AiSOC is an open-source AI-driven Security Operations Center platform designed to address the challenges of high alert volumes, fragmented context, and lack of auditability in security operations. It introduces an agentic workflow, where four named agents—Detect, Triage, Hunt, and Respond—collaborate to investigate incidents from start to finish. Each agent is responsible for a specific stage, with defined capabilities and a replayable audit trail that logs every prompt, tool call, and decision, ensuring transparency and accountability throughout the incident response process.
The platform supports a wide range of security integrations, offering 69 connectors across categories such as EDR, SIEM, cloud, IAM, SaaS, VCS, and network. Its detection engine utilizes 6,998 public YAML-based rules covering cloud, endpoint, identity, network, application, and data-exfiltration scenarios. The Detect agent fuses raw signals into incidents using techniques like entity-risk rollup and native detections, while Triage leverages large language models for automated prioritization and enrichment, supporting phishing, identity, cloud, and insider threat contexts. Hunt enables hypothesis-driven analysis using natural language queries converted to ES|QL, KQL, or SPL, and supports scheduled YAML-based hunts. Respond plans and executes containment and remediation actions, integrating with ChatOps platforms like Slack and Microsoft Teams for approval workflows, and features a maturity dial to control response automation.
AiSOC maintains a replayable incident ledger, allowing users to scrub timelines, examine rationales, and fork decisions into tickets. The platform is graph-native, writing entity relationships at ingest using Neo4j, and provides visual attack-chain timelines. It is built on an open-source stack, including LangGraph, Apache Kafka, Neo4j, PostgreSQL, Qdrant, and Ollama for local LLM support. io, Kubernetes, AWS, air-gapped environments, and more, with BYOK LLM credentials stored in an encrypted vault. The platform is MIT-licensed, emphasizing transparency and reproducibility, and includes a public detection corpus and reproducible benchmarks. AiSOC is suited for security teams seeking an auditable, agent-driven approach to incident detection, investigation, and response.
AiSOC is an AI security & guardrails project. It focuses on automating and streamlining security operations with agentic workflows and open-source deployment. AiSOC is an open-source project aimed at security analysts and IT teams. AiSOC is open source under the MIT license. AiSOC is available on the web and the command line, and it can be self-hosted.
It is developed by AiSOC, and it first shipped in 2026. Development happens publicly on GitHub with 1.4k stars and 458 commits in the last 90 days. Key capabilities include Agent-based SOC, self-hostable, and incident replay ledger. It exposes integrations via a public API.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do