Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
-
Updated
Jul 20, 2026 - Python
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud
Open-source framework to detect outliers in Elasticsearch events
Write detections, investigate alerts, and query logs from your favorite AI agents
基于Agent驱动的网络安全流量监控与分析平台,下一代AI驱动的安全运营协作平台 — 智能告警研判、资产关联、协同处置与自动化报告生成,为护网行动增添一把利器。
Elastic TIP is a python tool which automates the process of aggregating Threat Intelligence and ingesting the intelligence into a common format into Elasticsearch with the main goal of being used by the Security solution.
Intelligent SOC automation framework powered by LangGraph multi-agent workflows for alert triage, correlation, and incident response
AI-powered daily security digest with persona-based insights. Automatically delivers CVEs, security news & AI regulations to Notion. 100% free & open source.
Network device vendor analysis tool - Transform MAC address tables into interactive dashboards, detect new vendors, and export SIEM events for security monitoring. Supports Cisco, Juniper, HP/Aruba, Extreme, Brocade and more.
SOC子引擎,基于agent-skills技术通过AI赋能SOC平台,对SOC告警进行研判、调查、响应。
PS Banshee is a command-line interface (CLI) tool designed to provide quick and efficient access to Recorded Future Intelligence. Built for security professionals, PS Banshee helps streamline investigations and automate common security operations tasks.
Enterprise SOC Platform for Detection Engineering, IAM Governance, SOAR Automation, UEBA, Threat Intelligence, Compliance Auditing and Hybrid Infrastructure Security Monitoring.
Visual analytics using Databricks & Graphistry for cybersecurity investigations
Unified AI Security Operations Platform - OSINT Investigator, Zero-Day Monitor and SIEM Assistant powered by Claude AI
Sovereign AI SOC: local-first AI security operations with Wazuh, Suricata, correlation-first incidents, case management and human-in-the-loop AI.
A portfolio of completed rooms, challenges, and CTFs from TryHackMe.com, showcasing hands-on experience with real-world cybersecurity scenarios — from hacking machines to investigating attacks. This collection highlights my practical skills across diverse technologies, reflecting my growth and learning through various cybersecurity learning paths.
This project focuses on building an AI-driven anomaly detection framework that uses the Isolation Forest algorithm to identify suspicious events in unstructured system log data.
Parallax — a self-hosted toolkit for SentinelOne AI-SIEM engineers: map parser & detection-library coverage, visualize MITRE ATT&CK gaps, and validate that detection rules actually fire by generating synthetic test logs from each rule's own logic and verifying the resulting alerts.
Robust fuzzy parser and normalization toolkit for LLM-based SOC log evaluation
AI-powered SOC triage assistant. RAG-driven investigations across Wazuh, LimaCharlie, Splunk, Elastic, and Sentinel — with Claude Agent SDK, cloud APIs, or fully local Ollama. Open source, Apache 2.0.
Add a description, image, and links to the security-operations topic page so that developers can more easily learn about it.
To associate your repository with the security-operations topic, visit your repo's landing page and select "manage topics."