Awesome AI for Infra › Security Monitoring

beenuar/AiSOC

⭐ 2382 Python added to this list on 2026-06-14 repository created 2026-05-02

AiSOC is an open-source, self-hostable Security Operations Center (SOC) that leverages AI to enhance security operations. It functions by ingesting various security events, correlating them, and then performing AI-driven investigations. A key distinguishing feature is its transparent 'Investigation Ledger,' which logs the LLM prompts, responses, evidence cited, and tool calls for every step of an investigation, making agent decisions replayable and auditable. This provides a deep level of transparency often missing in proprietary AI SOC solutions. The platform includes a public evaluation harness in CI/CD, where every pull request is gated by five suites, including tests against a synthetic incident dataset for MITRE-tactic, investigation-completeness, and response-quality, as well as an alert-reduction gate. This rigorous testing ensures the reliability and effectiveness of its AI capabilities. AiSOC is designed to run entirely on user infrastructure, ensuring data privacy and preventing data exfiltration to vendor clouds. Its orchestrator, built with LangGraph, is compact and easily adaptable for model swapping or patching. The project emphasizes security hardening, multi-agent routing, and multi-cloud infrastructure support. Recent updates include prompt-injection sanitizers, cross-tenant isolation enforcement, and a comprehensive dependency refresh. The console features workbenches with global time-window selectors and tenant switchers, catering to both single-tenant and MSSP operational models. AiSOC aims to provide a robust, transparent, and controllable AI solution for modern security operations.

https://github.com/beenuar/AiSOC

ai-securityalert-triagecybersecurityincident-responsemitre-attacksecurity-operationssiemsoarsocthreat-detectionself-hostedopen-sourceaimlaio

Also in Security Monitoring

backbay-labs/clawdstrike

Clawdstrike is an AI-powered Endpoint Detection and Response (EDR) system providing policy enforcement, a signed audit chain, and threat detection for developer workstations and autonomous agent fl...

gensecaihq/Wazuh-MCP-Server

Model Context Protocol server that exposes a Wazuh SIEM to AI assistants, letting them query alerts, hunt threats, triage vulnerabilities and run active responses in natural language.