
Host Telemetry And Triage
Collect Windows process, network, file, WHIDS, OSSEC/HIDS, and incident signals into one analyst-readable operating picture.
Windows telemetry / malware triage / governed response
A local security operations platform for host telemetry, suspicious-process investigation, file and malware analysis, antivirus containment, ATT&CK coverage, enterprise casework, and audit-ready response.
ShadowLab separates the noise into rooms: telemetry, process intelligence, persistence, file analysis, network, antivirus containment, ATT&CK, evidence, casework, and controlled response. Each room keeps the next analyst action visible.

Collect Windows process, network, file, WHIDS, OSSEC/HIDS, and incident signals into one analyst-readable operating picture.

Combine native Detect It Easy, PE fallback, local YARA, memory tradecraft rules, sandbox traces, and AI-assisted triage.

Move from verdicts and quarantine into enterprise cases with assignments, approvals, notes, evidence pins, exports, and audit history.
The response path is intentionally governed. Every enrichment, ATT&CK mapping, approval, mutation, containment action, and export remains attached to the final record.
Windows process, file, network, WHIDS, OSSEC/HIDS, packet, and incident telemetry enter a normalized backend model.
Process trees, strings, internals, persistence artifacts, sandbox traces, and PE structure turn raw activity into evidence.
YARA, memory rules, trusted-publisher checks, antivirus providers, heuristics, and enrichment feed a consensus-aware verdict.
Incidents and cases are enriched with ATT&CK coverage, tactic heat, Navigator layers, and Workbench-oriented exports.
Quarantine, rollback, network blocker controls, approvals, signed mutations, and policy gates keep impact-heavy actions governed.
Reports, audit mirrors, artifact bundles, case notes, graph context, and timeline context move into handoff-ready output.
The screens are product-real surfaces from the lab: dashboards, WHIDS, HIDS, overview, processes, persistence, file analysis, network, graph, timeline, antivirus, artifacts, enterprise, and security operations.
The dashboard wall condenses platform health, threat posture, auth state, telemetry freshness, and investigation summaries into one operator view.

Overview gives the analyst a high-signal incident brief with monitor output, telemetry posture, and the current detection story.

Profiling, process-tree review, strings, internals, YARA, memory analysis, sandbox traces, AI triage, and response context stay together.

Scheduled tasks, services, registry footholds, and startup artifacts are grouped by risk so cleanup is deliberate instead of cosmetic.

Native Detect It Easy, optional DiE binaries, PE fallback, file/process submission, highlights, and YARA context sit in one focused workspace.

Connection review, packet capture, ARP discovery, blocker controls, and host inventory are separated by privilege so visibility does not become unsafe action.

Relationships are treated as evidence, not decoration. The graph makes the next investigative move legible.

Actions, detections, and analyst notes line up into a response narrative the team can trust.

Provider health, verdict history, quarantine, response actions, rules, lists, webhooks, and trusted-publisher logic keep containment explainable.

Incident, action, auth, and audit history stay available for retrospective investigation and operational review.

Reports, telemetry exports, collected evidence, files, hashes, screenshots, and investigation output remain attached to the record.

Enterprise Ops and Enterprise Intel manage assignments, tasks, approvals, notes, stories, evidence pins, ATT&CK coverage, and exports.

Integrity, observability, secrets, YARA health, retention, audit export, policy posture, origin controls, and reporting are operational controls.

WHIDS manager sync, report ingest, artifact pull, scheduler state, IoCs, rules, and enterprise pivots are available from one surface.

OSSEC/HIDS alert streams, live ingest, host state, rule matches, file changes, and response planning are connected to incidents.

The about surface keeps profile, FAQ, and platform framing close to the product so credibility follows the interface instead of replacing it.


Ulfat Ibadov created ShadowLab as a Windows-first cybersecurity operations platform for detection engineering, malware triage, incident response practice, enterprise casework, and evidence-led investigations.
ShadowLab is a Windows-first cybersecurity operations platform built around a local FastAPI backend and a PySide6 desktop operator console. It is made for cybersecurity engineers, detection engineers, threat hunters, incident responders, malware analysts, and developers who need telemetry, cases, response, and evidence to stay connected.
It is intended for owned, isolated lab environments where response actions, packet inspection, ARP discovery, network blocker controls, and malware-analysis workflows can be tested responsibly.