mirror of
https://github.com/FunnyWolf/agentic-soc-platform.git
synced 2026-08-22 13:12:56 +02:00
update link
This commit is contained in:
Binary file not shown.
|
Before Width: | Height: | Size: 2.1 MiB After Width: | Height: | Size: 2.8 MiB |
Binary file not shown.
|
Before Width: | Height: | Size: 513 KiB After Width: | Height: | Size: 870 KiB |
@@ -8,12 +8,6 @@
|
||||
<p align="center">
|
||||
<a href="https://asp.viperrtp.com/" target="_blank">
|
||||
<img alt="Static Badge" src="https://img.shields.io/badge/Website-F04438"></a>
|
||||
<a href="https://discord.gg/3R9yZvQueT" target="_blank">
|
||||
<img src="https://img.shields.io/badge/Community-blue?logo=discord&labelColor=%20%235462eb&logoColor=%20%23f5f5f5&color=%20%235462eb"
|
||||
alt="chat on Discord"></a>
|
||||
<a href="https://twitter.com/intent/follow?screen_name=viperrtp" target="_blank">
|
||||
<img src="https://img.shields.io/twitter/follow/viperrtp?logo=X&color=%20%23f5f5f5"
|
||||
alt="follow on X(Twitter)"></a>
|
||||
<a href="https://github.com/funnywolf/agentic-soc-platform/graphs/commit-activity" target="_blank">
|
||||
<img alt="Commits last month" src="https://img.shields.io/github/commit-activity/m/funnywolf/agentic-soc-platform?labelColor=%20%2332b583&color=%20%2312b76a"></a>
|
||||
<a href="https://github.com/funnywolf/agentic-soc-platform/" target="_blank">
|
||||
@@ -28,16 +22,24 @@
|
||||
</p>
|
||||
|
||||
|
||||
**Agentic SOC Platform** is a powerful, flexible, and open-source automated security operations platform. It integrates AI Agent capabilities with automation orchestration, supporting mainstream SIEM/SOAR scenarios to help enterprises efficiently build intelligent security operations systems.
|
||||
**Agentic SOC Platform** is a powerful, flexible, and open-source automated security operations platform. It integrates
|
||||
AI Agent capabilities with automation orchestration, supporting mainstream SIEM/SOAR scenarios to help enterprises
|
||||
efficiently build intelligent security operations systems.
|
||||
|
||||
## Core Features
|
||||
|
||||
- 🧠 **AI-driven Intelligence**: Utilizes built-in AI Agent templates like Langgraph and Dify, supporting local LLMs to enhance alert analysis and automated response capabilities.
|
||||
- 📊 **Built-in SIRP Platform**: Comes with a ready-to-use Security Incident Response Platform (SIRP) built on Nocoly, allowing for rapid customization of user interfaces, data models, reports, and workflows.
|
||||
- ⚙️ **Powerful Automation Workflow**: Achieves efficient alert processing through Webhook + Redis Stream, natively supporting mainstream SIEM platforms such as Splunk and Kibana (ELK).
|
||||
- 🛠️ **Highly Extensible**: Provides a rich library of modules and plugins. The entire framework is written in Python, facilitating secondary development and integration with various security devices and APIs.
|
||||
- 🛡️ **Local Deployment & Data Control**: Supports complete local deployment. All data, models, and operations can be hosted within your own environment, ensuring enterprise data security and privacy.
|
||||
- ⚡ **Streaming and Batch Processing**: Offers streaming processing (modules) for real-time alert analysis and event-driven automation (playbooks) for user-triggered tasks.
|
||||
- 🧠 **AI-driven Intelligence**: Utilizes built-in AI Agent templates like Langgraph and Dify, supporting local LLMs to
|
||||
enhance alert analysis and automated response capabilities.
|
||||
- 📊 **Built-in SIRP Platform**: Comes with a ready-to-use Security Incident Response Platform (SIRP) built on Nocoly,
|
||||
allowing for rapid customization of user interfaces, data models, reports, and workflows.
|
||||
- ⚙️ **Powerful Automation Workflow**: Achieves efficient alert processing through Webhook + Redis Stream, natively
|
||||
supporting mainstream SIEM platforms such as Splunk and Kibana (ELK).
|
||||
- 🛠️ **Highly Extensible**: Provides a rich library of modules and plugins. The entire framework is written in Python,
|
||||
facilitating secondary development and integration with various security devices and APIs.
|
||||
- 🛡️ **Local Deployment & Data Control**: Supports complete local deployment. All data, models, and operations can be
|
||||
hosted within your own environment, ensuring enterprise data security and privacy.
|
||||
- ⚡ **Streaming and Batch Processing**: Offers streaming processing (modules) for real-time alert analysis and
|
||||
event-driven automation (playbooks) for user-triggered tasks.
|
||||
|
||||
## Architecture Overview
|
||||
|
||||
@@ -45,10 +47,14 @@ ASP processes security alerts and incidents through a simplified multi-stage pro
|
||||
|
||||
1. **SIEM/Alert Sources**: EDR, NDR, or other security tools send alerts to a SIEM (e.g., Splunk, Kibana).
|
||||
2. **Webhook Forwarder**: The SIEM forwards these alerts via Webhook to the ASP's built-in Webhook receiver.
|
||||
3. **Redis Stream**: The receiver pushes the alerts to the corresponding Redis Stream, serving as a persistent message queue. Each alert type has its own stream.
|
||||
4. **Module Engine**: ASP **modules** consume alerts from their designated streams, perform analysis (often using AI Agents), enrich data, and determine outcomes.
|
||||
5. **SIRP Platform**: The output of the modules (now formatted into standardized security records) is sent to the **SIRP** platform, where cases, alerts, and artifacts are created or updated.
|
||||
6. **Playbook Engine**: Analysts can trigger **playbooks** from the SIRP user interface against cases, alerts, or artifacts to perform further automated actions, such as threat intelligence enrichment or remediation.
|
||||
3. **Redis Stream**: The receiver pushes the alerts to the corresponding Redis Stream, serving as a persistent message
|
||||
queue. Each alert type has its own stream.
|
||||
4. **Module Engine**: ASP **modules** consume alerts from their designated streams, perform analysis (often using AI
|
||||
Agents), enrich data, and determine outcomes.
|
||||
5. **SIRP Platform**: The output of the modules (now formatted into standardized security records) is sent to the **SIRP
|
||||
** platform, where cases, alerts, and artifacts are created or updated.
|
||||
6. **Playbook Engine**: Analysts can trigger **playbooks** from the SIRP user interface against cases, alerts, or
|
||||
artifacts to perform further automated actions, such as threat intelligence enrichment or remediation.
|
||||
|
||||

|
||||

|
||||
|
||||
+2
-9
@@ -1,19 +1,13 @@
|
||||

|
||||
|
||||
<p align="center">
|
||||
<a href="https://asp.viperrtp.com/asf/Development/environment_setup/">Getting-started</a> ·
|
||||
<a href="https://asp.viperrtp.com/asf/Introduction/what_is_asf/">Documentation</a>
|
||||
<a href="https://asp.viperrtp.com/zh/asf/Development/environment_setup/">Getting-started</a> ·
|
||||
<a href="https://asp.viperrtp.com/zh/asf/Introduction/what_is_asf/">Documentation</a>
|
||||
</p>
|
||||
|
||||
<p align="center">
|
||||
<a href="https://asp.viperrtp.com/" target="_blank">
|
||||
<img alt="Static Badge" src="https://img.shields.io/badge/Website-F04438"></a>
|
||||
<a href="https://discord.gg/3R9yZvQueT" target="_blank">
|
||||
<img src="https://img.shields.io/badge/Community-blue?logo=discord&labelColor=%20%235462eb&logoColor=%20%23f5f5f5&color=%20%235462eb"
|
||||
alt="chat on Discord"></a>
|
||||
<a href="https://twitter.com/intent/follow?screen_name=viperrtp" target="_blank">
|
||||
<img src="https://img.shields.io/twitter/follow/viperrtp?logo=X&color=%20%23f5f5f5"
|
||||
alt="follow on X(Twitter)"></a>
|
||||
<a href="https://github.com/funnywolf/agentic-soc-platform/graphs/commit-activity" target="_blank">
|
||||
<img alt="Commits last month" src="https://img.shields.io/github/commit-activity/m/funnywolf/agentic-soc-platform?labelColor=%20%2332b583&color=%20%2312b76a"></a>
|
||||
<a href="https://github.com/funnywolf/agentic-soc-platform/" target="_blank">
|
||||
@@ -52,7 +46,6 @@ ASP 通过简化的多阶段流程处理安全告警和事件:
|
||||
5. **SIRP 平台**: 模块的输出(现在已格式化为标准化的安全记录)被发送到 **SIRP** 平台,在那里创建或更新案例、告警和 Artifact。
|
||||
6. **剧本引擎**: 分析师可以从 SIRP 用户界面触发针对案例、告警或 Artifact 的 **剧本**,以执行进一步的自动化操作,例如威胁情报丰富或修复。
|
||||
|
||||
|
||||

|
||||

|
||||

|
||||
|
||||
Reference in New Issue
Block a user