Files
oc-sentinel/docs/ocsentinel-architecture.md
OfficeCom Codex b5e06b885a
Some checks failed
OfficeCom Sentinel Client / build-client (push) Has been cancelled
Remove legacy AttackTracer repo content
2026-07-17 00:55:16 +02:00

801 B

OfficeCom Sentinel Architecture

Goal

OfficeCom Sentinel is a Windows endpoint client that:

  • runs on every monitored device
  • reads local attack telemetry and optional local vulnerability exports
  • writes NinjaOne device custom fields locally
  • uploads signed JSON reports to n8n
  • receives updates through NinjaOne tasks from Gitea-hosted releases

Current Model

The repository now keeps only the client-side architecture:

  • endpoint scan and correlation
  • local NinjaOne field publishing
  • optional n8n upload
  • packaged ZIP release flow for NinjaOne deployment

Removed Model

The following older pieces are intentionally no longer part of the repo:

  • share-based organization aggregation
  • dedicated server-side collector package
  • server-side NinjaOne organization field updater