Windows telemetry index 001FastAPI / PySide6 operator consoleSignal live

Windows telemetry / malware triage / governed response

ShadowLabturns signalinto action.

A local security operations platform for host telemetry, suspicious-process investigation, file and malware analysis, antivirus containment, ATT&CK coverage, enterprise casework, and audit-ready response.

Local security operations surfaceTelemetry, cases, evidence, and response moving in one workflow
Core Capabilities

Windows defense work arranged like an operations atlas, not a dashboard dump.

ShadowLab separates the noise into rooms: telemetry, process intelligence, persistence, file analysis, network, antivirus containment, ATT&CK, evidence, casework, and controlled response. Each room keeps the next analyst action visible.

Host Telemetry And Triage screen
01

Host Telemetry And Triage

Collect Windows process, network, file, WHIDS, OSSEC/HIDS, and incident signals into one analyst-readable operating picture.

File And Malware Analysis screen
02

File And Malware Analysis

Combine native Detect It Easy, PE fallback, local YARA, memory tradecraft rules, sandbox traces, and AI-assisted triage.

Containment And Casework screen
03

Containment And Casework

Move from verdicts and quarantine into enterprise cases with assignments, approvals, notes, evidence pins, exports, and audit history.

Pipeline

A case moves forward only when the evidence and policy move with it.

The response path is intentionally governed. Every enrichment, ATT&CK mapping, approval, mutation, containment action, and export remains attached to the final record.

001

Ingest host signals

Windows process, file, network, WHIDS, OSSEC/HIDS, packet, and incident telemetry enter a normalized backend model.

002

Investigate behavior

Process trees, strings, internals, persistence artifacts, sandbox traces, and PE structure turn raw activity into evidence.

003

Fuse verdicts

YARA, memory rules, trusted-publisher checks, antivirus providers, heuristics, and enrichment feed a consensus-aware verdict.

004

Map ATT&CK context

Incidents and cases are enriched with ATT&CK coverage, tactic heat, Navigator layers, and Workbench-oriented exports.

005

Control response

Quarantine, rollback, network blocker controls, approvals, signed mutations, and policy gates keep impact-heavy actions governed.

006

Export the record

Reports, audit mirrors, artifact bundles, case notes, graph context, and timeline context move into handoff-ready output.

Platform

A product archive that reads like an operator console.

The screens are product-real surfaces from the lab: dashboards, WHIDS, HIDS, overview, processes, persistence, file analysis, network, graph, timeline, antivirus, artifacts, enterprise, and security operations.

Room 01 / Command

Platform posture is visible before the incident starts.

The dashboard wall condenses platform health, threat posture, auth state, telemetry freshness, and investigation summaries into one operator view.

ShadowLab Room 01 / Command: Platform posture is visible before the incident starts.
Room 02 / Monitor

Live operations need a calm first read.

Overview gives the analyst a high-signal incident brief with monitor output, telemetry posture, and the current detection story.

ShadowLab Room 02 / Monitor: Live operations need a calm first read.
Room 03 / Processes

Process behavior is where intent starts to show.

Profiling, process-tree review, strings, internals, YARA, memory analysis, sandbox traces, AI triage, and response context stay together.

ShadowLab Room 03 / Processes: Process behavior is where intent starts to show.
Room 04 / Persistence

Persistence is treated as a remediation map.

Scheduled tasks, services, registry footholds, and startup artifacts are grouped by risk so cleanup is deliberate instead of cosmetic.

ShadowLab Room 04 / Persistence: Persistence is treated as a remediation map.
Room 05 / File Analysis

Malware analysis becomes a decision surface.

Native Detect It Easy, optional DiE binaries, PE fallback, file/process submission, highlights, and YARA context sit in one focused workspace.

ShadowLab Room 05 / File Analysis: Malware analysis becomes a decision surface.
Room 06 / Network

Network telemetry is converted into response context.

Connection review, packet capture, ARP discovery, blocker controls, and host inventory are separated by privilege so visibility does not become unsafe action.

ShadowLab Room 06 / Network: Network telemetry is converted into response context.
Room 07 / Graph

Every host, process, and artifact has a place in the map.

Relationships are treated as evidence, not decoration. The graph makes the next investigative move legible.

ShadowLab Room 07 / Graph: Every host, process, and artifact has a place in the map.
Room 08 / Timeline

Incidents are reconstructed as a story with timestamps.

Actions, detections, and analyst notes line up into a response narrative the team can trust.

ShadowLab Room 08 / Timeline: Incidents are reconstructed as a story with timestamps.
Room 09 / Antivirus

Containment is governed by provider consensus.

Provider health, verdict history, quarantine, response actions, rules, lists, webhooks, and trusted-publisher logic keep containment explainable.

ShadowLab Room 09 / Antivirus: Containment is governed by provider consensus.
Room 10 / History

Past incidents become an audit instrument.

Incident, action, auth, and audit history stay available for retrospective investigation and operational review.

ShadowLab Room 10 / History: Past incidents become an audit instrument.
Room 11 / Artifacts

Evidence is stored like it may be challenged later.

Reports, telemetry exports, collected evidence, files, hashes, screenshots, and investigation output remain attached to the record.

ShadowLab Room 11 / Artifacts: Evidence is stored like it may be challenged later.
Room 12 / Enterprise

Cases scale when ownership is visible.

Enterprise Ops and Enterprise Intel manage assignments, tasks, approvals, notes, stories, evidence pins, ATT&CK coverage, and exports.

ShadowLab Room 12 / Enterprise: Cases scale when ownership is visible.
Room 13 / Security Ops

Readiness is measured before pressure arrives.

Integrity, observability, secrets, YARA health, retention, audit export, policy posture, origin controls, and reporting are operational controls.

ShadowLab Room 13 / Security Ops: Readiness is measured before pressure arrives.
Room 14 / WHIDS

Windows host telemetry gets its own lane.

WHIDS manager sync, report ingest, artifact pull, scheduler state, IoCs, rules, and enterprise pivots are available from one surface.

ShadowLab Room 14 / WHIDS: Windows host telemetry gets its own lane.
Room 15 / HIDS

Host intrusion signals are normalized for investigation.

OSSEC/HIDS alert streams, live ingest, host state, rule matches, file changes, and response planning are connected to incidents.

ShadowLab Room 15 / HIDS: Host intrusion signals are normalized for investigation.
Room 16 / About

The product explains itself without becoming a brochure.

The about surface keeps profile, FAQ, and platform framing close to the product so credibility follows the interface instead of replacing it.

ShadowLab Room 16 / About: The product explains itself without becoming a brochure.
Stack

The system is built like a local security platform, not a single-purpose script.

01FastAPI Routes
02PySide6 Operator Console
03SQLite / PostgreSQL
04YARA + YARAify
05Detect It Easy
06WHIDS / OSSEC HIDS
07Antivirus Providers
08RBAC + Signed Requests
Ulfat Ibadov, creator of ShadowLab
Built byUlfat Ibadov
Conversation

ShadowLab is Ulfat Ibadov's focused lab for defensible cyber decisions.

Ulfat Ibadov created ShadowLab as a Windows-first cybersecurity operations platform for detection engineering, malware triage, incident response practice, enterprise casework, and evidence-led investigations.

ShadowLab is a Windows-first cybersecurity operations platform built around a local FastAPI backend and a PySide6 desktop operator console. It is made for cybersecurity engineers, detection engineers, threat hunters, incident responders, malware analysts, and developers who need telemetry, cases, response, and evidence to stay connected.

It is intended for owned, isolated lab environments where response actions, packet inspection, ARP discovery, network blocker controls, and malware-analysis workflows can be tested responsibly.