Skip to content

About

File integrity monitoring, network intrusion alerts, and security log analysis

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Mini Security Suite shield icon

Mini Security Suite

Three security tools. One desktop workspace.
File integrity monitoring, network intrusion alerts, and security log analysis
in a Python desktop app with dark and light themes.

Screenshots · Features · Getting started · Build


Mini Security Suite brings MiniFIM, MiniIDS, and Security Log Analyzer together in one Windows application. Choose a folder to watch, select a network adapter, or open a security log—all from the same sidebar.

Windows desktop · Python 3.12 · Local processing · Dark & light modes

Screenshots

Dark and light modes

Switch themes without stopping your work. The app remembers your choice for the next launch.

Dark mode Light mode
Dark overview with file, network, and log-analysis tool cards Light overview showing the same tools and recent activity

Log analysis

Explore detected events, threat scores, source IPs, and activity over time.

Log-analysis dashboard showing detected events and charts for the included sample log

Screenshots show the running application with the included synthetic sample log. No live network capture or personal log data is shown. Click an image to view it at full size.

Features

Tool What it does
Overview Displays tool status, quick-start actions, and recent activity.
File Monitoring Detects created, modified, and deleted files using SHA-256 hashes. Includes a baseline viewer, exclusion patterns, configurable scan intervals, and CSV export.
Network Monitoring Observes IPv4 traffic and flags potential SYN floods, port scans, and unusually high traffic from a source. Includes adapter selection, configurable thresholds, and alert export.
Log Analysis Analyzes SSH/auth and Apache/Nginx-style access logs. Includes charts, searchable and sortable events, custom regex rules, saved scan history, and JSON/CSV/HTML reports.
Settings Controls appearance, desktop notifications, exclusions, scan intervals, and detection thresholds.

Shared experience

  • One application window with consistent navigation and a shield app icon.
  • Dark and light themes for app controls, tables, charts, and message dialogs.
  • Background file hashing, packet capture, and log analysis.
  • Independent start/stop controls for file and network monitoring.
  • SQLite history and settings saved locally between launches.
  • Log events displayed in pages of 500; search and sorting cover all matches.
  • Optional desktop notifications for warnings and alerts.

Log detections

Built-in rules cover SSH brute-force indicators, invalid SSH users, sudo/authentication failures, SQL injection probes, XSS payloads, path traversal attempts, sensitive-file scans, suspicious user agents, and repeated HTTP errors.

Getting started

Option 1: Windows executable

If a Windows build is provided under this repository's Releases:

  1. Download MiniSecuritySuite-Windows-x64.zip.
  2. Extract the entire ZIP into a folder you want to keep.
  3. Double-click MiniSecuritySuite.exe.
  4. Optionally run Create Desktop Shortcut.cmd to add the shield shortcut to your desktop.

No separate Python installation is needed. Keep the executable beside its _internal folder.

Option 2: Run from source

Install Python 3.12, 64-bit, then clone this repository or download it using Code → Download ZIP. Open PowerShell in the folder containing main.py and run:

python -m venv .venv
.\.venv\Scripts\python.exe -m pip install -r requirements.txt
.\.venv\Scripts\python.exe main.py
Dependency Purpose
ttkbootstrap Desktop interface and themes
Matplotlib Embedded analysis charts
Scapy Network packet capture and parsing
Pillow App and navigation icons
Plyer Optional desktop notifications
SQLite Local history, using Python's standard library

The tested package versions are recorded in requirements-lock.txt.

Windows network capture

Network monitoring requires Npcap, installed separately. Restart the app after installing it, then refresh the adapter list.

If capture reports access denied, close the app and launch it using Run as administrator. File monitoring and log analysis work without Npcap. The app does not automatically install drivers or request elevation.

Quick walkthrough

Monitor a folder

  1. Open File Monitoring and choose a folder.
  2. Select Start monitoring to build its baseline.
  3. Create, edit, or delete a file in that folder.
  4. Review Changes or inspect hashes under Baseline files → Refresh.
  5. Use Export CSV to save file activity.

Watch network activity

  1. Open Network Monitoring → Refresh adapters.
  2. Choose a Wi-Fi, Ethernet, or loopback adapter.
  3. Select Start monitoring and review alerts.
  4. Adjust thresholds under Settings, then restart monitoring to apply them.

Default detection settings preserve the original MiniIDS behavior:

Setting Default
Detection window 5 seconds
SYN threshold per source 20 packets
Port-scan threshold per source 15 distinct target ports
Traffic threshold per source 100 IPv4 packets

SYN+ACK packets do not count toward SYN scan thresholds. A detection is reported once per source within each window. The tool observes traffic visible to the selected adapter; it does not block connections.

Analyze the sample log

  1. Open Log Analysis → Open log.
  2. Choose sample_logs/mixed_security.log.
  3. Select Analyze.
  4. Explore Dashboard, Events, Rules, History, and Report.
  5. Export a JSON, CSV, or HTML report.

The sample uses demonstration addresses and can be analyzed without network capture.

Keyboard shortcuts

Shortcut Action
Ctrl+1 Overview
Ctrl+2 File Monitoring
Ctrl+3 Network Monitoring
Ctrl+4 Log Analysis
Ctrl+5 Settings
Ctrl+T Switch dark/light theme
Tab Move between controls

Local data and behavior

Settings, baseline snapshots, activity, scan history, custom rules, and diagnostic logs are stored in:

%LOCALAPPDATA%\MiniSecuritySuite

On first launch, the app imports a copy of an existing %USERPROFILE%\.security_log_analyzer\history.db if no suite database exists. The original database is preserved.

  • Each monitoring session builds a fresh file baseline. Later scans compare with the previous scan; changes made while the app is closed are not tracked.
  • Unreadable files retain their previous baseline and generate a warning instead of being reported as deleted.
  • The suite's own data directory is excluded from file monitoring.
  • Activity views show the latest 1,000 entries, with the latest 100 on Overview. Log-analysis history and reports retain all detected events.
  • Monitoring starts manually and stops when the app closes. Monitoring settings apply on the next start; themes change immediately.
  • Windows file pickers follow the operating system's appearance settings.

Build the Windows app

Run from the source project folder:

powershell -NoProfile -ExecutionPolicy Bypass -File build.ps1

The build installs dependencies, generates icons, runs regression tests, builds a windowed executable with PyInstaller, and packages the results:

dist/MiniSecuritySuite/MiniSecuritySuite.exe
release/MiniSecuritySuite-Windows-x64.zip
release/MiniSecuritySuite-Source.zip

Tests

Run regression tests:

.\.venv\Scripts\python.exe -m unittest discover -v

Run GUI smoke checks with isolated data:

$env:MINISECURITY_DATA_DIR = Join-Path $PWD 'build\smoke-check'
.\.venv\Scripts\python.exe main.py --smoke-test
Get-Content build\smoke-check\smoke-result.json
Remove-Item Env:\MINISECURITY_DATA_DIR

Tests cover file changes and unreadable paths, repeated monitor starts/stops, synthetic network detection, capture failures, log parsing, custom rules, history migration, exports, themes, and simultaneous background work. The smoke test does not start live packet capture.

See VERIFICATION.md for test results and verification limits.

Project structure

MiniSecuritySuite/
├── main.py                   # Application entry point
├── suite/                    # Shared UI, themes, settings, and monitor services
├── security_log_analyzer/    # Log parsing, rules, history, and report exports
├── assets/                   # Application and navigation icons
├── docs/images/              # README screenshots and logo
├── sample_logs/              # Synthetic demonstration log
├── tests/                    # Regression tests
├── tools/                    # Asset generation and packaging helpers
├── requirements.txt          # Application dependencies
├── requirements-build.txt    # Build dependencies
├── requirements-lock.txt     # Tested dependency versions
├── MiniSecuritySuite.spec    # PyInstaller configuration
└── build.ps1                 # Windows build script

Publishing this project

Keep README.md and docs/images/ together in the repository so these screenshots render on GitHub. Upload the source files to the repository and attach the Windows ZIP separately as a release asset.

See the GitHub upload guide for the files to include. The supplied .gitignore excludes virtual environments, build outputs, release archives, and runtime databases.

Acknowledgments

Built from the user-supplied MiniFIM, MiniIDS, and Security Log Analyzer projects. See THIRD_PARTY.md for source attribution and dependency notices.

About

File integrity monitoring, network intrusion alerts, and security log analysis

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages