Security logs are useful only when an analyst can connect a finding to the events behind it. TraceGuard is my open-source cybersecurity portfolio project for exploring that workflow: a browser-based workbench that investigates structured logs with five explainable correlation rules.
Built by onkar-cybersec with AI assistance, then reviewed and tested before release. This article was prepared with AI assistance as well.
Five signals, with evidence
TraceGuard analyzes these patterns:
| Signal | Rule |
|---|---|
| Authentication failure burst | Five or more failures for the same source IP and user within five minutes |
| Success after repeated failures | A successful login after five or more failures within ten minutes |
| Privileged role assignment | Explicit assignment of admin, administrator, root or superuser |
| Network egress indicator | At least 10 MiB to a public destination IP, or destination port 4444/1337 |
| Potential secret exposure | Recognized private-key, access-key, bearer-token or password patterns |
These are investigation signals, not proof of a breach. Password mistakes, authorized role changes, backups and lab services can explain some findings.
The investigation workflow
Import a JSON array, an object containing events, or quoted CSV. Inputs are bounded to 2 MiB and 20,000 events, and rejected rows get explanations alongside analysis of valid rows.
The dashboard shows a UTC timeline, category and severity breakdowns, affected users and sources, search and filters. Each finding links to evidence IDs, timestamps, an explanation and investigation steps. You can export redacted JSON or a self-contained HTML report.
The included trigger demo produces 21 valid events and eight findings across the five rules. Resetting and loading the benign baseline produces seven valid events and no findings. Those counts describe the supplied fixtures, not real-world detection accuracy.
Run it locally
Use Node.js 24 or later and pnpm 11 or later:
git clone https://github.com/onkar-cybersec/TraceGuard.git
cd TraceGuard
pnpm install --frozen-lockfile
pnpm dev
Open the local URL printed by Vite. No account, model API key or environment file is needed.
pnpm test
pnpm lint
pnpm build
Release validation included 50 passing automated tests, TypeScript checking and the production build. The trigger and benign demonstrations were also checked in the browser.
Privacy and limitations
Parsing and detection run in the browser. The source has no log-upload endpoint, runtime model calls, telemetry or persistent log store. The host still receives ordinary page requests. For sensitive records, review the source and run a trusted local copy.
Secret masking is best-effort and does not anonymize usernames or IP addresses. Exported reports may contain confidential operational context. Reset clears application state but does not guarantee forensic erasure of memory or downloaded files.
TraceGuard is an educational prototype, not a production SIEM, live scanner or complete intrusion detector. False positives and false negatives are expected. Its static IP classification is a heuristic, and a clean result does not prove a system secure.
Feedback welcome
I would welcome synthetic test cases and feedback on correlation thresholds, evidence presentation and analyst workflows.
Source, screenshots and documentation. MIT licensed.

Top comments (0)