diff --git a/package/secubox/secubox-app-mitmproxy/README.md b/package/secubox/secubox-app-mitmproxy/README.md new file mode 100644 index 00000000..ccb048ba --- /dev/null +++ b/package/secubox/secubox-app-mitmproxy/README.md @@ -0,0 +1,81 @@ +# SecuBox mitmproxy App + +LXC container with mitmproxy for HTTPS traffic inspection and threat detection. + +## Components + +| Component | Description | +|-----------|-------------| +| **LXC Container** | Debian-based container with mitmproxy | +| **secubox_analytics.py** | Threat detection addon for mitmproxy | +| **haproxy_router.py** | HAProxy backend routing addon | +| **CrowdSec Integration** | Threat logging for automatic IP banning | + +## Threat Detection Patterns + +### Attack Types Detected + +| Category | Patterns | +|----------|----------| +| **SQL Injection** | UNION SELECT, OR 1=1, SLEEP(), BENCHMARK() | +| **XSS** | `