agentic-soc-platform
AI-driven security operations for alert triage and investigation
All Skills in This Repository (16)
Pure Emerald Level Indicatorsasp-alert-en
Review ASP alerts, update AI triage fields, and attach artifacts.
asp-enrichment-en
Create and attach enrichment records to cases, alerts, or artifacts on the ASP platform.
asp-artifact-en
Find, create, attach, and enrich artifacts via the ASP MCP server.
asp-siem-en
Explore ASP SIEM indices and fields for structured investigations.
asp-playbook-en
Identify ASP playbook definitions and inspect playbook run records.
asp-alert-zh
Review ASP alerts by ID and update AI analysis fields.
asp-enrichment-zh
Attach structured analysis enrichments to cases, alerts, or artifacts.
asp-artifact-zh
Search artifacts by IOC values, create records, and attach them to alerts.
asp-siem-zh
Explore schemas, search keywords, and run adaptive queries on ASP SIEM data.
asp-playbook-zh
Manage ASP playbook definitions and run histories via the MCP server.
asp-ticket-en
Create, attach, list, and update external tickets in ASP with case links.
asp-knowledge-en
Search and update ASP knowledge records on the MCP server.
Frequently Asked Questions
FAQPage SchemaHow to install Agentic SOC Platform?▼
Run `npx skills add FunnyWolf/agentic-soc-platform --all -g -y` in your terminal to install all skills in this suite globally.
What does Agentic SOC Platform do?▼
It uses AI agents to triage SIEM alerts, investigate cases, and enrich threat intelligence automatically. Massive alert volumes are condensed into a small number of actionable cases.
Which SIEM tools does it support?▼
It supports Splunk, ELK, and generic webhook alert ingestion with unified log search. Analysts and AI agents share the same security context across all sources.
Does it work with Claude Code and other AI agents?▼
Yes. It exposes its capabilities to Claude Code, Codex, and OpenCode through CLI and plugins, letting agents operate cases, search logs, and query threat intelligence directly.
Can I deploy it privately on my own network?▼
Yes. It is MIT licensed and supports fully local Docker deployment, so all security data stays inside your own network.
Related Repositories in Software Engineering
View All in Software Engineering→openclaw
Run a personal AI assistant across your devices and chat apps
superpowers
Gives coding agents a disciplined workflow from idea to merged code
react
AI agent skills for building, testing, and porting React core