Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
-
Updated
Aug 17, 2026 - Python
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
Intelligent SOC automation framework powered by LangGraph multi-agent workflows for alert triage, correlation, and incident response
EFF-Assistant是一款面向安全运营场景的浏览器插件,让现有 WAF、NDR、SOC 等安全设备快速具备告警解析、AI 研判、资产关联与工单联动能力。
n8n workflow that pipes Wazuh SIEM alerts through Claude Haiku for AI triage. ~$0.001 per alert. Slack output with risk assessment + investigation commands.
SOC子引擎,基于agent-skills技术通过AI赋能SOC平台,对SOC告警进行研判、调查、响应。
Hands-on cybersecurity portfolio featuring GRC, SOC/SIEM, Incident Response, and Automation projects. Includes risk assessments, Splunk log analysis, IR playbooks, and a full enterprise capstone case study.
ML-based SOC alert triage system using Random Forest to auto-classify alerts as True/False Positive — reducing analyst workload with real-time confidence scoring and live dashboard.
meerkat — SOC alert triage: ranks a daily review queue with MITRE ATT&CK context from Suricata, Wazuh and AMiner alerts.
SentinelForge: Autonomous SOC analyst platform with AI agents for alert triage, log correlation, threat hunting, and incident response.
30+ projects AWS SOC/SOAR Ecosystem portfolio with Wazuh, TheHive, Cortex, MISP, n8n, network security monitoring, Threat Detection & Hunting, Alert triage, Log Analysis, Detection engineering, Incident Response, dashboards, and AI security automation.
Real-data SOC alert triage engine & training package. Multi-format log parser, attack-chain correlation, FP heuristics & MITRE mapping — pure Python stdlib, zero dependencies.
AML triage prototype - This is a small Python prototype demonstrating how transaction monitoring alerts can be risk-scored and summarised for investigator review.
AI-powered Security Operations (SOC) system that automates L1 alert triage, threat enrichment, and incident response.
OpsPilot Discord-native AI on-call team that triages alerts, creates safe PRs, and manages incidents automatically.
A local-LLM SOC analyst: an L1 agent (Gemma via Ollama) triages overnight SIEM alerts, learns benign patterns, and escalates only what it cannot resolve to an L2 (Claude) review. Runs on-box, free.
Our reusable, modifiable prompts and simple agents that are included within the Arcanna platform and invokable via Arcanna's AI Assistant
Hands-on SOC alert triage investigation simulating a real-world Blue Team incident response workflow using evidence correlation, analyst decision-making, incident documentation, and containment recommendations.
Hands-on SOC Analyst lab portfolio — alert triage, reporting, escalation, and workbook-driven investigations (30-day project)
SOC / DFIR investigations portfolio with hands-on lab cases covering SIEM alert triage, Phishing Analysis, Malware analysis, Endpoint detection, Network Analysis. Built to demonstrate practical SOC Analyst L1/L2 and DFIR skills.
Add a description, image, and links to the alert-triage topic page so that developers can more easily learn about it.
To associate your repository with the alert-triage topic, visit your repo's landing page and select "manage topics."