Ross ROSS = Recommend OSS · open-source software intelligence for agents

beenuar/AiSOC

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable. observed · 2026-08-28

github.com/beenuar/AiSOC · homepage · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

80/100

  • Activity 99
  • Release rhythm 96
  • Longevity 8

Flags: young

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 8.0
  • age_days: 123
  • days_rel: 30
  • days_push: 9
  • n_releases_24m: 9

Full methodology

Adoption not part of the score

2408 stars · 254 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

AiSOC is an open-source, self-hostable AI-powered Security Operations Center that fuses alerts, performs agent-assisted triage, purple-team drills, and MITRE ATT&CK-aligned investigations with replayable agent traces. It includes a deterministic triage CLI, 70+ data connectors for SIEM/EDR/cloud/identity sources, and is MIT-licensed.

Use cases

  • triage security alerts with AI agents
  • fuse and correlate alerts from SIEM and EDR
  • investigate incidents mapped to MITRE ATT&CK
  • run purple-team detection drills
  • score alert batches to escalate/review/suppress verdicts
  • self-host a SOC platform with replayable agent audit trails
  • hunt threats with plain-language queries across connected sources

When to choose

  • you want an open-source, self-hostable alternative to commercial SIEM/SOAR triage
  • your team needs agent-assisted alert triage with auditable, replayable reasoning
  • you need integrations across Splunk, Sentinel, CrowdStrike, Defender, and cloud logs
  • you want a deterministic CLI triage scorer without LLM keys

When to avoid

  • you need a fully managed multi-tenant MSSP platform with SLAs and compliance reports
  • you require guaranteed vendor support and SOC 2/ISO attestations from the open-source edition
  • your environment cannot run Python/ClickHouse/Neo4j self-hosted components

Facets

application · maturity active

security monitoring alerting agent-framework search-engine analytics self-hosted cli security artificial-intelligence monitoring developer-tools self-hosted python cli cross-platform soc siem soar alert-triage incident-response mitre-attack purple-team threat-intelligence detection-engineering agentic-ai clickhouse neo4j langgraph ai-agents docker web-server

5 sources

Member repositories

RepositoryRoleHealth v2
beenuar/AiSOCmain80

For agents

markdown · JSON · MCP: product_card(name="beenuar/AiSOC")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem