Aurora Core

Aurora Core

Loading

SOC & NOC

Standard monitoring tools are actually pretty good and they do their job, but they can be a bit too technical and rigid. You can’t really customize them the way you want. I wanted something different for my home network protection, a dedicated view that displays real-time key metrics from my entire home infrastructure and every device connected to it, scrubbed of all sensitive intelligence so it can be safely mirrored here on my public site.

Of course, in my quest to avoid “too technical” tools, I might have climbed the tree ass-first; AURORA CORE V6.3 (and next versions) is anything but simple.

The Blood, Sweat, and Tears

Before we go further, let’s be clear: Aurora Core, SIG, and the WpE UI are not for distribution. I’m never giving these out. This project has evolved through cycles of absolute pain and frustration. We’re talking about several cycles of “sudo mkfs -t ext4 /dev/sd0” (complete drive wipes) constant re-installs, dozens of bash scripts, and factory resetting my core infrastructure because the dashboard’s data logic didn’t match the “Aurora’s” state 1:1.

I’ve lost my internet connection dozens of times, bricked CSS layouts, and fought with JSON parsing errors for weeks just to get the current interactive state. I have enough of a job providing “micro-support” for myself, this is private for a reason.

The Hardware & Logic

The engine is a heavily overclocked Raspberry Pi 4. I’ve pushed the clock speeds to the limit because when you’re running CrowdSec, Pi-hole, Suricata, NetData, NetAlertX and real-time UI generation, you need every bit of performance. To keep her from melting under the load, she’s housed in a dual-fan Armor Case.

Important: The Aurora Core hardware is the heart of my digital perimeter. It’s built to be a rock-solid, professional-grade appliance that handles real-time threat intelligence without breaking a sweat, while maintaining a visual “vibe” that screams total network control.

Advanced Alerting & Status Sync

In V6.3, the system’s “heartbeat” is visual. The Status Monitoring and the new Hex Buffers pulse in a synchronised rhythm. When the network is STABLE, everything glows a calm green. But the moment a threat is detected, the entire UI shifts into a high-visibility alert mode. It’s not just a dashboard; it’s an atmosphere.

  • Uptime Alert: If the uptime counter resets, Aurora Core was forced into a “sudo reboot” state. The massive System Resources panel will reflect this immediately with a fresh counter and updated metrics.

The Vibe

The goal was an interface pulled straight from a high-level operative’s monitor, the kind of UI you’d use to track global threats in real-time. It’s functional, heavy-duty, and every pixel serves a purpose. The Huge Temperature display and the A1B2::C3D4 hex buffers are there to remind you: this machine is alive and it’s working hard.

The Stack

I wanted a system that actually drops threats. Here’s the 24/7 stack protecting the perimeter:

  • Pi-hole: Stripping malicious DNS requests before they hit the wire.
  • CrowdSec & Suricata: Real-time IDS/IPS that detects and kills bad actors at the gate.
  • Netdata & NetAlertX: Full visibility over every node on the network.
  • Custom Data Engine: A complex layer of Bash and JQ that scrubs local data and prepares the interactive JSON packets.
  • Privacy: All external traffic is secured via a private VPN layer, keeping the internal architecture completely invisible to the outside world.

Layman’s TL;DR

1. What are the Hex Buffers in the header? That’s the system’s “Digital DNA.” The hex::hex codes are generated live. If they are pulsing green, the data integrity is 100%. If they turn red and pulse fast, the perimeter is under active pressure.

2. Why is the Threat Map interactive? In this version, the map is fully interactive, hovering over a country shows the threat count, and the layering has been fixed so it no longer clips through the header.

3. Why is the temperature so big? (Huge Metrics) Because heat is the enemy. An overclocked Pi 4 running this many security layers needs constant monitoring. If that number climbs too high, the system automatically adjusts. It’s the most critical hardware metric, so it gets the biggest font.

4. What is the Country Intel panel? This is a massive upgrade. It’s not just a list anymore. Click any country in the Intel panel to open a Country Intelligence Report. It reveals the top 3 attack scenarios used by that region and identifies the most active hostile IP originating from there. It’s deep-dive data at your fingertips.

5. Why is the clock ticking down from 30 seconds? (Next Sync) We cut the update cycle in half. Every 30 seconds, the UI performs a hard-sync with the server’s latest pre-scrubbed JSON packet. It ensures the “Last Sync” time is always fresh and the metrics are as close to real-time as web-mirroring allows.

6. What’s IP Analytics? Every hostile IP that triggers a block gets analyzed here. Click any IP to see its Intel Report: its risk level, origin, ASN (Autonomous System Number), and the specific network range it belongs to. It’s built for professional-grade threat hunting.

The Logic in a Nutshell: Aurora Core collects raw data, scrubs sensitive info, enriches it with country-specific intelligence, and pushes a safe JSON packet to the web server every 30 seconds. Your browser then renders this data with high-performance CSS and Google GeoCharts for a seamless, interactive experience.


Fun Facts (The Road to Perfection)

Country Intelligence Popups (10 hours): This was a nightmare. Instead of just showing names, I wanted a deep-dive modal. Getting jq to group CrowdSec alerts by country, then sub-group them by attack scenario, and then pick the top IP for each—all within a Bash script—nearly broke my brain. But now, when you click a country, you see exactly how they are trying to get in.

The 30s Sync Logic (4 hours): Transitioning from 60s to 30s meant I had to re-write the timing logic in both Bash and JavaScript. I spent hours debugging why the “Last Sync” would occasionally show a 1-second lag. Now it’s perfectly synchronized with the hardware’s update cycle.

The “Pretty” Hex Buffers (3 hours): I hated the old, long hex strings. They were too messy. I spent an entire evening refining the genHex function to produce the A1B2::C3D4 format. It’s clean, symmetrical, and fits the “NSA operative” aesthetic perfectly. It’s a small detail, but it makes the header look cool.

Map Layering & Transparency (5 hours): Google GeoCharts are notoriously difficult to style. I had a bug where the map would “bleed” through the box headers. Fixing the z-index and ensuring the background remained a pure, transparent-to-black gradient took way longer than I’m willing to admit.

Massive Metric Scaling (2 hours): Making the temperature look “huge” while keeping the Uptime, CPU, and RAM rows perfectly aligned required a complete overhaul of the CSS Flexbox logic. I wanted it to feel like a heavy-duty industrial gauge.

Total Time Investment: We are now well past the 1000+ hour (I think?) mark. Every version adds more complexity under the hood while trying to keep the UI “clean” and interactive. The sheer amount of pain involved in making a Raspberry Pi handle this much data is astronomical. Was it worth it? Just look at those pulsing hexes. Absolutely.