beenuar/AiSOC
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable. observed · 2026-08-28
Health v2 · maintenance only
80/100
- Activity 99
- Release rhythm 96
- Longevity 8
Flags: young
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 8.0
- age_days: 123
- days_rel: 30
- days_push: 9
- n_releases_24m: 9
Adoption not part of the score
2408 stars · 254 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
AiSOC is an open-source, self-hostable AI-powered Security Operations Center that fuses alerts, performs agent-assisted triage, purple-team drills, and MITRE ATT&CK-aligned investigations with replayable agent traces. It includes a deterministic triage CLI, 70+ data connectors for SIEM/EDR/cloud/identity sources, and is MIT-licensed.
Use cases
- triage security alerts with AI agents
- fuse and correlate alerts from SIEM and EDR
- investigate incidents mapped to MITRE ATT&CK
- run purple-team detection drills
- score alert batches to escalate/review/suppress verdicts
- self-host a SOC platform with replayable agent audit trails
- hunt threats with plain-language queries across connected sources
When to choose
- you want an open-source, self-hostable alternative to commercial SIEM/SOAR triage
- your team needs agent-assisted alert triage with auditable, replayable reasoning
- you need integrations across Splunk, Sentinel, CrowdStrike, Defender, and cloud logs
- you want a deterministic CLI triage scorer without LLM keys
When to avoid
- you need a fully managed multi-tenant MSSP platform with SLAs and compliance reports
- you require guaranteed vendor support and SOC 2/ISO attestations from the open-source edition
- your environment cannot run Python/ClickHouse/Neo4j self-hosted components
Facets
application · maturity active
security monitoring alerting agent-framework search-engine analytics self-hosted cli security artificial-intelligence monitoring developer-tools self-hosted python cli cross-platform soc siem soar alert-triage incident-response mitre-attack purple-team threat-intelligence detection-engineering agentic-ai clickhouse neo4j langgraph ai-agents docker web-server
5 sources
- readme: https://github.com/beenuar/AiSOC · fetched 2026-08-28 · a50bf438ee13
- homepage: https://tryaisoc.com · fetched 2026-08-29 · 1cd5494290b0
- site_page: https://tryaisoc.com/about · fetched 2026-08-29 · 65114b0ae1ad
- site_page: https://tryaisoc.com/integrations · fetched 2026-08-29 · 91d9f06cddeb
- site_page: https://tryaisoc.com/pricing · fetched 2026-08-29 · 954eacc80e8a
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| beenuar/AiSOC | main | 80 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem