// backend/routes/dashboard/threatsHelper.js // ───────────────────────────────────────────────────────────────────────────── // Intelligence data mapping helpers for threats routes // ───────────────────────────────────────────────────────────────────────────── const { getTimeFilter, getBaseFilter } = require('./helpers'); const { generateMacFromIp } = require('../../deviceResolver'); async function getIntelData(Threat, req, threatTypeRegex = null, limit = 0) { const timeFilter = getTimeFilter(req); const query = getBaseFilter(req, timeFilter); if (threatTypeRegex) { query.threat_type = { $regex: threatTypeRegex, $options: 'i' }; } let dbQuery = Threat.find(query).sort({ detected_at: -1, timestamp: -1 }); if (limit > 0) dbQuery = dbQuery.limit(limit); const list = await dbQuery.lean(); return list.map((t) => { const ip = t.ip_address || t.src_ip || t.dst_ip || '0.0.0.0'; const mac = t.mac_address || t.src_mac || generateMacFromIp(ip); const eTime = t.detected_at || t.timestamp?.toISOString() || new Date().toISOString(); return { id: t._id?.toString(), detected_at: eTime, ip_address: ip, mac_address: mac, pool_host: t.domain || null, pool_ip: t.dst_ip || null, protocol: t.protocol || 'TCP', app_label: t.app_label || 'Unknown', confidence: t.severity === 'Critical' ? 99 : (t.severity === 'High' ? 90 : 75), download: t.download || 0, upload: t.upload || 0, exit_node: t.dst_ip || null, circuit_id: t.flow_id || null, country: 'Unknown', vpn_type: t.app_label || 'Unknown VPN', remote_ip: t.dst_ip || null, device_label: ip, device_type: 'Unknown', os_label: 'Unknown', manufacturer: 'Unknown', risk_level: t.severity || 'Medium', risk: t.severity || 'Medium', reputation: t.threat_type || 'Malicious IP', severity: t.severity || 'Warning' }; }); } function mapThreatData(threats) { return threats.map((t) => { return { id: t._id?.toString(), threat_type: t.threat_type || 'Unknown Threat', severity: t.severity || 'Medium', ip_address: t.src_ip || t.ip_address || null, dst_ip: t.dst_ip || null, mac_address: t.src_mac || t.mac_address || null, app_label: t.app_label || t.protocol || null, domain: t.domain || t.dst_ip || null, detected_at: t.detected_at || t.event_at || t.timestamp?.toISOString() || new Date().toISOString(), description: t.description || null }; }); } module.exports = { getIntelData, mapThreatData };