AiSOC
View on GitHubOpen-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue.
Self-hosted security operations platform that ingests telemetry, detects and correlates threats, and uses auditable AI agents to triage alerts and investigate incidents. Includes local Ollama inference and an MCP server; response actions require human approval.
Use Cases
Triage security alerts with an AI agentInvestigate incidents using correlated alerts and entity contextQuery event lakes and entity graphs through typed agent toolsRecord agent prompts, tool calls, citations, and verdicts in an investigation ledgerPropose security response actions for human approvalConnect security telemetry sources and correlate detections
Built With
- Language
- Python
- Frameworks
- LangGraph · Ollama
Tags
AI security · SOC · security operations · alert triage · incident investigation · MITRE ATT&CK · human approval · auditable agents · threat detection · self-hosted · MCP · SIEM