![cover](img/img.png)

Agentic SOC Platform

Quick Start · Learn More · Workspace Features

Commits last month Issues closed Release

README in English 简体中文版自述文件

**Agentic SOC Platform** is an open-source security operations platform built on Agentic AI, enabling agents to proactively participate in triage, investigation, enrichment, and knowledge accumulation so security teams can move from alert fatigue to AI-assisted decision-making. --- ### Alert Floods, Converged into Actionable Cases Modules stream SIEM / Webhook alerts, extract IOCs, correlate related signals, and generate Cases, Alerts, and Artifacts so massive log volumes converge into a small number of actionable cases. ![Alert Floods, Converged into Actionable Cases](img/img_1.png) ### AI-Powered Investigation, Seconds Not Hours Compress hours of manual analysis into seconds, automatically producing severity, confidence, impact, priority, verdicts, and structured investigation reports. ![AI-Powered Investigation, Seconds Not Hours](img/img_2.png) ### One Click to Drive Complex Investigations Launch LLM investigation, knowledge extraction, threat intelligence enrichment, and CMDB enrichment around each Case, orchestrating traditional SOAR workflows and AI analysis in the same Playbook system. ![One Click to Drive Complex Investigations](img/img_3.png) ### Deep Harness Agent Integration Expose ASP capabilities to Claude Code / Codex / OpenCode and other Harness Agents through the CLI and plugins, enabling agents to operate Cases, search logs, query threat intelligence, and write modules and playbooks directly. ![Deep Harness Agent Integration](img/img_6.png) ### Multi-SIEM Access, One Investigation Entry Point Support Splunk, ELK configuration, unified log search, and Webhook alert ingestion so LLMs, agents, and analysts all work with the same security context. ![Multi-SIEM Access, One Investigation Entry Point](img/img_4.png) ### Automated Threat Intelligence Enrichment Automatically enrich IOCs and Artifacts with reputation, pulses, asset, identity, and historical context so every suspicious entity appears with evidence for judgment. ![Automated Threat Intelligence Enrichment](img/img_5.png) ### Knowledge Accumulation, Smarter Over Time Extract reusable knowledge from closed Case investigation records, response processes, and discussions, allowing organizational experience to grow with every response. ![Knowledge Accumulation](img/img_7.png) ### Collaboration, Audit, and Access Control Built In Local / LDAP login, user roles, API Keys, Inbox notifications, and Audit Log provide foundational governance so security operations no longer depend on fragmented tools. ![Collaboration, Audit, and Access Control Built In](img/img_9.png) ### Low-Cost Adaptation, Highly Flexible Customization Use Python Modules to adapt new SIEM rules and alert sources, and use Playbooks to orchestrate LLM analysis and automated actions so the platform grows with your security scenarios. ![Low-Cost Adaptation, Highly Flexible Customization](img/img_10.png) ### Open Source, Private Deployment, Python & Typescript MIT licensed, fully local deployment supported. Security data stays inside your network, while the backend, frontend, and extension scripts remain clear and controllable. ![Open Source & Private](img/img_8.png) --- ## Official Website [https://asp.viperrtp.com](https://asp.viperrtp.com) ## 404Starlink Agentic SOC Platform has joined [404Starlink](https://github.com/knownsec/404StarLink)