AiSOC
AiSOC delivers an open-source AI Security Operations Center that unifies event ingestion, graph correlation, autonomous triage, and purple-team adversary emulation into a single self-hosted console. Security analysts triage alerts across an interactive Investigation Rail that visualizes six-event attack timelines, pivot-path entity graphs, and recommended containment steps. The underlying LangGraph agentic engine reasons over ingested telemetry, querying MITRE ATT&CK frameworks, CISA Known Exploited Vulnerabilities catalogs, and Shodan intelligence while recording every prompt, tool execution, and evidentiary citation in an immutable Investigation Ledger. Incident responders execute automated containment playbooks, including host network isolation, credential revocation in identity providers, and firewall blocklist updates with human-in-the-loop sign-offs. Threat hunters input plain-English hypotheses into the natural-language hunt workbench to generate and execute ES|QL, SPL, and KQL queries against historical telemetry stores. Platform operators connect over seventy vendor connectors spanning CrowdStrike, SentinelOne, Microsoft Defender, AWS Security Hub, Okta, and Cloudflare to normalize streaming events into Open Cybersecurity Schema Framework standards. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. MIT licensed.
Deploy