Automated Security Reconnaissance and Intelligence Pipeline
Project Watchdog is a high-performance, automated reconnaissance and vulnerability scanning pipeline. Engineered for speed and scalability, it leverages a serverless AWS architecture to deploy ephemeral, tool-rich scanning environments on demand.
The system operates on a "Trigger-and-Terminate" model, ensuring maximum cost-efficiency and security isolation.
- Ingress: A secure webhook hits the API Gateway.
- Orchestration: AWS Lambda validates the request and provisions an EC2 Spot Instance.
- Bootstrapping: The instance executes a specialized setup sequence, installing a full suite of security tools in seconds.
- Intelligence Gathering:
- Network Mapping: netmalper generates a comprehensive attack surface graph.
- Vulnerability Discovery: vulnmalper identifies potential entry points.
- AI Synthesis: malper-analyse uses Large Language Models to interpret raw data into actionable intelligence.
- Exfiltration: Results are securely pushed to a Supabase backend.
- Alerting: Real-time status updates are dispatched via Telegram.
- Auto-Destruction: The instance self-terminates immediately upon completion, leaving no footprint.
- Serverless Orchestration: No idle infrastructure; pay only for active scan time.
- AI-Enhanced Analysis: Moves beyond raw tool output to provide human-readable summaries.
- Rapid Deployment: Tailored bootstrap scripts ensure tools are ready in under 2 minutes.
- Isolated Environments: Every target is scanned in a fresh, dedicated instance.
- Instant Visibility: Telegram integration provides a live "heartbeat" of the scanning process.
Scripts/: The "Brain" - Contains orchestrator and bootstrap logic.Terraform/: The "Skeleton" - Defines the entire AWS infrastructure.docs/: The "Manual" - Comprehensive guides for deployment, operation, and the Web UI.examples/: The "Templates" - Payload and configuration examples.
Note: This project requires an active AWS account and API keys for Supabase, OpenRouter, and Telegram.
For complete, step-by-step instructions on deploying the pipeline, please consult our primary documentation:
Once your infrastructure is live, initiate a scan using a standard HTTP client:
curl -X POST https://<your-api-endpoint>/scan \
-H "x-api-key: <your_secret_key>" \
-H "Content-Type: application/json" \
-d '{
"target": "example.com",
"mode": "normal"
}'| Profile | Compute Resource | Performance Characteristics |
|---|---|---|
| normal | t3.small | Balanced for speed and cost. |
| stealth | t3.large | Rate-limited to avoid detection. |
| head | t3.large | Full browser rendering for complex JS targets. |
- PROJECT LOGO: Interactive, high-tech HTML/CSS branding for the Watchdog project.
AUTHORIZED TESTING ONLY. This software is designed for security professionals and researchers. Usage against targets without explicit permission is strictly prohibited and may be illegal.