About this project
A governed threat-hunting platform transforming security telemetry into ATT&CK-aligned hypotheses, detection plans, and SIEM-ready workflows. Features include LLM-based query generation (Qwen3-8B), MITRE ATT&CK integration, Sigma rule validation, and Splunk SIEM compatibility. The architecture emphasizes deterministic components for telemetry grounding, detection eligibility, and ML triage. Contains 540 validated Sigma rules, 697 ATT&CK techniques evaluated, and 1,145 canonical records. Intended for SOC teams to automate threat detection with AI-driven workflows.
Comments
0 Rating appears after 10 ratings
Sign in to join the discussion.