
A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based behavioral memory, and validates real-time anomalies using LLMs.
A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based behavioral memory, and validates real-time anomalies using LLMs.
logic.py (Python) + instruction.md (LLM guidance)StateGraph; conversation and chat working memory checkpointed to SQLite via SqliteSaverdata/conversations.db; the scheduler/CLI runtime now uses the same checkpoint-backed model via data/runtime_memory.dbContext budgeting notes:
llm.max_tokens: 16384 in config.yaml.max_context_chars budget of 4000 characters.
python --version)The current example configuration in config.yaml.example uses:
qwen2.5:7b-instruct-q4_K_M for chat/reasoningnomic-embed-text:latest as the lightweight local auxiliary model for embeddings referenced by the sample configQuick setup:
curl -fsSL https://ollama.com/install.sh | sh
ollama serve
ollama pull qwen2.5:7b-instruct-q4_K_M
ollama pull nomic-embed-text:latest
Step 1a: Clone the repository
git clone https://github.com/SecurityClaw/SecurityClaw.git
cd SecurityClaw
Step 1b: Create a Python virtual environment
# Using venv (built-in)
python3.11 -m venv .venv
# Or using virtualenv (if installed)
virtualenv .venv
Step 1c: Activate the virtual environment
# On Linux/macOS
source .venv/bin/activate
# On Windows (PowerShell)
.venv\Scripts\Activate.ps1
# On Windows (Command Prompt)
.venv\Scripts\activate.bat
Step 1d: Install Python dependencies
pip install -r requirements.txt
# Or using Pipenv (if you prefer):
pipenv install --dev
Verify installation:
python -c "import main; import core; print('✓ Dependencies OK')"
.venv/bin/python main.py onboard
The wizard will guide you through:
config.yaml and .envSee ONBOARDING.md for detailed walkthrough.
.venv/bin/python main.py service
Launches both the background scheduler and the web API server:
http://localhost:5173 (React frontend with hot reload)http://localhost:7799 (FastAPI REST service)For API-only mode (no scheduler):
SECURITYCLAW_API_ONLY=1 .venv/bin/python main.py service
For pure CLI/background agent operation without the web interface:
.venv/bin/python main.py run # Start scheduler loop (anomaly watcher + memory builder)
.venv/bin/python main.py dispatch <skill> # Fire a skill once (e.g., threat_analyst)
.venv/bin/python main.py chat # Interactive terminal-based chat with routing
.venv/bin/python main.py status # Print compact agent memory snapshot
.venv/bin/python main.py list-skills # Show loaded skills and intervals
If you want to develop the React frontend locally:
.venv/bin/python main.py web-dev # Start Vite dev server on :5173
# In a second terminal:
.venv/bin/python main.py service # Start backend API on :7799
The React web UI provides:
config.yaml and .env through the UISecurityClaw's chat orchestration is moving toward a capability-first contract model: