Disclosure
Built inside a telco security division. This case study covers architecture and engineering decisions only: no real hostnames, addresses, topology or asset data appears anywhere on this page. Interface visuals are reconstructions using fabricated demonstration data.
Less manual effort
Hours, down from 93.17
Months, concept to production
Engineer
CYFER ONE (known internally as Tangkap) is a platform built for U Mobile that discovers what is actually running on the network, consolidates months of scan results into one authoritative asset view, and gives the security team the evidence they need to make segmentation decisions. Built end to end during a five-month industrial placement and presented to the CIO.
The problem
Server inventory lived in spreadsheets that went stale the moment they were saved. Scans produced raw output nobody had time to reconcile, so the question "what is on this segment, and should it be?" took days to answer and the answer was never quite trusted. Without a dependable inventory, segmentation work stalls: you cannot draw a boundary around assets you have not confidently enumerated. Compliance reporting had the same root problem, and was assembled by hand each cycle.
What I built
CYFER ONE automates the whole loop. Discovery accepts more than one way in: a live SSH/Nmap sweep, an Nmap XML file, an Excel import, or a single manual entry. All four converge on the same enrichment and consolidation pipeline. A Python worker runs Nmap over SSH against defined scopes and streams results back as JSON events; a Node.js orchestration layer supervises those runs with heartbeats and process-liveness checks so a hung scan surfaces as a failure instead of silence. Results land in a temporal PostgreSQL model that keeps every monthly snapshot while projecting a single current-state asset view, so you can ask both "what is there now" and "what changed since last month". New assets resolve and register themselves against the Master Assets database automatically; anything the system can’t confidently place waits in a Verify Queue instead of stalling everyone behind it. On top sits role-based access scoped by division, a tick-based scheduler running the pipeline on cron, scheduled Excel compliance reports published straight to SharePoint, and an AI assistant that answers natural-language questions by querying the live database through tool-calling.
How it works
Scanning engine
A Python worker drives Nmap over SSH via Paramiko against explicitly defined scopes. Rather than waiting for a scan to finish and parsing a file, the worker emits newline-delimited JSON events as hosts resolve, so the UI shows progress in real time and a long sweep never looks frozen.
Liveness and failure surfacing
Long-running scans fail in quiet ways: a dropped SSH session looks identical to a slow subnet. The Node.js supervisor tracks heartbeats and process liveness, so a stalled worker is reported as a failed run with a reason instead of hanging indefinitely.
Temporal data model
Scan results are stored as immutable monthly snapshots in PostgreSQL through Prisma, with a derived current-state view layered on top. Overwriting would have been simpler, but it destroys the audit trail, and "when did this host appear" is exactly the question segmentation work depends on.
Verification as a queue, not a gate
Verification was first designed as a hard gate: nothing reaches the registry until a human confirms it. In practice that queue became the bottleneck it was meant to prevent, so it was redesigned: new IPs auto-resolve division, location, system and device type and register immediately, while anything the system can’t confidently place waits in a Verify Queue instead of blocking everyone behind it. A hostname that collides with an already-registered asset is flagged and held out of every export until a person untangles it.
Authentication and division-scoped RBAC
NextAuth with bcrypt password hashing, JWT sessions and TOTP-based MFA. Authorisation is scoped by division, so a user sees only the assets their team owns, which matters for a tool that inventories infrastructure across an organisation.
Scheduling that survives being ignored
Jobs are cron-defined but evaluated on a recurring tick against next-run times stored in the database, rather than registered as in-process cron. A fire is never doubled, and a run missed by a restart at the wrong moment still happens once it’s noticed, inside a configurable grace window. Automation itself runs as ordered stages (scan, consolidate, reconcile, publish) with the stage set varying by job type, and every run persists its status and error so a failure is something you look up rather than infer from silence.
Automated compliance reporting
A cron-scheduled job generates Excel compliance workbooks and publishes them to SharePoint through the Microsoft Graph API, replacing a manual assembly step that recurred every reporting cycle.
AI assistant with tool-calling
An assistant layer exposes read-only database queries as tools to an LLM (Gemini and Anthropic), letting the team ask questions in natural language and get answers computed against live data rather than against the model’s guess.
3D topology view
An interactive Three.js visualisation of network topology, built so segment relationships could be read at a glance in a review meeting instead of traced through a table.
What it does
Authentication & access
- Local email/password sign-in against a bcrypt hash, with no external identity provider
- Mandatory TOTP MFA, enrolled by QR code, enforced at every login for MFA-enabled accounts
- Configurable password policy (minimum length, case, number, symbol) with expiry and a forced change on first login
- Account lockout after repeated failed attempts; administrators can invalidate a user’s active sessions on demand
- Guest, user and admin roles, every one scoped to a division for both reads and writes
Discovery & import
- Batch SSH → Nmap scans over operator-defined CIDR ranges with a selectable timing template
- Nmap XML import, Excel import and single manual entry: four intake paths that all converge on the same enrichment and consolidation pipeline
- Scans stream progress live, can be paused and resumed without losing state, and recover automatically from a dropped SSH session
Consolidation & the registry
- Every discovered host is deduplicated to one record per IP per month and enriched against subnet and server reference data
- New IPs auto-resolve division, location, system and device type and register into the Master Assets database on their own
- Anything the system can’t confidently resolve waits in a Verify Queue instead of blocking the pipeline behind it
- A hostname already registered under a different asset is flagged and held out of every export until a person reconciles it
- A read-only diff report compares the external asset-master spreadsheet against the database: added, removed, modified
Reporting, dashboards & AI
- A configurable dashboard, with draggable and resizable widgets, covering host totals, month-over-month trend, division and subnet breakdowns, and port/vulnerability alerts
- Full-text search across IPs, hostnames and systems
- A library of generated reports (monthly summary, asset discovery, full Master Assets, IP history) plus a delta feed built for Power BI
- A read-only AI assistant that answers questions by calling tools against the live database, not by guessing
Scheduling & automation
- Administrators define cron-based jobs; a tick-based scheduler evaluates and runs whatever’s due without double-firing
- A run missed by a restart at the wrong moment still fires once, inside a configurable grace window
- Automation runs as ordered stages (scan, consolidate, reconcile, publish) with the stage set varying by job type
- Every run persists its status and error, so a failure is something you look up, not infer from silence
Integrations & notifications
- SharePoint publishing over an application-only Microsoft Graph connection, with fixed filenames and timestamped backups so Power BI bindings never break
- Automatic retry with backoff when SharePoint returns a lock conflict
- Optional Microsoft Teams and email delivery, alongside in-app alerts for verification, pending, flagged and new-asset events
Outcome
The monthly discovery cycle went from 93.17 hours of manual work (SSH sessions, a 90-hour scan, then hours of Excel reconciliation) to 8.9 hours end to end, a 91% reduction. Enrichment, reconciliation, registration and publishing each dropped to under five minutes, and the InfoSec team adopted the system for daily and ad-hoc use. Compliance reports that were assembled by hand now generate and publish on a cron schedule. Delivered to production and presented to the CIO at the close of the placement.
Stack
← No previous
