gurpreetkaur-ds

Netsentinel — Security skill for Claude Code

Security community

API-driven network threat detection & incident response: CICIDS-2017 ML detector (hierarchical, time-window features), agents with guarded Claude investigations, human-approved responses, tickets, HTT.

How to install Netsentinel

This entry records only its repository, not the path inside it, so there is no exact command to give. Open gurpreetkaur-ds/netsentinel and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Netsentinel does

API-driven network threat detection & incident response: CICIDS-2017 ML detector (hierarchical, time-window features), agents with guarded Claude investigations, human-approved responses, tickets, HTTPS dashboard

Alternatives in Security

  • Free Code — The free build of Claude Code 8.1k ★
  • Memory Self Review — Mine recent agent history (claude-mem + usage stats) for recurring failures and repeated patterns, audit MEMOR 297 ★
  • AWS MCP Server — by alexei-led - Features multiple Python environment setup options with detailed code style guidelines, compre 182 ★

README

NetSentinel

API-driven network threat detection and incident response, grown from a CICIDS-2017 anomaly-detection notebook. Machine learning makes the detection decision; agents correlate, investigate (Claude), score risk, propose reversible responses for **human approval**, and track tickets.

sensor / replay ─► 1 INGEST (API key) ─► 2-4 VALIDATE · NORMALIZE · EXTRACT ─► 5 MODEL CHECK ─► 6 INFERENCE
  ─► 7 EVENT PUBLISH ─► Orchestrator (cases) ─► 8 Investigation (Claude) ─► 9 Risk ─► 10 Response (proposals)
  ─► 11 Ticket ─► 12 Dashboard
Where What
netsentinel/ml/ data loading, feature schema, taxonomy, v0 reproduction, v1 hierarchical detector, v2 time-window features
netsentinel/api/ ingest API (/v1/…, loopback) and read-only dashboard (/dashboard, HTTPS)
netsentinel/agents/ detection, orchestrator, investigation, risk, response, ticket
netsentinel/{bus,registry,llm,wall,db}.py event bus, model registry + check, Claude client, Security Wall client
netsentinel/migrations/ PostgreSQL schema (applied by netsentinel migrate)
ops/ systemd units, hardening, TLS, Apache redirect, Security Wall onboarding (root scripts)
original/ the original notebook, unchanged (read-only)
presentation/NetSentinel.ipynb cleaned, runnable story of the project (reads saved results)
docs/ model reports, agents, API, security review, end-to-end validation

Live deployment

Service Purpose
netsentinel-api ingest API on 127.0.0.1:8200
netsentinel-detection / -orchestrator / -investigation / -risk / -response / -ticket the agents
netsentinel-sensor live capture of this server's traffic (shadow mode: scored, no alerts); see docs/live-sensor.md
netsentinel-dashboard https://:8443/dashboard (Let's Encrypt; firewall: owner IPs only)

Active model: **`netsentinel-v2`** (per-flow + per-source 60 s window features, with a pe