socprime/detectflow-main

Detection intelligence turbocharged with Al.

What it solves

Prime Detect (formerly DetectFlow) addresses the latency and capacity limits of traditional SIEMs. It enables line-speed detection of cyberattacks by processing events in-flight before they are ingested into a SIEM, reducing the Mean Time to Detect (MTTD) from minutes to sub-second levels (0.005–0.01 seconds).

How it works

The system uses Apache Flink-based ETL pipelines to apply tens of thousands of Sigma rules to streaming events via Apache Kafka. It tags and enriches events in-flight, allowing for high-scale detection orchestration across data pipelines, EDRs, and data lakes without requiring changes to existing SIEM ingestion architectures.

Who it’s for

Security operations teams who need to perform real-time, high-volume threat detection at scale and reduce the time between an event occurring and its detection.

Highlights

  • Sub-second detection: Achieves 0.005–0.01 seconds MTTD compared to 15+ minutes for typical SIEMs.
  • High rule capacity: Increases rule capacity by 10x on existing infrastructure.
  • Hot-reload support: Update rules, filters, and parsers without needing to restart pipelines.
  • Flexible deployment: Supports both full Kubernetes clusters and lightweight local Minikube deployments.
  • Broad rule integration: Syncs detection rules from the SOC Prime Platform, SigmaHQ, and local repositories.

Related

  • Project
  • Project
  • Project
  • Project
  • Project