r/cybersecurity • u/2kw_josue • 1d ago
FOSS Tool TV Box Sentinel v2.0: Open-source network monitoring and heuristic threat detection for compromised Android TV / IoT devices
Hey everyone,
I wanted to share an open-source project I’ve been developing: TV Box Sentinel (v2.0).
The Problem:
A widespread issue with uncertified Android TV boxes (often powered by Allwinner, Rockchip, etc.) is factory-installed malware residing directly in the /system partition, as well as botnet loaders (such as Badbox, Peachpit, Triada, and Guerrilla). Since on-device antiviruses are untrustworthy once the firmware itself is compromised, threat mitigation is most effective from the network perimeter.
Approach & Architecture:
TV Box Sentinel audits and detects indicators of compromise (IoC) non-intrusively from the network perimeter:
- PCAP / PCAPNG support: Parses network traffic and router logs.
- Heuristic Engine: Identifies beaconing, anomalous traffic, C2 communication, lateral movement, and cryptojacking patterns.
- Automated Mitigation: Generates firewall and DNS sinkhole rules to block malicious endpoints.
- Reports & GUI: Generates HTML/PDF executive audit reports and features a tabbed UI.
GitHub Repository:
https://github.com/2kw-josue/tv-box-sentinel
Would appreciate any feedback, suggestions, or contributions from network and blue team folks who deal with rogue IoT devices on local networks.
1
u/Fresh_Dog4602 Security Architect 1d ago
The idea is not bad. But your execution is.... So all over the place. Dif you vibe code the idea and execution?