diff --git a/Docker/Img/img.png b/Docker/Img/img.png index 8b606e4..a377aff 100644 Binary files a/Docker/Img/img.png and b/Docker/Img/img.png differ diff --git a/Docker/Img/img_21.png b/Docker/Img/img_21.png index d960dbc..1d122a2 100644 Binary files a/Docker/Img/img_21.png and b/Docker/Img/img_21.png differ diff --git a/README.md b/README.md index 32f4d2f..c3c3e3a 100644 --- a/README.md +++ b/README.md @@ -8,12 +8,6 @@

Static Badge - - chat on Discord - - follow on X(Twitter) Commits last month @@ -28,16 +22,24 @@

-**Agentic SOC Platform** is a powerful, flexible, and open-source automated security operations platform. It integrates AI Agent capabilities with automation orchestration, supporting mainstream SIEM/SOAR scenarios to help enterprises efficiently build intelligent security operations systems. +**Agentic SOC Platform** is a powerful, flexible, and open-source automated security operations platform. It integrates +AI Agent capabilities with automation orchestration, supporting mainstream SIEM/SOAR scenarios to help enterprises +efficiently build intelligent security operations systems. ## Core Features -- 🧠 **AI-driven Intelligence**: Utilizes built-in AI Agent templates like Langgraph and Dify, supporting local LLMs to enhance alert analysis and automated response capabilities. -- 📊 **Built-in SIRP Platform**: Comes with a ready-to-use Security Incident Response Platform (SIRP) built on Nocoly, allowing for rapid customization of user interfaces, data models, reports, and workflows. -- ⚙️ **Powerful Automation Workflow**: Achieves efficient alert processing through Webhook + Redis Stream, natively supporting mainstream SIEM platforms such as Splunk and Kibana (ELK). -- 🛠️ **Highly Extensible**: Provides a rich library of modules and plugins. The entire framework is written in Python, facilitating secondary development and integration with various security devices and APIs. -- 🛡️ **Local Deployment & Data Control**: Supports complete local deployment. All data, models, and operations can be hosted within your own environment, ensuring enterprise data security and privacy. -- ⚡ **Streaming and Batch Processing**: Offers streaming processing (modules) for real-time alert analysis and event-driven automation (playbooks) for user-triggered tasks. +- 🧠 **AI-driven Intelligence**: Utilizes built-in AI Agent templates like Langgraph and Dify, supporting local LLMs to + enhance alert analysis and automated response capabilities. +- 📊 **Built-in SIRP Platform**: Comes with a ready-to-use Security Incident Response Platform (SIRP) built on Nocoly, + allowing for rapid customization of user interfaces, data models, reports, and workflows. +- ⚙️ **Powerful Automation Workflow**: Achieves efficient alert processing through Webhook + Redis Stream, natively + supporting mainstream SIEM platforms such as Splunk and Kibana (ELK). +- 🛠️ **Highly Extensible**: Provides a rich library of modules and plugins. The entire framework is written in Python, + facilitating secondary development and integration with various security devices and APIs. +- 🛡️ **Local Deployment & Data Control**: Supports complete local deployment. All data, models, and operations can be + hosted within your own environment, ensuring enterprise data security and privacy. +- ⚡ **Streaming and Batch Processing**: Offers streaming processing (modules) for real-time alert analysis and + event-driven automation (playbooks) for user-triggered tasks. ## Architecture Overview @@ -45,10 +47,14 @@ ASP processes security alerts and incidents through a simplified multi-stage pro 1. **SIEM/Alert Sources**: EDR, NDR, or other security tools send alerts to a SIEM (e.g., Splunk, Kibana). 2. **Webhook Forwarder**: The SIEM forwards these alerts via Webhook to the ASP's built-in Webhook receiver. -3. **Redis Stream**: The receiver pushes the alerts to the corresponding Redis Stream, serving as a persistent message queue. Each alert type has its own stream. -4. **Module Engine**: ASP **modules** consume alerts from their designated streams, perform analysis (often using AI Agents), enrich data, and determine outcomes. -5. **SIRP Platform**: The output of the modules (now formatted into standardized security records) is sent to the **SIRP** platform, where cases, alerts, and artifacts are created or updated. -6. **Playbook Engine**: Analysts can trigger **playbooks** from the SIRP user interface against cases, alerts, or artifacts to perform further automated actions, such as threat intelligence enrichment or remediation. +3. **Redis Stream**: The receiver pushes the alerts to the corresponding Redis Stream, serving as a persistent message + queue. Each alert type has its own stream. +4. **Module Engine**: ASP **modules** consume alerts from their designated streams, perform analysis (often using AI + Agents), enrich data, and determine outcomes. +5. **SIRP Platform**: The output of the modules (now formatted into standardized security records) is sent to the **SIRP + ** platform, where cases, alerts, and artifacts are created or updated. +6. **Playbook Engine**: Analysts can trigger **playbooks** from the SIRP user interface against cases, alerts, or + artifacts to perform further automated actions, such as threat intelligence enrichment or remediation. ![img_1.webp](Docker/Img/img_20.png) ![img_2.webp](Docker/Img/img_21.png) diff --git a/README_ZH.md b/README_ZH.md index f6499e9..29f704a 100644 --- a/README_ZH.md +++ b/README_ZH.md @@ -1,19 +1,13 @@ ![cover-v5-optimized](Docker/Img/img.png)

- Getting-started · - Documentation + Getting-started · + Documentation

Static Badge - - chat on Discord - - follow on X(Twitter) Commits last month @@ -52,7 +46,6 @@ ASP 通过简化的多阶段流程处理安全告警和事件: 5. **SIRP 平台**: 模块的输出(现在已格式化为标准化的安全记录)被发送到 **SIRP** 平台,在那里创建或更新案例、告警和 Artifact。 6. **剧本引擎**: 分析师可以从 SIRP 用户界面触发针对案例、告警或 Artifact 的 **剧本**,以执行进一步的自动化操作,例如威胁情报丰富或修复。 - ![img_1.webp](Docker/Img/img_20.png) ![img_2.webp](Docker/Img/img_21.png) ![img_2.webp](Docker/Img/img_22.png)