeTab === 'systems'" x-cloak class="admin-card space-y-4">
  90. <div class="panel-block">
  91. <div class="mb-2 flex flex-wrap items-center gap-2">
  92. <h3 class="panel-subtitle mb-0">Systems Monitor</h3>
  93. <button class="btn btn-primary" @click="loadSystemsMonitor()">Refresh Now</button>
  94. <button class="btn btn-ghost" @click="systemsTogglePaused()" x-text="systemsMonitor.paused ? 'Resume' : 'Pause'"></button>
  95. <span class="text-xs text-slate-500" x-text="systemsMonitor.loading ? 'Loading...' : 'Idle'"></span>
  96. <span class="text-xs text-slate-500" x-text="systemsMonitor.lastRefreshAt ? `Last refresh: ${systemsMonitor.lastRefreshAt}` : 'Not refreshed yet'"></span>
  97. </div>
  98. <div class="grid gap-3 md:grid-cols-4">
  99. <label class="text-sm">
  100. <span class="input-label">Minutes</span>
  101. <input class="input" type="number" min="1" x-model.number="systemsMonitor.minutes" />
  102. </label>
  103. <label class="text-sm">
  104. <span class="input-label">Limit</span>
  105. <input class="input" type="number" min="1" x-model.number="systemsMonitor.limit" />
  106. </label>
  107. <label class="text-sm">
  108. <span class="input-label">Auto refresh</span>
  109. <select class="input" :value="systemsMonitor.autoRefresh ? 'true' : 'false'" @change="systemsSetAutoRefresh($event.target.value === 'true')">
  110. <option value="true">true</option>
  111. <option value="false">false</option>
  112. </select>
  113. </label>
  114. <label class="text-sm">
  115. <span class="input-label">Interval (seconds)</span>
  116. <select class="input" :value="String(systemsMonitor.intervalSeconds)" @change="systemsSetInterval($event.target.value)">
  117. <option value="10">10</option>
  118. <option value="20">20</option>
  119. <option value="30">30</option>
  120. </select>
  121. </label>
  122. </div>
  123. </div>
  124. <div class="panel-block">
  125. <h3 class="panel-subtitle">Run Sim Logs</h3>
  126. <div class="grid gap-3 md:grid-cols-3 lg:grid-cols-6">
  127. <label class="text-sm">
  128. <span class="input-label">Script</span>
  129. <select class="input" x-model="simLogs.form.script">
  130. <option value="fortigate">fortigate</option>
  131. <option value="endpoint">endpoint</option>
  132. <option value="cisco">cisco</option>
  133. <option value="proposal_required">proposal_required</option>
  134. <option value="proposal_appendix_b">proposal_appendix_b</option>
  135. <option value="proposal_appendix_c">proposal_appendix_c</option>
  136. <option value="wazuh_test">wazuh_test</option>
  137. </select>
  138. </label>
  139. <label class="text-sm">
  140. <span class="input-label">Target</span>
  141. <input class="input" x-model="simLogs.form.target" placeholder="all" />
  142. </label>
  143. <label class="text-sm" x-show="simScriptUsesScenario()">
  144. <span class="input-label">Scenario</span>
  145. <input class="input" x-model="simLogs.form.scenario" placeholder="all" />
  146. </label>
  147. <label class="text-sm">
  148. <span class="input-label">Count</span>
  149. <input class="input" type="number" min="1" x-model.number="simLogs.form.count" />
  150. </label>
  151. <label class="text-sm">
  152. <span class="input-label">Delay (s)</span>
  153. <input class="input" type="number" min="0" step="0.1" x-model.number="simLogs.form.delay_seconds" />
  154. </label>
  155. <label class="text-sm">
  156. <span class="input-label">Forever</span>
  157. <select class="input" x-model="simLogs.form.forever">
  158. <option :value="false">false</option>
  159. <option :value="true">true</option>
  160. </select>
  161. </label>
  162. </div>
  163. <div class="action-row mt-2">
  164. <button class="btn btn-primary" @click="startSimRun()">Start</button>
  165. <button class="btn btn-neutral" @click="loadSimRuns()">Refresh Runs</button>
  166. <button class="btn btn-danger" @click="stopRunningSimRuns()">Stop Running</button>
  167. <button class="btn btn-ghost" @click="loadSimOutput()">Refresh Logs</button>
  168. </div>
  169. <pre class="json-box mt-2" x-text="pretty(simLogs.startResult)"></pre>
  170. <div class="table-wrap mt-2" x-show="simRunRows().length">
  171. <table class="data-table">
  172. <thead>
  173. <tr>
  174. <template x-for="col in tableColumns(simRunRows())" :key="col">
  175. <th x-text="col"></th>
  176. </template>
  177. <th>Logs</th>
  178. <th>Action</th>
  179. </tr>
  180. </thead>
  181. <tbody>
  182. <template x-for="(row, idx) in simRunRows()" :key="idx">
  183. <tr>
  184. <template x-for="col in tableColumns(simRunRows())" :key="col">
  185. <td x-text="cellText(row[col])"></td>
  186. </template>
  187. <td>
  188. <button class="btn btn-ghost" @click="selectSimRun(row.run_id)">View</button>
  189. </td>
  190. <td>
  191. <button class="btn btn-danger" x-show="row.running" @click="stopSimRun(row.run_id)">Stop</button>
  192. </td>
  193. </tr>
  194. </template>
  195. </tbody>
  196. </table>
  197. </div>
  198. <div class="mt-3 rounded-lg border border-slate-200 bg-white p-3" x-show="simLogs.selectedRunId">
  199. <div class="mb-2 flex flex-wrap items-center gap-2">
  200. <h4 class="panel-mini-title mb-0">Run Output</h4>
  201. <span class="text-xs text-slate-600" x-text="`run_id: ${simLogs.selectedRunId}`"></span>
  202. <span class="status-pill" :class="simSelectedRun() && simSelectedRun().running ? 'status-ok' : 'status-warn'" x-text="simSelectedRun() && simSelectedRun().running ? 'running' : 'stopped'"></span>
  203. </div>
  204. <div class="grid gap-3 md:grid-cols-3">
  205. <label class="text-sm">
  206. <span class="input-label">Tail lines</span>
  207. <input class="input" type="number" min="10" max="1000" x-model.number="simLogs.outputLimit" />
  208. </label>
  209. <label class="text-sm">
  210. <span class="input-label">Auto refresh logs</span>
  211. <select class="input" x-model="simLogs.autoRefresh" @change="startSimLogsAutoRefresh()">
  212. <option :value="true">true</option>
  213. <option :value="false">false</option>
  214. </select>
  215. </label>
  216. <label class="text-sm">
  217. <span class="input-label">Interval (seconds)</span>
  218. <input class="input" type="number" min="2" max="60" x-model.number="simLogs.intervalSeconds" @change="startSimLogsAutoRefresh()" />
  219. </label>
  220. </div>
  221. <pre class="json-box mt-2" x-text="unwrapApiData(simLogs.output)?.text || 'No logs yet'"></pre>
  222. </div>
  223. <div class="mt-3 rounded-lg border border-slate-200 bg-white p-3" x-show="simLogs.selectedRunId">
  224. <div class="mb-2 flex flex-wrap items-center gap-2">
  225. <h4 class="panel-mini-title mb-0">Wazuh Live Correlation</h4>
  226. <span class="text-xs text-slate-600" x-text="`run_id: ${simLogs.selectedRunId}`"></span>
  227. <span class="status-pill status-ok">auto refresh every 5s</span>
  228. </div>
  229. <div class="grid gap-3 md:grid-cols-2">
  230. <div class="text-sm">
  231. <span class="input-label">Records</span>
  232. <div class="input">Latest 100 (no filter)</div>
  233. </div>
  234. <div class="action-row mt-6">
  235. <button class="btn btn-neutral" @click="loadSimWazuhLatest()">Refresh Wazuh</button>
  236. </div>
  237. </div>
  238. <div class="mt-2">
  239. <label class="text-sm inline-flex items-center gap-2">
  240. <input type="checkbox" x-model="simWazuh.showQuery" />
  241. <span>Show query used</span>
  242. </label>
  243. </div>
  244. <pre class="json-box mt-2" x-show="simWazuh.showQuery" x-text="pretty(unwrapApiData(simWazuh.latest)?.query || null)"></pre>
  245. <div class="mt-2">
  246. <div>
  247. <h5 class="panel-mini-title">Latest Event Logs</h5>
  248. <div class="table-wrap mt-2" x-show="simWazuhEventTableRows().length">
  249. <table class="data-table">
  250. <thead>
  251. <tr>
  252. <th>Time</th>
  253. <th>rule.id</th>
  254. <th>rule.description</th>
  255. <th>full_log</th>
  256. </tr>
  257. </thead>
  258. <tbody>
  259. <template x-for="(row, idx) in simWazuhEventTableRows()" :key="idx">
  260. <tr>
  261. <td x-text="cellText(row.time)"></td>
  262. <td x-text="cellText(row.rule_id)"></td>
  263. <td x-text="cellText(row.rule_description)"></td>
  264. <td><pre class="text-xs whitespace-pre-wrap" x-text="fullLogAsJsonText(row.full_log)"></pre></td>
  265. </tr>
  266. </template>
  267. </tbody>
  268. </table>
  269. </div>
  270. <div class="text-xs text-slate-500" x-show="!simWazuhEventTableRows().length">No events found for selected run yet.</div>
  271. </div>
  272. </div>
  273. </div>
  274. </div>
  275. <div class="grid gap-3 lg:grid-cols-4">
  276. <template x-for="meta in systemsCardMeta" :key="meta.key">
  277. <div class="panel-block">
  278. <div class="mb-2 flex items-center justify-between">
  279. <h4 class="panel-mini-title" x-text="meta.label"></h4>
  280. <span class="status-pill" :class="systemsStatusClass(systemsCard(meta.key).status || 'down')" x-text="systemsCard(meta.key).status || 'down'"></span>
  281. </div>
  282. <div class="text-xs text-slate-600">Latency: <span x-text="cellText(systemsCard(meta.key).latency_ms)"></span> ms</div>
  283. <div class="text-xs text-slate-600">Last OK: <span x-text="cellText(systemsCard(meta.key).last_ok_at)"></span></div>
  284. <div class="mt-1 text-xs text-rose-700" x-show="systemsCard(meta.key).last_error" x-text="`Error: ${systemsCard(meta.key).last_error}`"></div>
  285. </div>
  286. </template>
  287. </div>
  288. <div class="panel-block">
  289. <h3 class="panel-subtitle">Incident Pipeline KPIs</h3>
  290. <div class="table-wrap mt-2" x-show="systemsPipelineRows().length">
  291. <table class="data-table">
  292. <thead><tr><th>KPI</th><th>Value</th></tr></thead>
  293. <tbody>
  294. <template x-for="row in systemsPipelineRows()" :key="row.key">
  295. <tr><td x-text="row.key"></td><td x-text="row.value"></td></tr>
  296. </template>
  297. </tbody>
  298. </table>
  299. </div>
  300. </div>
  301. <div class="grid gap-3 lg:grid-cols-2">
  302. <template x-for="meta in systemsCardMeta" :key="`table-${meta.key}`">
  303. <div class="panel-block">
  304. <h3 class="panel-subtitle" x-text="`${meta.label} Recent Data`"></h3>
  305. <div class="table-wrap mt-2" x-show="systemsRecentRows(meta.key).length">
  306. <table class="data-table">
  307. <thead>
  308. <tr>
  309. <template x-for="col in systemsRecentColumns(meta.key)" :key="col">
  310. <th x-text="col"></th>
  311. </template>
  312. </tr>
  313. </thead>
  314. <tbody>
  315. <template x-for="(row, idx) in systemsRecentRows(meta.key)" :key="idx">
  316. <tr>
  317. <template x-for="col in systemsRecentColumns(meta.key)" :key="col">
  318. <td x-text="cellText(row[col])"></td>
  319. </template>
  320. </tr>
  321. </template>
  322. </tbody>
  323. </table>
  324. </div>
  325. <div class="text-xs text-slate-500" x-show="!systemsRecentRows(meta.key).length">No recent rows</div>
  326. </div>
  327. </template>
  328. </div>
  329. </section>
  330. <section x-show="activeTab === 'monitoring'" x-cloak class="admin-card space-y-4">
  331. <div class="panel-block">
  332. <div class="mb-2 flex flex-wrap items-center gap-2">
  333. <h3 class="panel-subtitle mb-0">Log Loss Check</h3>
  334. <button class="btn btn-ghost" @click="applyLogLossPreset('default')">Default</button>
  335. <button class="btn btn-ghost" @click="applyLogLossPreset('b2')">B2 only</button>
  336. </div>
  337. <div class="grid gap-3 md:grid-cols-4">
  338. <label class="text-sm">
  339. <span class="input-label">Minutes</span>
  340. <input x-model.number="logLossForm.minutes" type="number" min="1" class="input" />
  341. </label>
  342. <label class="text-sm md:col-span-3">
  343. <span class="input-label">Create IRIS Ticket</span>
  344. <select x-model="logLossForm.createTicket" class="input">
  345. <option :value="false">false</option>
  346. <option :value="true">true</option>
  347. </select>
  348. </label>
  349. </div>
  350. <template x-for="(stream, index) in logLossForm.streams" :key="index">
  351. <div class="mt-3 grid gap-3 rounded-lg border border-slate-200 bg-white p-3 md:grid-cols-12">
  352. <input x-model="stream.name" placeholder="stream name" class="input md:col-span-2" />
  353. <input x-model="stream.query" placeholder="query string" class="input md:col-span-8" />
  354. <input x-model.number="stream.min_count" type="number" min="0" class="input md:col-span-1" />
  355. <button class="btn btn-danger md:col-span-1" @click="removeLogLossStream(index)">Remove</button>
  356. </div>
  357. </template>
  358. <div class="action-row mt-3">
  359. <button class="btn btn-ghost" @click="addLogLossStream()">Add Stream</button>
  360. <button class="btn btn-primary" @click="runLogLossCheck()">Run Check</button>
  361. </div>
  362. <pre class="json-box mt-2" x-text="pretty(logLoss.result)"></pre>
  363. <div class="table-wrap mt-2" x-show="extractRows(logLoss.result).length">
  364. <table class="data-table">
  365. <thead>
  366. <tr>
  367. <template x-for="col in tableColumns(extractRows(logLoss.result))" :key="col">
  368. <th x-text="col"></th>
  369. </template>
  370. </tr>
  371. </thead>
  372. <tbody>
  373. <template x-for="(row, idx) in extractRows(logLoss.result)" :key="idx">
  374. <tr>
  375. <template x-for="col in tableColumns(extractRows(logLoss.result))" :key="col">
  376. <td x-text="cellText(row[col])"></td>
  377. </template>
  378. </tr>
  379. </template>
  380. </tbody>
  381. </table>
  382. </div>
  383. </div>
  384. <div class="panel-block">
  385. <h3 class="panel-subtitle">Appendix C Detections</h3>
  386. <div class="action-row">
  387. <button class="btn btn-neutral" @click="loadCState()">Refresh State</button>
  388. <button class="btn btn-primary" @click="runCEvaluate()">Run Evaluate</button>
  389. <button class="btn btn-ghost" @click="loadCHistory()">Load History</button>
  390. </div>
  391. <div class="grid gap-3 md:grid-cols-3">
  392. <label class="text-sm"><span class="input-label">Minutes</span><input x-model.number="cEvalForm.minutes" type="number" min="1" class="input" /></label>
  393. <label class="text-sm"><span class="input-label">Limit</span><input x-model.number="cEvalForm.limit" type="number" min="1" class="input" /></label>
  394. <label class="text-sm"><span class="input-label">Dry run</span><select x-model="cEvalForm.dry_run" class="input"><option :value="true">true</option><option :value="false">false</option></select></label>
  395. </div>
  396. <label class="mt-2 block text-sm"><span class="input-label">Query</span><input x-model="cEvalForm.query" class="input" /></label>
  397. <label class="mt-2 block text-sm"><span class="input-label">Selectors (comma-separated)</span><input x-model="cEvalForm.selectorsText" class="input" /></label>
  398. <div class="mt-3 grid gap-3 lg:grid-cols-3">
  399. <div><h4 class="panel-mini-title">State</h4><pre class="json-box" x-text="pretty(cDetections.state)"></pre></div>
  400. <div><h4 class="panel-mini-title">Evaluate</h4><pre class="json-box" x-text="pretty(cDetections.evaluate)"></pre></div>
  401. <div><h4 class="panel-mini-title">History</h4><pre class="json-box" x-text="pretty(cDetections.history)"></pre></div>
  402. </div>
  403. <div class="table-wrap mt-2" x-show="extractRows(cDetections.evaluate).length">
  404. <table class="data-table">
  405. <thead>
  406. <tr>
  407. <template x-for="col in tableColumns(extractRows(cDetections.evaluate))" :key="col">
  408. <th x-text="col"></th>
  409. </template>
  410. </tr>
  411. </thead>
  412. <tbody>
  413. <template x-for="(row, idx) in extractRows(cDetections.evaluate)" :key="idx">
  414. <tr>
  415. <template x-for="col in tableColumns(extractRows(cDetections.evaluate))" :key="col">
  416. <td x-text="cellText(row[col])"></td>
  417. </template>
  418. </tr>
  419. </template>
  420. </tbody>
  421. </table>
  422. </div>
  423. <div class="table-wrap mt-2" x-show="extractRows(cDetections.history).length">
  424. <table class="data-table">
  425. <thead>
  426. <tr>
  427. <template x-for="col in tableColumns(extractRows(cDetections.history))" :key="col">
  428. <th x-text="col"></th>
  429. </template>
  430. </tr>
  431. </thead>
  432. <tbody>
  433. <template x-for="(row, idx) in extractRows(cDetections.history)" :key="idx">
  434. <tr>
  435. <template x-for="col in tableColumns(extractRows(cDetections.history))" :key="col">
  436. <td x-text="cellText(row[col])"></td>
  437. </template>
  438. </tr>
  439. </template>
  440. </tbody>
  441. </table>
  442. </div>
  443. </div>
  444. </section>
  445. <section x-show="activeTab === 'ioc'" x-cloak class="admin-card space-y-4">
  446. <div class="panel-block">
  447. <h3 class="panel-subtitle">IOC Enrich / Evaluate</h3>
  448. <div class="grid gap-3 md:grid-cols-4">
  449. <label class="text-sm"><span class="input-label">Type</span><select x-model="iocForm.ioc_type" class="input"><option>ip</option><option>domain</option><option>hash</option><option>url</option></select></label>
  450. <label class="text-sm md:col-span-2"><span class="input-label">IOC Value</span><input x-model="iocForm.ioc_value" class="input" /></label>
  451. <label class="text-sm"><span class="input-label">Providers</span><input x-model="iocForm.providersText" class="input" placeholder="virustotal,abuseipdb" /></label>
  452. </div>
  453. <div class="grid gap-3 md:grid-cols-2">
  454. <label class="text-sm"><span class="input-label">Malicious threshold</span><input x-model.number="iocForm.malicious_threshold" type="number" min="0" class="input" /></label>
  455. <label class="text-sm"><span class="input-label">Suspicious threshold</span><input x-model.number="iocForm.suspicious_threshold" type="number" min="0" class="input" /></label>
  456. </div>
  457. <div class="action-row">
  458. <button class="btn btn-primary" @click="runIocEnrich()">Enrich</button>
  459. <button class="btn btn-neutral" @click="runIocEvaluate()">Evaluate</button>
  460. <button class="btn btn-ghost" @click="loadIocHistory()">History</button>
  461. </div>
  462. <div class="grid gap-3 lg:grid-cols-3">
  463. <div><h4 class="panel-mini-title">Enrich</h4><pre class="json-box" x-text="pretty(ioc.enrich)"></pre></div>
  464. <div><h4 class="panel-mini-title">Evaluate</h4><pre class="json-box" x-text="pretty(ioc.evaluate)"></pre></div>
  465. <div><h4 class="panel-mini-title">History</h4><pre class="json-box" x-text="pretty(ioc.history)"></pre></div>
  466. </div>
  467. <div class="table-wrap mt-2" x-show="extractRows(ioc.history).length">
  468. <table class="data-table">
  469. <thead>
  470. <tr>
  471. <template x-for="col in tableColumns(extractRows(ioc.history))" :key="col">
  472. <th x-text="col"></th>
  473. </template>
  474. </tr>
  475. </thead>
  476. <tbody>
  477. <template x-for="(row, idx) in extractRows(ioc.history)" :key="idx">
  478. <tr>
  479. <template x-for="col in tableColumns(extractRows(ioc.history))" :key="col">
  480. <td x-text="cellText(row[col])"></td>
  481. </template>
  482. </tr>
  483. </template>
  484. </tbody>
  485. </table>
  486. </div>
  487. </div>
  488. <div class="panel-block">
  489. <h3 class="panel-subtitle">File IOC (VirusTotal)</h3>
  490. <div class="grid gap-3 md:grid-cols-4">
  491. <label class="text-sm md:col-span-2"><span class="input-label">File</span><input type="file" @change="onFileSelected($event)" class="input" /></label>
  492. <label class="text-sm"><span class="input-label">Poll timeout (s)</span><input x-model.number="iocFileForm.poll_timeout_seconds" type="number" min="1" class="input" /></label>
  493. <label class="text-sm"><span class="input-label">Poll interval (s)</span><input x-model.number="iocFileForm.poll_interval_seconds" type="number" min="1" class="input" /></label>
  494. </div>
  495. <div class="action-row">
  496. <button class="btn btn-primary" @click="uploadIocFile()">Upload</button>
  497. <button class="btn btn-neutral" @click="evaluateIocFile()">Evaluate File</button>
  498. </div>
  499. <label class="text-sm mt-2 block"><span class="input-label">Analysis ID</span><input x-model="iocFileForm.analysis_id" class="input" /></label>
  500. <button class="btn btn-ghost mt-2" @click="getIocAnalysis()">Get Analysis</button>
  501. <div class="grid gap-3 lg:grid-cols-3 mt-2">
  502. <div><h4 class="panel-mini-title">Upload</h4><pre class="json-box" x-text="pretty(ioc.upload)"></pre></div>
  503. <div><h4 class="panel-mini-title">Analysis</h4><pre class="json-box" x-text="pretty(ioc.analysis)"></pre></div>
  504. <div><h4 class="panel-mini-title">Evaluate File</h4><pre class="json-box" x-text="pretty(ioc.fileEval)"></pre></div>
  505. </div>
  506. <div class="table-wrap mt-2" x-show="extractRows(ioc.analysis).length">
  507. <table class="data-table">
  508. <thead>
  509. <tr>
  510. <template x-for="col in tableColumns(extractRows(ioc.analysis))" :key="col">
  511. <th x-text="col"></th>
  512. </template>
  513. </tr>
  514. </thead>
  515. <tbody>
  516. <template x-for="(row, idx) in extractRows(ioc.analysis)" :key="idx">
  517. <tr>
  518. <template x-for="col in tableColumns(extractRows(ioc.analysis))" :key="col">
  519. <td x-text="cellText(row[col])"></td>
  520. </template>
  521. </tr>
  522. </template>
  523. </tbody>
  524. </table>
  525. </div>
  526. </div>
  527. </section>
  528. <section x-show="activeTab === 'geoip'" x-cloak class="admin-card space-y-4">
  529. <div class="panel-block">
  530. <h3 class="panel-subtitle">GeoIP Lookup</h3>
  531. <div class="grid gap-3 md:grid-cols-3">
  532. <label class="text-sm md:col-span-2">
  533. <span class="input-label">IP Address</span>
  534. <input x-model="geoip.ip" class="input" placeholder="8.8.8.8" />
  535. </label>
  536. <div class="action-row mt-6">
  537. <button class="btn btn-primary" @click="lookupGeoIp()">Lookup</button>
  538. </div>
  539. </div>
  540. <pre class="json-box mt-2" x-text="pretty(geoip.result)"></pre>
  541. <div class="table-wrap mt-2" x-show="keyValueRows(unwrapApiData(geoip.result)?.geoip || {}).length">
  542. <table class="data-table">
  543. <thead><tr><th>Field</th><th>Value</th></tr></thead>
  544. <tbody>
  545. <template x-for="row in keyValueRows(unwrapApiData(geoip.result)?.geoip || {})" :key="row.key">
  546. <tr><td x-text="row.key"></td><td x-text="row.value"></td></tr>
  547. </template>
  548. </tbody>
  549. </table>
  550. </div>
  551. </div>
  552. </section>
  553. <section x-show="activeTab === 'iris'" x-cloak class="admin-card space-y-4">
  554. <div class="panel-block">
  555. <h3 class="panel-subtitle">Create IRIS Ticket</h3>
  556. <div class="grid gap-3 md:grid-cols-2">
  557. <label class="text-sm"><span class="input-label">Title</span><input x-model="irisForm.title" class="input" /></label>
  558. <label class="text-sm"><span class="input-label">Description</span><input x-model="irisForm.description" class="input" /></label>
  559. <label class="text-sm"><span class="input-label">Customer ID</span><input x-model.number="irisForm.case_customer" type="number" class="input" /></label>
  560. <label class="text-sm"><span class="input-label">SOC ID</span><input x-model="irisForm.case_soc_id" class="input" /></label>
  561. </div>
  562. <button class="btn btn-primary mt-2" @click="createIrisTicket()">Create Ticket</button>
  563. <pre class="json-box mt-2" x-text="pretty(iris.create)" ></pre>
  564. </div>
  565. <div class="panel-block">
  566. <h3 class="panel-subtitle">List IRIS Tickets</h3>
  567. <div class="action-row">
  568. <label class="text-sm">Limit <input x-model.number="irisList.limit" type="number" min="1" class="input inline-input" /></label>
  569. <label class="text-sm">Offset <input x-model.number="irisList.offset" type="number" min="0" class="input inline-input" /></label>
  570. <button class="btn btn-neutral" @click="loadIrisTickets()">Load</button>
  571. </div>
  572. <pre class="json-box" x-text="pretty(iris.list)"></pre>
  573. <div class="table-wrap mt-2" x-show="extractRows(iris.list).length">
  574. <table class="data-table">
  575. <thead>
  576. <tr>
  577. <template x-for="col in tableColumns(extractRows(iris.list))" :key="col">
  578. <th x-text="col"></th>
  579. </template>
  580. </tr>
  581. </thead>
  582. <tbody>
  583. <template x-for="(row, idx) in extractRows(iris.list)" :key="idx">
  584. <tr>
  585. <template x-for="col in tableColumns(extractRows(iris.list))" :key="col">
  586. <td x-text="cellText(row[col])"></td>
  587. </template>
  588. </tr>
  589. </template>
  590. </tbody>
  591. </table>
  592. </div>
  593. </div>
  594. </section>
  595. <section x-show="activeTab === 'shuffle'" x-cloak class="admin-card space-y-4">
  596. <div class="panel-block">
  597. <h3 class="panel-subtitle">Shuffle Status</h3>
  598. <div class="action-row">
  599. <button class="btn btn-primary" @click="loadShuffleHealth()">Health</button>
  600. <button class="btn btn-neutral" @click="loadShuffleAuth()">Auth Test</button>
  601. <button class="btn btn-ghost" @click="loadShuffleApps()">Apps</button>
  602. <button class="btn btn-ghost" @click="loadShuffleWorkflows()">Workflows</button>
  603. </div>
  604. <div class="grid gap-3 lg:grid-cols-2">
  605. <div><h4 class="panel-mini-title">Health/Auth</h4><pre class="json-box" x-text="pretty(shuffle.status)"></pre></div>
  606. <div><h4 class="panel-mini-title">Apps/Workflows</h4><pre class="json-box" x-text="pretty(shuffle.catalog)"></pre></div>
  607. </div>
  608. <div class="table-wrap mt-2" x-show="extractRows(shuffle.catalog).length">
  609. <table class="data-table">
  610. <thead>
  611. <tr>
  612. <template x-for="col in tableColumns(extractRows(shuffle.catalog))" :key="col">
  613. <th x-text="col"></th>
  614. </template>
  615. </tr>
  616. </thead>
  617. <tbody>
  618. <template x-for="(row, idx) in extractRows(shuffle.catalog)" :key="idx">
  619. <tr>
  620. <template x-for="col in tableColumns(extractRows(shuffle.catalog))" :key="col">
  621. <td x-text="cellText(row[col])"></td>
  622. </template>
  623. </tr>
  624. </template>
  625. </tbody>
  626. </table>
  627. </div>
  628. </div>
  629. <div class="panel-block">
  630. <h3 class="panel-subtitle">Execute Workflow</h3>
  631. <label class="text-sm"><span class="input-label">Workflow ID</span><input x-model="shuffleExec.workflow_id" class="input" /></label>
  632. <label class="text-sm mt-2 block"><span class="input-label">Payload (JSON)</span><textarea x-model="shuffleExec.payloadText" class="input code-input" rows="6"></textarea></label>
  633. <button class="btn btn-primary mt-2" @click="executeShuffleWorkflow()">Execute</button>
  634. <pre class="json-box mt-2" x-text="pretty(shuffle.execute)"></pre>
  635. </div>
  636. </section>
  637. <section x-show="activeTab === 'wazuh'" x-cloak class="admin-card space-y-4">
  638. <div class="panel-block">
  639. <h3 class="panel-subtitle">Wazuh Status</h3>
  640. <div class="action-row">
  641. <button class="btn btn-primary" @click="wazuhCall('auth')">Auth Test</button>
  642. <button class="btn btn-neutral" @click="wazuhCall('manager')">Manager Info</button>
  643. <button class="btn btn-ghost" @click="wazuhCall('version')">Version</button>
  644. <button class="btn btn-ghost" @click="wazuhCall('autosync')">Auto Sync</button>
  645. </div>
  646. <pre class="json-box" x-text="pretty(wazuh.status)"></pre>
  647. </div>
  648. <div class="panel-block">
  649. <h3 class="panel-subtitle">Wazuh Data</h3>
  650. <div class="action-row">
  651. <label class="text-sm">Limit <input x-model.number="wazuhList.limit" type="number" min="1" class="input inline-input" /></label>
  652. <label class="text-sm">Offset <input x-model.number="wazuhList.offset" type="number" min="0" class="input inline-input" /></label>
  653. <button class="btn btn-neutral" @click="loadWazuhAgents()">Agents</button>
  654. <button class="btn btn-ghost" @click="loadWazuhAlerts()">Alerts</button>
  655. <button class="btn btn-ghost" @click="loadWazuhManagerLogs()">Manager Logs</button>
  656. </div>
  657. <label class="text-sm mt-2 block"><span class="input-label">Query (alerts/logs)</span><input x-model="wazuhList.q" class="input" placeholder="optional q" /></label>
  658. <pre class="json-box mt-2" x-text="pretty(wazuh.list)"></pre>
  659. <div class="table-wrap mt-2" x-show="extractRows(wazuh.list).length">
  660. <table class="data-table">
  661. <thead>
  662. <tr>
  663. <template x-for="col in tableColumns(extractRows(wazuh.list))" :key="col">
  664. <th x-text="col"></th>
  665. </template>
  666. </tr>
  667. </thead>
  668. <tbody>
  669. <template x-for="(row, idx) in extractRows(wazuh.list)" :key="idx">
  670. <tr>
  671. <template x-for="col in tableColumns(extractRows(wazuh.list))" :key="col">
  672. <td x-text="cellText(row[col])"></td>
  673. </template>
  674. </tr>
  675. </template>
  676. </tbody>
  677. </table>
  678. </div>
  679. </div>
  680. <div class="panel-block">
  681. <h3 class="panel-subtitle">Sync Wazuh to MVP</h3>
  682. <div class="grid gap-3 md:grid-cols-3">
  683. <label class="text-sm"><span class="input-label">Minutes</span><input x-model.number="wazuhSync.minutes" type="number" min="1" class="input" /></label>
  684. <label class="text-sm"><span class="input-label">Limit</span><input x-model.number="wazuhSync.limit" type="number" min="1" class="input" /></label>
  685. <label class="text-sm"><span class="input-label">Query</span><input x-model="wazuhSync.q" class="input" /></label>
  686. </div>
  687. <button class="btn btn-primary mt-2" @click="syncWazuhToMvp()">Run Sync</button>
  688. <pre class="json-box mt-2" x-text="pretty(wazuh.sync)"></pre>
  689. </div>
  690. </section>
  691. <section x-show="activeTab === 'mvp'" x-cloak class="admin-card space-y-4">
  692. <div class="panel-block">
  693. <h3 class="panel-subtitle">MVP Health & Policy</h3>
  694. <div class="action-row">
  695. <button class="btn btn-primary" @click="loadMvpDependencies()">Dependencies</button>
  696. <button class="btn btn-neutral" @click="loadMvpPolicy()">Get Policy</button>
  697. <button class="btn btn-ghost" @click="updateMvpPolicy()">Update Policy</button>
  698. </div>
  699. <label class="text-sm block"><span class="input-label">Policy JSON</span><textarea x-model="mvp.policyText" rows="6" class="input code-input"></textarea></label>
  700. <pre class="json-box mt-2" x-text="pretty(mvp.status)"></pre>
  701. <div class="table-wrap mt-2" x-show="keyValueRows(mvp.status).length">
  702. <table class="data-table">
  703. <thead><tr><th>Field</th><th>Value</th></tr></thead>
  704. <tbody>
  705. <template x-for="row in keyValueRows(mvp.status)" :key="row.key">
  706. <tr><td x-text="row.key"></td><td x-text="row.value"></td></tr>
  707. </template>
  708. </tbody>
  709. </table>
  710. </div>
  711. </div>
  712. <div class="panel-block">
  713. <h3 class="panel-subtitle">MVP Incident Ingest</h3>
  714. <textarea x-model="mvp.ingestText" rows="8" class="input code-input"></textarea>
  715. <button class="btn btn-primary mt-2" @click="mvpIngestIncident()">Ingest</button>
  716. <pre class="json-box mt-2" x-text="pretty(mvp.ingest)" ></pre>
  717. </div>
  718. <div class="panel-block">
  719. <h3 class="panel-subtitle">MVP IOC / VPN Evaluate</h3>
  720. <div class="grid gap-3 lg:grid-cols-2">
  721. <div>
  722. <h4 class="panel-mini-title">IOC Evaluate JSON</h4>
  723. <textarea x-model="mvp.iocEvalText" rows="6" class="input code-input"></textarea>
  724. <button class="btn btn-neutral mt-2" @click="mvpEvaluateIoc()">Evaluate IOC</button>
  725. </div>
  726. <div>
  727. <h4 class="panel-mini-title">VPN Evaluate JSON</h4>
  728. <textarea x-model="mvp.vpnEvalText" rows="6" class="input code-input"></textarea>
  729. <button class="btn btn-neutral mt-2" @click="mvpEvaluateVpn()">Evaluate VPN</button>
  730. </div>
  731. </div>
  732. <pre class="json-box mt-2" x-text="pretty(mvp.evaluate)"></pre>
  733. </div>
  734. </section>
  735. <section x-show="activeTab === 'explorer'" x-cloak class="admin-card space-y-4">
  736. <div class="panel-block">
  737. <h3 class="panel-subtitle">OpenAPI Explorer</h3>
  738. <div class="action-row">
  739. <button class="btn btn-primary" @click="loadOpenApiSpec()">Reload OpenAPI</button>
  740. <span class="text-xs text-slate-500" x-text="`Endpoints: ${explorer.endpoints.length}`"></span>
  741. </div>
  742. <div class="grid gap-3 md:grid-cols-3">
  743. <label class="text-sm md:col-span-2">
  744. <span class="input-label">Endpoint</span>
  745. <select class="input" x-model="explorer.selectedKey" @change="selectExplorerEndpoint()">
  746. <template x-for="ep in explorer.endpoints" :key="ep.key">
  747. <option :value="ep.key" x-text="`${ep.method.toUpperCase()} ${ep.path}`"></option>
  748. </template>
  749. </select>
  750. </label>
  751. <label class="text-sm">
  752. <span class="input-label">Path Params (JSON)</span>
  753. <input class="input" x-model="explorer.pathParamsText" placeholder='{"analysis_id":"..."}' />
  754. </label>
  755. </div>
  756. <label class="text-sm block mt-2"><span class="input-label">Query Params (JSON)</span><textarea x-model="explorer.queryText" rows="3" class="input code-input"></textarea></label>
  757. <label class="text-sm block mt-2"><span class="input-label">Body (JSON)</span><textarea x-model="explorer.bodyText" rows="8" class="input code-input"></textarea></label>
  758. <button class="btn btn-primary mt-2" @click="runExplorerRequest()">Run Request</button>
  759. <pre class="json-box mt-2" x-text="pretty(explorer.result)"></pre>
  760. <div class="table-wrap mt-2" x-show="extractRows(explorer.result).length">
  761. <table class="data-table">
  762. <thead>
  763. <tr>
  764. <template x-for="col in tableColumns(extractRows(explorer.result))" :key="col">
  765. <th x-text="col"></th>
  766. </template>
  767. </tr>
  768. </thead>
  769. <tbody>
  770. <template x-for="(row, idx) in extractRows(explorer.result)" :key="idx">
  771. <tr>
  772. <template x-for="col in tableColumns(extractRows(explorer.result))" :key="col">
  773. <td x-text="cellText(row[col])"></td>
  774. </template>
  775. </tr>
  776. </template>
  777. </tbody>
  778. </table>
  779. </div>
  780. </div>
  781. </section>
  782. </main>
  783. </div>
  784. </div>
  785. </body>
  786. </html>