Developer links
Agentic SOC Platform
Agentic SOC Platform compresses hours of manual security analysis into seconds by deploying specialized AI agents that autonomously triage, investigate, and enrich security alerts. The Python/Django backend processes SIEM webhooks through Redis Streams into a modular pipeline where LangGraph-orchestrated agents extract IOCs, correlate signals, and generate Cases with severity, confidence, impact, priority, and structured verdicts. The built-in SIRP provides full case management with Alerts, Artifacts, Enrichments, Tickets, and a Knowledge base that accumulates institutional memory for both human analysts and LLM agents. Native Splunk and Elasticsearch/Kibana integrations deliver unified log search through a standardized interface so agents and analysts share identical security context. The playbook engine combines traditional SOAR automation with AI-powered investigation — launching threat hunting agents, knowledge extraction, threat intelligence enrichment, and CMDB lookups from a single orchestration layer. MCP Plugin support exposes ASP capabilities to Claude Code, Codex, and OpenCode, enabling external AI agents to operate cases, search logs, query threat intelligence, and write custom modules directly. Python Modules adapt new alert sources while Playbooks orchestrate LLM analysis and automated response actions, scaling the platform with your security scenarios. Deploy via Docker Compose with all data staying inside your network. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Benefits
- AI-Powered Automated Alert Triage
- LangGraph-orchestrated agents compress hours of manual security analysis into seconds, automatically producing severity, confidence, impact, priority scores, and structured investigation reports for every incoming alert.
- Built-In Incident Response Platform
- Complete SIRP with Cases, Alerts, Artifacts, Enrichments, Tickets, and Knowledge objects providing end-to-end case management without requiring external SOAR or ticketing tool integrations.
- Native SIEM Dual-Stack Integration
- Direct Splunk and Elasticsearch/Kibana connectors with unified log retrieval API ensure LLM agents, playbooks, and human analysts all query from identical security data context.
- Extensible Module and Playbook System
- Python-based Modules adapt new alert sources and SIEM rules while LangGraph Playbooks orchestrate AI investigation, threat hunting, and automated remediation actions in a single pipeline.
Features
- LangGraph Agent Orchestration
- Specialized AI agents for SIEM search, knowledge extraction, and threat intelligence enrichment collaborate through LangGraph pipelines with configurable system prompts.
- Redis Streams Pipeline
- Webhook-ingested alerts flow through Redis Streams into per-type processing queues where modules extract IOCs, correlate signals, and generate structured cases.
- MCP Plugin Ecosystem
- Model Context Protocol integration exposes platform capabilities to Claude Code, Codex, and OpenCode for external agent-driven case operations and log queries.
- Threat Intelligence Enrichment
- Automatic IOC and Artifact enrichment with reputation data, threat pulses, asset context, identity mapping, and historical incident correlation for evidence-based verdicts.
- Knowledge Accumulation Layer
- Qdrant vector store maintains high-timeliness shared knowledge accessible to both human analysts and LLM agents for cross-case institutional memory.