Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
-
Updated
Sep 7, 2026 - Python
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
Intelligent SOC automation framework powered by LangGraph multi-agent workflows for alert triage, correlation, and incident response
EFF-Assistant是一款面向安全运营场景的浏览器插件,让现有 WAF、NDR、SOC 等安全设备快速具备告警解析、AI 研判、资产关联与工单联动能力。
n8n workflow that pipes Wazuh SIEM alerts through Claude Haiku for AI triage. ~$0.001 per alert. Slack output with risk assessment + investigation commands.
SOC子引擎,基于agent-skills技术通过AI赋能SOC平台,对SOC告警进行研判、调查、响应。
Hands-on cybersecurity portfolio featuring GRC, SOC/SIEM, Incident Response, and Automation projects. Includes risk assessments, Splunk log analysis, IR playbooks, and a full enterprise capstone case study.
Real-data SOC alert triage engine & training package. Multi-format log parser, attack-chain correlation, FP heuristics & MITRE mapping — pure Python stdlib, zero dependencies.
ML-based SOC alert triage system using Random Forest to auto-classify alerts as True/False Positive — reducing analyst workload with real-time confidence scoring and live dashboard.
meerkat — SOC alert triage: ranks a daily review queue with MITRE ATT&CK context from Suricata, Wazuh and AMiner alerts.
SentinelForge: Autonomous SOC analyst platform with AI agents for alert triage, log correlation, threat hunting, and incident response.
30+ projects AWS SOC/SOAR Ecosystem portfolio with Wazuh, TheHive, Cortex, MISP, n8n, network security monitoring, Threat Detection & Hunting, Alert triage, Log Analysis, Detection engineering, Incident Response, dashboards, and AI security automation.
LLM-powered, ATT&CK-grounded security log triage with RAG — turn an alert flood into a short list of explained, prioritized incidents.
AML triage prototype - This is a small Python prototype demonstrating how transaction monitoring alerts can be risk-scored and summarised for investigator review.
AI-powered Security Operations (SOC) system that automates L1 alert triage, threat enrichment, and incident response.
Our reusable, modifiable prompts and simple agents that are included within the Arcanna platform and invokable via Arcanna's AI Assistant
AI-powered SOC alert triage dashboard built with Streamlit & scikit-learn – enhances Microsoft's Modern Security Operations by prioritizing alerts with ML to reduce analyst fatigue.
A local-LLM SOC analyst: an L1 agent (Gemma via Ollama) triages overnight SIEM alerts, learns benign patterns, and escalates only what it cannot resolve to an L2 (Claude) review. Runs on-box, free.
OpsPilot Discord-native AI on-call team that triages alerts, creates safe PRs, and manages incidents automatically.
Hands-on SOC case study covering malware alert triage, malware behavior analysis, incident response execution, IOC creation, and security control improvement using MITRE ATT&CK.
To associate your repository with the alert-triage topic, visit your repo's landing page and select "manage topics."