beenuar/AiSOC
AiSOC is an open-source, self-hostable AI-powered Security Operations Center that ingests, correlates, and investigates security events using AI, providing a transparent investigation ledger.
Awesome AI for Infra › Security Monitoring
Clawdstrike delivers an AI EDR solution designed for securing developer workstations and multi-agent systems, functioning as a policy engine, EDR, and signed audit chain. It monitors various events, from AI agent tool calls to kernel-level file accesses, process executions, network flows, and dynamic library loads, evaluating them against a unified policy engine. The system enforces 'fail closed' defaults, meaning actions are blocked unless explicitly allowed. Each decision is recorded with an Ed25519-signed receipt, contributing to a causal graph that tracks agent identity through operational events. Key features include a guard stack for composable checks against threats like forbidden path access, secret leaks, dangerous shell commands, prompt injection, and AI model jailbreaks. It integrates with native OS security features (macOS Endpoint Security, Linux Tetragon/Hubble) and offers SDKs for Rust, TypeScript, Python, and Go, allowing agents to run under enforcement. For fleet deployments, a Helm chart provides cluster-wide management, including a control plane for enrollment and posture commands, and integrates with NATS JetStream for audit chaining. This approach ensures a verifiable audit trail and robust security for modern, AI-driven IT environments.
https://github.com/backbay-labs/clawdstrike
AiSOC is an open-source, self-hostable AI-powered Security Operations Center that ingests, correlates, and investigates security events using AI, providing a transparent investigation ledger.
Model Context Protocol server that exposes a Wazuh SIEM to AI assistants, letting them query alerts, hunt threats, triage vulnerabilities and run active responses in natural language.