mirror of
https://github.com/FunnyWolf/agentic-soc-platform.git
synced 2026-08-22 13:12:56 +02:00
201f92e2b2f2759b5ed6bceefba49cb3c19ff44e
- Merge attach_enrichment_to_target into create_enrichment (target_id required) - Merge attach_ticket_to_case into create_ticket (case_id required) - Merge get_case_discussions into list_cases (include_discussions param) - Remove comment_ai/summary_ai from update_case, add comment/summary - Remove unused agent files (agent_cmdb, agent_report, simpler/agents) - Update all skill files to match new MCP interfaces
…
…
Getting-started · Documentation
Agentic SOC Platform A powerful, flexible, open-source, and agent-centric automated security operations platform.
Core Features
- 🧠 AI-driven Intelligence: Utilizes built-in AI Agent templates like Langgraph and Dify, supporting local LLMs to enhance alert analysis and automated response capabilities.
- 📊 Built-in SIRP Platform: Comes with a ready-to-use Security Incident Response Platform (SIRP) built on Nocoly, allowing for rapid customization of user interfaces, data models, reports, and workflows.
- ⚙️ Powerful Automation Workflow: Achieves efficient alert processing through Webhook + Redis Stream, natively supporting mainstream SIEM platforms such as Splunk and Kibana (ELK).
- 🛠️ Highly Extensible: Provides a rich library of modules and plugins. The entire framework is written in Python, facilitating secondary development and integration with various security devices and APIs.
- 🛡️ Local Deployment & Data Control: Supports complete local deployment. All data, models, and operations can be hosted within your own environment, ensuring enterprise data security and privacy.
- ⚡ Streaming and Batch Processing: Offers streaming processing (modules) for real-time alert analysis and event-driven automation (playbooks) for user-triggered tasks.
Architecture Overview
ASP processes security alerts and incidents through a simplified multi-stage process:
- SIEM/Alert Sources: EDR, NDR, or other security tools send alerts to a SIEM (e.g., Splunk, Kibana).
- Webhook Forwarder: The SIEM forwards these alerts via Webhook to the ASP's built-in Webhook receiver.
- Redis Stream: The receiver pushes the alerts to the corresponding Redis Stream, serving as a persistent message queue. Each alert type has its own stream.
- Module ModuleEngine: ASP modules consume alerts from their designated streams, perform analysis (often using AI Agents), enrich data, and determine outcomes.
- SIRP Platform: The output of the modules (now formatted into standardized security records) is sent to the **SIRP ** platform, where cases, alerts, and artifacts are created or updated.
- PlaybookLoader ModuleEngine: Analysts can trigger playbooks from the SIRP user interface against cases, alerts, or artifacts to perform further automated actions, such as threat intelligence enrichment or remediation.
Official Website
404Starlink
Agentic SOC Platform has joined 404Starlink
Languages
Python
59.7%
TypeScript
36.5%
CSS
2.2%
Shell
1.5%





