Sign inSign up

kygnus/clamnet

By kygnus

โ€ขUpdated 12 months ago

Image
0

133

kygnus/clamnet repository overview

โ ๐Ÿ›ก๏ธ ClamAV Console Web App

A cross-platform, web-based, open-source console for managing and automating ClamAV antivirus across remote Linux and Windows systems. This app provides tools for remote installation, on-demand scanning, database updates, network topology visualization, IOC scanning, PCAP analysis, and malware analysis โ€” all from a single, secure dashboard.


โ ๐Ÿš€ Features

โ Core ClamAV Management
  • โœ… Remote Installation of ClamAV on Linux and Windows systems
  • ๐Ÿ” Scan Local and Remote Systems with ClamAV
  • ๐Ÿ”„ Automatic Virus Database Updates across multiple remote hosts
  • ๐ŸŒ Network Scanning to detect systems with ClamAV installed
โ Network Analysis
  • ๐Ÿ“Š System Monitoring: CPU, RAM, and network usage
  • ๐Ÿ”Ž PCAP Analysis for network traffic inspection
  • ๐ŸŒ Network Protocol Visualization
โ Security Analysis
  • ๐Ÿ” IOC Scanning with YARA rules and hash matching
  • ๐Ÿงช Malware Analysis with Pepper framework
  • ๐Ÿ•ต๏ธ Control Flow Graph Analysis for binary inspection
  • ๐Ÿ“ File Metadata Analysis
โ Platform Features
  • ๐Ÿงฐ CLI and GUI elements powered by Flask + Jinja2
  • ๐Ÿ“ฆ Multi-threaded with real-time logs using Server-Sent Events (SSE)
  • ๐Ÿ–ฅ๏ธ Cross-platform: supports both Linux and Windows servers
  • ๐Ÿ” Login-Authenticated Dashboard (Flask-Login)

โ ๐Ÿ“ธ Screenshots

clamNET Dashboard clamNET scan IOC Scanner PCAP Analysis


โ โš™๏ธ Installation

โ ๐Ÿ“‹ Prerequisites
  • Python 3.11+
  • pip / virtualenv
  • SSH access to remote systems
  • ClamAV MSI for Windows installs (clamav-1.*.*.win.x64.msi) should be present on the server
  • Optional dependencies for advanced features:
    • libpcap for PCAP analysis
    • yara for IOC scanning
    • pepper for malware analysis
โ ๐Ÿ”ง Setup
git clone https://github.com/KYGnus/clamNET.git
cd clamNET
python3 -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate
pip install -r requirements.txt

Note: These requirements are for Python 3.11.13

โ Advanced Feature Setup

For PCAP analysis:

sudo apt-get install libpcap-dev  # Debian/Ubuntu
sudo yum install libpcap-devel    # CentOS/RHEL

For Pepper analysis:

git clone https://github.com/KYGnus/pepper.git
cp pepper/pepper.py ./clamNET/

โ ๐Ÿ” Default Login

UsernamePassword
config.USERNAMEconfig.PASSWORD

โš ๏ธ Change the admin password in main.py before deploying to production:

ADMIN_PASSWORD_HASH = generate_password_hash('your_secure_password_here')

โ โ–ถ๏ธ Running the App

python main.py

Then visit: http://localhost:5005โ 


โ ๐ŸŒ Network Features

โ Topology Scanning

Scan a network (e.g., 192.168.1.0/24) to:

  • Discover active hosts
  • Detect OS via TTL analysis
  • Visualize network structure
  • Identify ClamAV installations
โ PCAP Analysis
  • Upload packet capture files (.pcap, .pcapng)
  • Protocol distribution visualization
  • Traffic pattern analysis
  • Suspicious activity detection

โ ๐Ÿ› ๏ธ Usage Guide

โ ๐Ÿ”ง ClamAV Installation
  1. Navigate to the Install page
  2. Enter target IPs (comma-separated)
  3. Provide SSH credentials
  4. The app will auto-detect OS and install the appropriate ClamAV version
โ ๐Ÿ”„ Database Updates
  1. Go to the Update page
  2. Select target hosts
  3. Monitor real-time update progress
โ ๐Ÿงช Security Scanning
โ Basic Scanning:
  • Select local or remote scan
  • Choose directory path
  • View real-time results
โ Advanced Scanning:
  • IOC Scanner: Upload files for YARA rule matching and hash analysis
  • PCAP Analyzer: Inspect network traffic patterns
  • Pepper Analysis: Perform deep malware analysis on executables
  • CFG Analysis: Examine binary control flow graphs

โ ๐Ÿ“ File Structure

.
โ”œโ”€โ”€ main.py                # Main Flask application
โ”œโ”€โ”€ modules/               # Additional functional modules
โ”‚   โ”œโ”€โ”€ pcap.py            # PCAP analysis
โ”‚   โ””โ”€โ”€ installer.py       # Remote installation
โ”œโ”€โ”€ templates/             # HTML templates
โ”œโ”€โ”€ static/                # CSS/JS assets
โ”œโ”€โ”€ ioc_rules/             # YARA rules for IOC scanning
โ”œโ”€โ”€ uploads/               # File upload directory
โ”œโ”€โ”€ clamav-*.win.x64.msi   # Windows installer
โ”œโ”€โ”€ pepper.py              # Malware analysis tool
โ””โ”€โ”€ requirements.txt       # Python dependencies

โ ๐Ÿงช Tested Platforms

OSRemote InstallScanningUpdateIOC ScanPCAP Analysis
Ubuntuโœ…โœ…โœ…โœ…โœ…
openSUSEโœ…โœ…โœ…โœ…โœ…
Windows 10โœ…โœ…โœ…โœ…โœ…
macOSโŒโœ…โŒโœ…โœ…

โ ๐Ÿค Contributing

  1. Fork the repository
  2. Create a feature branch: git checkout -b feature-name
  3. Commit your changes: git commit -m "Add feature"
  4. Push to your fork: git push origin feature-name
  5. Submit a pull request

Development Setup:

git clone https://github.com/KYGnus/clamNET.git
cd clamNET
python3.12 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
cd app
python main.py

run in Firejail

# run your venv python in firejail, no network, private home and tmp
firejail --private=/home/koosha/sandbox-home \
         --net=none \
         --caps.drop=all \
         --private-tmp \
         --whitelist=/path/to/allowed/data \
         /path/to/venv/bin/python /path/to/app.py


โ ๐Ÿ“ƒ License

MIT Licenseโ  ยฉ 2025 KYGnus


โ ๐Ÿ“ž Contact

Tag summary

Content type

Image

Digest

sha256:883b87a6eโ€ฆ

Size

502.2 MB

Last updated

12 months ago

docker pull kygnus/clamnet