Skip to content

feat(monitors): heartbeat + real DNS source discovery + medium port-scan notice - #242

Merged
ralyodio merged 1 commit into
masterfrom
feat/monitor-heartbeat-and-dns-discovery
Sep 25, 2026
Merged

ralyodio merged 1 commit into
masterfrom
feat/monitor-heartbeat-and-dns-discovery

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Problem

network-monitor and dns-monitor show running but emit nothing, ever — so an operator can't tell "watching, quiet" from "dead". Both are detection-only with thresholds that rarely (network) or never (dns) trip:

  • dns-monitor tails /var/log/syslog etc., but systemd-resolved logs no queries there by default and the real resolver logs to a journal unit that was never configured → it parses zero queries and cannot emit.
  • network-monitor only fires on ≥10 listening-port probes/30s (since the 0.12.4 fix counts listening ports only, that basically never happens) or a SYN flood.

Fixes

  1. Proof-of-life heartbeat (both, info severity, every 15m, never bannable): a low-severity summary of what each module saw in the window. dns-monitor reports queries seen + active sources; network-monitor reports inbound connections/sources across listening ports.
  2. dns-monitor source discovery: defaults to discovering common per-query resolver units (moshpit-dns, dnsmasq, named, unbound, pdns-recursor), tailing only those that exist, and reports its real sources in the host status (or no source). [dns-monitor] journal_units=[...] still overrides.
  3. network-monitor medium notice: a smaller scan (5–9 listening ports) now logs at medium (visible, never bans — auto-defence bans at high); 10+ stays high. Inbound-to-listening only, so the ephemeral outbound-port bug that once banned our upstreams cannot recur.

Tests

New monitor-heartbeat.test.ts: heartbeat emits info with the observed count and resets; DNS tunneling still alerts high; the 5-port medium notice fires with no high event; 10 ports still detects high. Full apps/cli suite 365 pass, tsup build clean.

🤖 Generated with Claude Code

…can notice

network-monitor and dns-monitor showed "running" but emitted nothing, ever:
both are detection-only and their thresholds rarely (or never) trip, so an
operator could not tell "watching, quiet" from "dead". Three fixes:

1. Proof-of-life heartbeat (both, info severity, every 15m, never bannable):
   a low-severity summary of what each module observed in the window —
   dns-monitor reports queries seen and its active sources, network-monitor
   reports inbound connections/sources across listening ports.

2. dns-monitor was blind by default: it tailed /var/log/syslog etc., but
   systemd-resolved logs no queries there and the real resolver logs to a
   journal unit that was never configured. It now defaults to discovering the
   common per-query resolver units (moshpit-dns, dnsmasq, named, unbound,
   pdns-recursor), tailing only those that actually exist, and reports its real
   sources in the host status line (or "no source"). Config still overrides.

3. network-monitor now surfaces a smaller scan (5-9 listening ports) at
   MEDIUM, which logs but never bans (auto-defence bans at high); a real scan
   (10+) stays high. Inbound-to-listening only, so the ephemeral outbound-port
   bug that once banned our upstreams cannot recur.

Tests: heartbeat emits info with the observed count and resets; DNS tunneling
still alerts high; the 5-port medium notice fires without any high event; 10
ports still detects high. Full apps/cli suite 365 pass, build clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

13 finding(s)

HIGH/CRITICAL: 1 | MEDIUM: 6 | LOW: 6

Severity Rule Location
HIGH secret-aws-access-key prd/0003-detect-hardcoded-secrets-before-they-are-committed-or-served.md:126
MEDIUM js-open-redirect apps/web/src/app/auth/login/page.tsx:50
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:104
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:108
MEDIUM js-open-redirect apps/web/src/components/funding/FundingClient.tsx:97
MEDIUM js-unescaped-html-sink apps/web/src/components/GuideReader.tsx:265
MEDIUM js-uninitialized-buffer packages/scan/src/node-rules.ts:456
LOW secret-generic-credential apps/web/src/app/api/auth/refresh/route.ts:17
LOW secret-generic-credential PRD.md:269
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:121
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:122
LOW sh-remote-script-execution scripts/smoke-test.sh:47
LOW secret-aws-access-key scripts/smoke-test.sh:112

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 60c4c40 into master Sep 25, 2026
12 checks passed
@ralyodio
ralyodio deleted the feat/monitor-heartbeat-and-dns-discovery branch September 25, 2026 19:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant