Files
Deep-Package-Inspection/scratch/check_domain_apps.js
T
vanne 26179a0270 feat: device detail drill-down modal + smart domain/app display
- Add DeviceDetailModal with 8 tabs (Info, Flows, Apps, Encryption,
  Servers, Password Leaks, IP Reputation, VPN & Events)
- Make device cards in AgentDetailModal clickable (nested modal drill-down)
- Expand fetchDeviceDetails backend to query all 10 correlated tables
  (devices, flows, intel_device_discovery, intel_encryption_audit,
   intel_server_discovery, intel_unencrypted_passwords, intel_ip_reputation,
   intel_vpn_detection, events, mac_bandwidth)
- Smart combined app/domain display: prioritize actual domain names over
  port-only labels (Port 443 -> scontent.fcgk42-1.fna.fbcdn.net)
- Update Flows tab: domain shown in teal monospace, protocols in purple,
  port-only entries muted
- Add 10 new TypeScript interfaces for device detail data types
- Add MAC address fallback queries (by MAC when IP yields no results)
- Fix fmtBytes for very large values
2026-06-30 23:58:04 +07:00

39 lines
1.6 KiB
JavaScript

const db = require('../backend/database').getDB();
// Check all flows - how many have domain vs just port
const stats = db.prepare(`
SELECT
COUNT(*) as total,
SUM(CASE WHEN domain IS NOT NULL THEN 1 ELSE 0 END) as with_domain,
SUM(CASE WHEN app_label IS NOT NULL AND app_label NOT LIKE 'Port %' THEN 1 ELSE 0 END) as named_app,
SUM(CASE WHEN app_label LIKE 'Port %' THEN 1 ELSE 0 END) as port_only,
SUM(CASE WHEN app_label IS NULL AND domain IS NULL THEN 1 ELSE 0 END) as both_null
FROM flows
`).get();
console.log('Flow stats:', stats);
// What are the unique domain values?
const uniqueDomains = db.prepare(`SELECT DISTINCT domain FROM flows WHERE domain IS NOT NULL LIMIT 20`).all();
console.log('\nUnique domains in DB:', uniqueDomains.length);
uniqueDomains.forEach(r => console.log(' ', r.domain));
// What devices have domain data, and how many?
console.log('\n\nDevices with domain+app data:');
const devDomains = db.prepare(`
SELECT src_ip, src_mac,
COUNT(*) total_flows,
SUM(CASE WHEN domain IS NOT NULL THEN 1 ELSE 0 END) domain_flows,
SUM(CASE WHEN app_label IS NOT NULL AND app_label NOT LIKE 'Port %' THEN 1 ELSE 0 END) named_flows,
GROUP_CONCAT(DISTINCT domain) sample_domains
FROM flows
WHERE domain IS NOT NULL OR (app_label IS NOT NULL AND app_label NOT LIKE 'Port %')
GROUP BY src_ip
ORDER BY domain_flows DESC
LIMIT 10
`).all();
devDomains.forEach(r => {
const {sample_domains, ...rest} = r;
console.log(JSON.stringify(rest));
if (sample_domains) console.log(' domains:', sample_domains.split(',').slice(0,3).join(', '));
});