Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
AiSOC — Self-hostable AI SOC that fuses security alerts, auto-triages via agentic AI, runs MITRE ATT&CK investigations, and logs every agent decision in a replayable ledger. | Kitploit
工具/GitHubGitHub/beenuar/aisoc
Defensive ToolsThreat IntelligenceMachine LearningIntrusion DetectionIncident ResponseAI SecurityAnomaly DetectionLog Analysis
GitHubbeenuar/aisoc

AiSOC

Self-hostable AI SOC that fuses security alerts, auto-triages via agentic AI, runs MITRE ATT&CK investigations, and logs every agent decision in a replayable ledger.

查看仓库
1.8k234354小时6分前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站
内容在请求的语言中不可用。显示英文版本。
AiSOC

AiSOC

An open-source, self-hostable AI Security Operations Center. It ingests your security telemetry, detects and correlates threats, investigates them with AI agents whose reasoning is fully auditable, and proposes responses a human approves.

License: MIT Version CI CodeQL OpenSSF Scorecard

Docs · Architecture · What actually works · Discussions


What AiSOC does

Telemetry arrives from your security tools. AiSOC normalizes it, runs the 2603 executable rules of its 6991-rule library, groups what fires into incidents, investigates each one with an AI agent whose every prompt and tool call is recorded, and proposes an action. New threat intelligence re-sweeps the history you already collected. A human approves before anything runs.

What it looks like running

AiSOC on one host: make up brings the stack up and prints the sign-in address, the console shows real CISA KEV rows, a pushed event becomes an alert, and the cost dashboard reports the tokens triage spent

Watch the full three minutes — install to AI verdict on one server, against the published images. Terminal waits are shortened, which the recording says on screen. (step by step)

Stills from earlier runs under the same rules — no seeded rows, no demo mode, no mockups. The events were authored to be representative; everything downstream is the product doing its job. (what is real)

Alerts queueAI triage verdict in the Investigation Rail
Alerts — each attributed to the connector that fed it.Automated triage — the bundled local model's verdict, confidence and rationale, verbatim.
Threat intelligence page showing CISA KEV entriesSOC operations dashboard with honest empty states
Threat intelligence — the real CISA KEV catalog, minutes after boot, with no API key.SOC operations — with nothing connected yet, and it says so rather than showing a placeholder.

Quick start

git clone https://github.com/beenuar/AiSOC && cd AiSOC
make up

Needs Docker Compose v2 with 8 GB memory and 20 GB free disk in the Docker VM, plus python3 (3.9+) and bash — make doctor checks all of it, and Installation says what each number was measured against. The first run downloads a ~2 GB language model into a named volume; only make clean fetches it again.

make up also creates .env and generates the fourteen secrets in it — the credential vault, the session signing key, the five service-to-service credentials and the four datastore passwords — then creates an administrator and prints its password. That password is generated on your machine, shown once, and stored nowhere: copy it, or mint a new one with make bootstrap ARGS=--reset-password.

Then prove it actually works. make smoke posts one real event to the ingest API, follows it through Kafka, detection, correlation and Postgres, and reads the alert back out of the public API. Every stage reports PASS or FAIL:

$ make smoke
[PASS] raw telemetry accepted by ingest
[PASS] event traversed the spine and became an alert
[PASS] alert is retrievable by id from the API

Open http://localhost:3000 and sign in with the credentials make up printed (API docs at http://localhost:8000/api/docs). On a server, set AISOC_CONSOLE_URL in .env — make up then prints that address rather than localhost, which is the one people can browse to. Stuck? make doctor.

Try it without connecting anything

make demo loads a synthetic dataset — the pipeline shape, not real activity, and never a benchmark, a customer or an incident. Every row is is_synthetic = true and labelled in the console.

Connect real data

Two ways in. Push, with a credential from make ingest-token (the tenant comes from it, not from a header):

curl -X POST http://localhost:8081/v1/ingest/batch \
  -H 'Content-Type: application/json' -H "Authorization: Bearer $AISOC_INGEST_TOKEN" \
  -d '{"connector_id":"edr-1","connector_type":"crowdstrike","source_format":"json",
       "events":[{"severity":"high","title":"Encoded PowerShell from Office",
                  "host":"WIN-FIN-01","process_name":"powershell.exe"}]}'

Or pull, by configuring one of 84 click-and-connect data connectors in Settings → Connectors (needs the full profile). Those with vendor-specific normalization and live setup docs include Splunk, Microsoft Sentinel, Elastic, CrowdStrike, Okta, AWS (GuardDuty / CloudTrail / Security Hub), Wiz, and Kubernetes audit logs — full list in the connector docs. Without a vendor profile a connector still ingests through a generic mapping that resolves host, user and source IP from the usual spellings.

How it works

Ingest normalizes to a common shape and Kafka carries it. Then fusion runs 2603 executable detection rules, of 6991 on disk, and decides what becomes an alert, correlation groups related alerts, an agent investigates and writes its reasoning to the Investigation Ledger, and a human approves any response. Separately, new threat intelligence sweeps the lake for sightings you already collected, and a hypothesis becomes a hunt without anyone writing a query — the model fills a closed schema and every value it supplies is bound as a parameter, so it cannot express a query at all.

下载工具