FunnyWolf/agentic-soc-platform
Agentic SOC Platform: A powerful, flexible, open-source, and agent-centric automated security operations platform (AI SOC)
What it solves
Agentic SOC Platform (ASP) addresses the problem of alert fatigue in security operations centers (SOCs). It transforms massive volumes of raw SIEM and webhook alerts into a small number of actionable cases, reducing the manual analysis time from hours to seconds by using AI-driven triage and investigation.
How it works
The platform integrates with multiple SIEMs (like Splunk and ELK) and webhooks to ingest alerts. It extracts Indicators of Compromise (IOCs) and correlates related signals to generate structured cases. It then uses LLMs and Agentic AI to automate the investigation process—producing severity, confidence, and impact reports. The system orchestrates these AI analyses alongside traditional SOAR workflows via a Playbook system. It also allows external agents (like Claude Code or Codex) to interact with the platform via CLI and plugins.
Who it’s for
Security teams and analysts who need to automate their triage, investigation, and enrichment processes to move from manual log analysis to AI-assisted decision-making.
Highlights
- AI-Powered Investigation: Automatically generates verdicts, priority, and structured investigation reports.
- Multi-SIEM Integration: Unified log search and alert ingestion for Splunk and ELK.
- Agentic Integration: Exposes capabilities to external agents (Claude Code, Codex, OpenCode) via CLI and plugins.
- Knowledge Accumulation: Extracts reusable knowledge from closed cases and response processes to improve organizational experience over time.
- Automated Enrichment: Automatically enriches IOCs and Artifacts with reputation and historical context.
- Private Deployment: MIT licensed and supports fully local deployment to keep security data within the network.