I've been working on an open-source project called darklab_shell, and it's finally at the point where I'd like to get some feedback from people outside of my own bubble.
The original idea was pretty simple: I wanted a web-based interface where I could quickly run common network diagnostic and security tools. Especially from enterprise and/or corporate environments where internal machines do not have direct internet access and outbound SSH is discouraged or blocked.
It has grown quite a bit from there.
darklab_shell now provides a browser-based interface for running network/security tools, with things like saved runs and history, file handling, findings/triage, secrets, notifications, and other features built around the basic workflow.
It's designed to be self-hosted and runs in Docker.
Live instance:
https://shell.darklab.sh
Source:
https://gitlab.com/darklab.sh/darklab_shell
One of my goals has been to keep the interface useful for someone who knows the underlying tools without trying to completely hide what's happening behind the scenes. I don't want it to become a giant enterprise vulnerability-management platform. It's meant to be a practical toolbox that I can deploy and use when I need it.
I'm at the point now where I've spent enough time looking at it that I know I'm going to miss things that will be obvious to someone seeing it for the first time.
I'd especially appreciate feedback around:
- Whether the UI/workflow makes sense without already knowing how the project works
- Installation and self-hosting experience
- Tools or workflows that seem obviously missing
- Security concerns or questionable design decisions
- Things that feel unnecessarily complicated
- Features that seem useful vs. features that are just adding clutter
I'm also very interested in hearing how people would actually use something like this. Some of the best features so far have come from scratching my own itch, but that also means the project is naturally biased toward my particular workflow.
Feel free to be critical. At this stage, finding the things I've designed poorly is more useful to me than hearing that everything looks good.
It's open source, so PRs/issues are welcome too.
https://www.reddit.com/gallery/1wply3x
Source: r/selfhosted · by /u/mmayhew
