socprime/detectflow-main
Detection intelligence turbocharged with Al.
What it solves
Prime Detect (formerly DetectFlow) addresses the latency and capacity limits of traditional SIEMs. It enables line-speed detection of cyberattacks by processing events in-flight before they are ingested into a SIEM, reducing the Mean Time to Detect (MTTD) from minutes to sub-second levels (0.005–0.01 seconds).
How it works
The system uses Apache Flink-based ETL pipelines to apply tens of thousands of Sigma rules to streaming events via Apache Kafka. It tags and enriches events in-flight, allowing for high-scale detection orchestration across data pipelines, EDRs, and data lakes without requiring changes to existing SIEM ingestion architectures.
Who it’s for
Security operations teams who need to perform real-time, high-volume threat detection at scale and reduce the time between an event occurring and its detection.
Highlights
- Sub-second detection: Achieves 0.005–0.01 seconds MTTD compared to 15+ minutes for typical SIEMs.
- High rule capacity: Increases rule capacity by 10x on existing infrastructure.
- Hot-reload support: Update rules, filters, and parsers without needing to restart pipelines.
- Flexible deployment: Supports both full Kubernetes clusters and lightweight local Minikube deployments.
- Broad rule integration: Syncs detection rules from the SOC Prime Platform, SigmaHQ, and local repositories.
Related
- Project
- Project
- Project
- Project
- Project