Netsentinel — Security skill for Claude Code
API-driven network threat detection & incident response: CICIDS-2017 ML detector (hierarchical, time-window features), agents with guarded Claude investigations, human-approved responses, tickets, HTT.
How to install Netsentinel
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open gurpreetkaur-ds/netsentinel and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Netsentinel does
API-driven network threat detection & incident response: CICIDS-2017 ML detector (hierarchical, time-window features), agents with guarded Claude investigations, human-approved responses, tickets, HTTPS dashboard
Alternatives in Security
- Free Code — The free build of Claude Code 8.1k ★
- Memory Self Review — Mine recent agent history (claude-mem + usage stats) for recurring failures and repeated patterns, audit MEMOR 297 ★
- AWS MCP Server — by alexei-led - Features multiple Python environment setup options with detailed code style guidelines, compre 182 ★
README
NetSentinel
API-driven network threat detection and incident response, grown from a CICIDS-2017 anomaly-detection notebook. Machine learning makes the detection decision; agents correlate, investigate (Claude), score risk, propose reversible responses for **human approval**, and track tickets.
sensor / replay ─► 1 INGEST (API key) ─► 2-4 VALIDATE · NORMALIZE · EXTRACT ─► 5 MODEL CHECK ─► 6 INFERENCE
─► 7 EVENT PUBLISH ─► Orchestrator (cases) ─► 8 Investigation (Claude) ─► 9 Risk ─► 10 Response (proposals)
─► 11 Ticket ─► 12 Dashboard
| Where | What |
|---|---|
netsentinel/ml/ |
data loading, feature schema, taxonomy, v0 reproduction, v1 hierarchical detector, v2 time-window features |
netsentinel/api/ |
ingest API (/v1/…, loopback) and read-only dashboard (/dashboard, HTTPS) |
netsentinel/agents/ |
detection, orchestrator, investigation, risk, response, ticket |
netsentinel/{bus,registry,llm,wall,db}.py |
event bus, model registry + check, Claude client, Security Wall client |
netsentinel/migrations/ |
PostgreSQL schema (applied by netsentinel migrate) |
ops/ |
systemd units, hardening, TLS, Apache redirect, Security Wall onboarding (root scripts) |
original/ |
the original notebook, unchanged (read-only) |
presentation/NetSentinel.ipynb |
cleaned, runnable story of the project (reads saved results) |
docs/ |
model reports, agents, API, security review, end-to-end validation |
Live deployment
| Service | Purpose |
|---|---|
netsentinel-api |
ingest API on 127.0.0.1:8200 |
netsentinel-detection / -orchestrator / -investigation / -risk / -response / -ticket |
the agents |
netsentinel-sensor |
live capture of this server's traffic (shadow mode: scored, no alerts); see docs/live-sensor.md |
netsentinel-dashboard |
https://:8443/dashboard (Let's Encrypt; firewall: owner IPs only) |
Active model: **`netsentinel-v2`** (per-flow + per-source 60 s window features, with a pe
Related Skills
Safeai
🛡️ Local security gateway & Human-in-the-Loop firewall for AI coding agents (Copilot, Cursor, Antigravity, Cl
Agent Security Super Skill
Comprehensive AI agent security skill — prompt injection defense, skill validation, memory poisoning preventio
Security AI Workflows
AI assistants can support security engineering through code analysis, threat identification, configuration rev
Cybersecurity Automation Portfolio 30 n8n Workflows
30 ready-to-import n8n workflows for security operations across three tiers (Basic, Mid, Advanced). They cover
Audit Tenancy
Audit multi-tenancy enforcement — RLS policies, withTenantDb usage, query-time tenant filters, and cross-tenan
Linear Implementation Audit
Check open Linear tickets against the code to find what is done, partly done, not started, or obsolete, then u
Related Agents
UX Research Synthesizer
Synthesizes user interviews, survey responses, support tickets, or other user research into themes, patterns,
Discovery Synthesizer
Turns raw research (interview transcripts, feedback, survey responses, tickets) into coded themes, scored oppo
Swagger Documenter
Enriches the FastAPI OpenAPI/Swagger docs of the BookShelf backend. Adds summary, description, response_descri