About this project
AiSOC is an open-source, self-hostable AI Security Operations Center designed to ingest security telemetry, normalize it, and run a large library of executable detection rules. It groups triggered rules into alerts and incidents, then uses AI agents to investigate with fully logged prompts, tool calls, citations, verdicts, and token costs in an Investigation Ledger. Responses require human approval, and the system is designed to avoid silent fallback to synthetic data.
The project ships with a local LLM through Ollama, so the core deployment can produce real triage verdicts without external API keys. It also includes the CISA Known Exploited Vulnerabilities feed as a real external threat intelligence source. Deployment profiles range from a core alerting pipeline to a full profile with event lake, entity graph, full-text search, and enrichment.
AiSOC supports both push-based ingestion through an API and pull-based connectors for tools such as Splunk, Microsoft Sentinel, Elastic, CrowdStrike, Okta, AWS, Wiz, and Kubernetes audit logs. It provides a REST API, web console, and an MCP server for Claude, Cursor, and Continue. The repository emphasizes honest reporting of real versus synthetic data, executable rule verification, and security practices such as per-deployment secrets, encrypted connector credentials, RBAC, and fail-closed services.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.