Open-source SIEM pipeline: raw security logs → OCSF → correlation rules → alerts. OT and IT in one pipeline. Local-first AI triage, 10-minute self-hosted quickstart.
-
Updated
Oct 3, 2026 - Python
Open-source SIEM pipeline: raw security logs → OCSF → correlation rules → alerts. OT and IT in one pipeline. Local-first AI triage, 10-minute self-hosted quickstart.
Console-IR. OCSF-native incident response and investigation TUI for the terminal. Triage findings, pivot on indicators, investigate hosts and accounts, GeoIP and WHOIS enrichment, case management, write the report. Single Go binary, SQLite, no server. Open Cybersecurity Schema Framework security tooling for SOC analysts and DFIR.
To associate your repository with the ocsf-native topic, visit your repo's landing page and select "manage topics."