Overview
AWD-Watchdog is built for authorized Attack-Defense CTF environments where teams need fast visibility into who is hitting their box, which endpoint is under pressure, and whether service changes or outages need immediate action.
Problem
In AWD rounds, teams often split attention between patching, checking service health, watching logs, and collecting evidence. This toolkit pulls those signals into one defensive workflow so decisions can happen faster.
Workflow
- Collect network, web, and host signals from the challenge box.
- Classify activity such as SQL injection, command injection, traversal, upload abuse, or debug probing.
- Surface attacker IPs, target endpoints, and file-change evidence in the terminal dashboard.
- Use the alert context to patch, restart services, verify checkers, and improve rules.
Future improvements
- Add richer web dashboard views for long-running competitions.
- Export evidence into SIEM-friendly formats.
- Expand competition playbooks and custom rule packs.
- Harden service deployment profiles for repeat team use.