AI Skill Hub 强烈推荐:AiSOC 是一款优质的Agent工作流。已获得 1.1k 颗 GitHub Star,AI 综合评分 8.0 分,在同类工具中表现稳健。如果你正在寻找可靠的Agent工作流解决方案,这是一个值得深入了解的选择。
AiSOC 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
AiSOC 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
# 方式一:pip 安装(推荐)
pip install aisoc
# 方式二:虚拟环境安装(推荐生产环境)
python -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install aisoc
# 方式三:从源码安装(获取最新功能)
git clone https://github.com/beenuar/AiSOC
cd AiSOC
pip install -e .
# 验证安装
python -c "import aisoc; print('安装成功')"
# 命令行使用
aisoc --help
# 基本用法
aisoc input_file -o output_file
# Python 代码中调用
import aisoc
# 示例
result = aisoc.process("input")
print(result)
# aisoc 配置文件示例(config.yml) app: name: "aisoc" debug: false log_level: "INFO" # 运行时指定配置文件 aisoc --config config.yml # 或通过环境变量配置 export AISOC_API_KEY="your-key" export AISOC_OUTPUT_DIR="./output"
<img src="apps/web/public/logo-mark.svg" alt="AiSOC" width="120" />
A handful of headline capabilities — the rest are catalogued in apps/docs/docs/features/ and indexed at the top of apps/docs/docs/intro.md:
Maturity (v7.7.0 — Fully-Operational release). The end-to-end spine is wired and CI-gated: ingest → ClickHouse lake → live detection → fused alert → auto-triage → governed response. Connectors, Investigation Rail + Ledger, Hunt-as-Code, live-stream detection, and copilot auto-triage are GA. Autonomous response defaults to copilot/dry-run (an autonomy policy governs every real execution). The live-agent LLM benchmark is preview (the deterministic-tier scoreboard is CI-gated per PR); substrate eval suites are GA. Every product claim is backed by a failing test — claim-to-gate matrix: 46 GATED / 9 PARTIAL / 0 NO GATE. Full per-claim status:docs/audit/REALITY_REPORT.md. v7.7.0 adds three detection-authoring modes (Python framework + AI builder + no-code), least-privilege invoking-identity scoping for response actions, self-service data lifecycle (retention + a ReDoS-proof transform DSL + custom parsers), an agentless CSPM scanner with compliance auto-evidence and Opsgenie/email/SOAR destinations, and a customizable report builder — all tested, all landed onmain.
Test connection, and vault-encrypted secrets — recently adding Qualys, GreyNoise, JumpCloud, Darktrace, and Imperva alongside IBM QRadar, Netskope, Zeek/Suricata NDR, and more. One query runs SIEM-agnostic federated search across Splunk SPL / Sentinel KQL / Elastic ES|QL / QRadar AQL. Walkthrough: apps/docs/docs/connectors/index.md.docker compose up ingests connector data → lands it in the ClickHouse event lake → the executable detection corpus (947 rules) fires on the live stream → a fused alert is created, all asserted by an extended integration gate. Fuse-time threat-intel + CISA-KEV enrichment now feeds the confidence score and exploit-in-wild boost, and stateful/windowed detections (brute-force, password-spray, port-scan) run alongside the corpus. apps/docs/docs/architecture.md.apps/docs/docs/concepts/automation-maturity.md./explore.apps/docs/docs/console/investigation-rail.md.apps/docs/docs/concepts/detections.md — and the 869 native rules live in detections/.services/agents/app/routing/./hunt workbench. hunts/ + apps/docs/docs/console/rule-tuning.md. Plus free, login-free browser tools: a Sigma/SPL/KQL/ES|QL rule translator, an ATT&CK coverage grader, NL→Sigma, and a noise calculator.apps/docs/docs/benchmark-scoreboard.mdx.---
| Capability | AiSOC | Wazuh | Splunk ES | Closed-source AI SOC |
|---|---|---|---|---|
| Open-source license | MIT | GPL-2 | proprietary | proprietary |
| Self-hostable | yes | yes | enterprise-only | cloud-only |
| Autonomous AI investigation | LangGraph | no | partial (Splunk AI) | yes |
| Agent decision audit trail | public Investigation Ledger | n/a | n/a | not published |
| Public substrate eval harness | CI-gated, reproducible, with synthetic telemetry corpus + per-template macros | n/a | n/a | not published |
| Detection content | 947 executable (869 native) firing on the live stream + 6 000-rule provenance-tracked imported library ([truth table](docs/detections/truth-table.md)) | 1 200+ rules | 1 000+ apps | curated |
| Plugin SDK | Python / TypeScript / Go | YAML rules only | apps | proprietary |
| Data residency | your infra | your infra | partial | vendor cloud |
| Pricing | $0 (self-host) | $0 (self-host) | per ingest GB | enterprise |
Closed-source AI SOC vendors ship working products. AiSOC's contribution is making the agent itself open, the per-step decision trail readable, and the substrate gated by a public eval harness on every PR targeting main / develop.
---
AiSOC 是一个集成化的安全运营中心(SOC)解决方案,旨在打破传统 SOC 需要从多个供应商处拼凑组件的局限。它将数据连接、分析与响应能力整合进统一的平台,帮助安全团队实现高效的威胁检测与自动化处置。
AiSOC 提供强大的数据集成能力,内置包含 50 多个连接器的目录,支持通过简单的点击操作快速接入 EDR/XDR(如 CrowdStrike Falcon、SentinelOne、Microsoft Defender XDR 等)以及 SIEM(如 Splunk、Microsoft Sentinel、Elastic 等)平台。最新版本已强化安全性与稳定性,通过升级 cryptography 等核心依赖,确保能够抵御最新的 CVE 漏洞威胁。
AiSOC 提供了一键式安装程序(One-click installer),即使您的系统中尚未安装 Docker、Node、pnpm 或 git,也可以通过 bootstrap 安装程序实现自动化部署。该工具会自动检测您的操作系统,并以幂等(idempotent)的方式完成所有环境配置与仓库克隆。
项目支持多种极速部署路径。对于本地开发,您可以使用 Docker Compose,通过一条命令即可拉取预构建的镜像并启动包含 Postgres、Redis、Kafka、api、agents 等组件的演示环境,系统会自动运行数据种子脚本,让您直接进入 LockBit 3.0 勒索软件调查案例进行体验。此外,项目还为 Fly.io、Render 和 Railway 等云平台提供了经过测试的配置文件,支持快速上线。
项目内置了预设的演示场景(如 INC-RT-001 案例),用户在通过 Docker Compose 启动后,浏览器会自动跳转至对应的调查页面,并实现自动登录,方便开发者快速上手并理解 AiSOC 的实际工作流。
除了基础配置外,AiSOC 支持通过环境变量进行功能增强。您可以配置 CYBLE_API_KEY、VIRUSTOTAL_API_KEY、SHODAN_API_KEY 等第三方安全 API 来丰富威胁情报。此外,系统还支持接入可选的 TAXII feeds 以获取最新的威胁数据,并支持通过 SAML 2.0 进行 SSO 单点登录配置。
AiSOC是一个高质量的开源AI安全项目
AI Skill Hub 为第三方内容聚合平台,本页面信息基于公开数据整理,不对工具功能和质量作任何法律背书。
建议在沙箱或测试环境中充分验证后,再部署至生产环境,并做好必要的安全评估。
✅ MIT 协议 — 最宽松的开源协议之一,可自由商用、修改、分发,仅需保留版权声明。
总体来看,AiSOC 是一款质量优秀的Agent工作流,在同类工具中具备一定竞争力。AI Skill Hub 将持续追踪其更新动态,建议收藏备用,结合自身场景选择合适时机引入使用。
| 原始名称 | AiSOC |
| 原始描述 | 开源AI工作流:Open-source AI-powered Security Operations Center — alert fusion, purple-team dr。⭐1.1k · Python |
| Topics | ai-securitycybersecuritydetection-engineering |
| GitHub | https://github.com/beenuar/AiSOC |
| License | MIT |
| 语言 | Python |
收录时间:2026-05-29 · 更新时间:2026-05-30 · License:MIT · AI Skill Hub 不对第三方内容的准确性作法律背书。
选择 Agent 类型,复制安装指令后粘贴到对应客户端