Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
-
Updated
Jul 20, 2026 - Python
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
Intelligent SOC automation framework powered by LangGraph multi-agent workflows for alert triage, correlation, and incident response
n8n workflow that pipes Wazuh SIEM alerts through Claude Haiku for AI triage. ~$0.001 per alert. Slack output with risk assessment + investigation commands.
SOC子引擎,基于agent-skills技术通过AI赋能SOC平台,对SOC告警进行研判、调查、响应。
ML-based SOC alert triage system using Random Forest to auto-classify alerts as True/False Positive — reducing analyst workload with real-time confidence scoring and live dashboard.
Hands-on cybersecurity portfolio featuring GRC, SOC/SIEM, Incident Response, and Automation projects. Includes risk assessments, Splunk log analysis, IR playbooks, and a full enterprise capstone case study.
AML triage prototype - This is a small Python prototype demonstrating how transaction monitoring alerts can be risk-scored and summarised for investigator review.
meerkat — SOC alert triage: ranks a daily review queue with MITRE ATT&CK context from Suricata, Wazuh and AMiner alerts.
SentinelForge: Autonomous SOC analyst platform with AI agents for alert triage, log correlation, threat hunting, and incident response.
Our reusable, modifiable prompts and simple agents that are included within the Arcanna platform and invokable via Arcanna's AI Assistant
Hands-on SOC Analyst lab portfolio — alert triage, reporting, escalation, and workbook-driven investigations (30-day project)
OpsPilot Discord-native AI on-call team that triages alerts, creates safe PRs, and manages incidents automatically.
SOC / DFIR investigations portfolio with hands-on lab cases covering SIEM alert triage, Phishing Analysis, Malware analysis, Endpoint detection, Network Analysis. Built to demonstrate practical SOC Analyst L1/L2 and DFIR skills.
Event-driven, read-only AI agent that triages AWS GuardDuty findings on Amazon Bedrock and forwards verdicts to your SIEM.
SOAR alert triage automation — n8n + 5 threat intel APIs, composite risk scoring, MITRE ATT&CK mapping. Auto-triages phishing and IP/URL alerts.
SOC alert investigations, SIEM practice labs, and incident analysis exercises completed on LetsDefend.
Leakage-safe, capacity-aware transaction fraud scoring: calibrated risk model, rule catalogue, anomaly layer, and cost-based alert prioritisation with drift monitoring.
Splunk-based TryHackMe write-up covering alert triage, brute-force analysis, scheduled task persistence, and web shell investigation.
SOC incident response simulation demonstrating alert triage, investigation steps, and incident documentation.
Add a description, image, and links to the alert-triage topic page so that developers can more easily learn about it.
To associate your repository with the alert-triage topic, visit your repo's landing page and select "manage topics."