能力标签
AiSOC
⚙️
Agent工作流

AiSOC

基于 Python · 无代码搭建完整 AI 自动化流程
⭐ 1.1k Stars 🍴 104 Forks 💻 Python 📄 MIT 🏷 AI 8.0分
8.0AI 综合评分
ai-securitycybersecuritydetection-engineering
✦ AI Skill Hub 推荐

AI Skill Hub 强烈推荐:AiSOC 是一款优质的Agent工作流。已获得 1.1k 颗 GitHub Star,AI 综合评分 8.0 分,在同类工具中表现稳健。如果你正在寻找可靠的Agent工作流解决方案,这是一个值得深入了解的选择。

📚 深度解析

AiSOC 是一套完整的 AI Agent 自动化工作流方案。随着 AI 能力的不断提升,基于 Agent 的自动化工作流正在成为提升个人和团队效率的核心方式。区别于传统的 RPA 自动化(模拟鼠标键盘操作),AI Agent 工作流通过理解任务意图、动态规划执行路径,能够处理更复杂的非结构化任务。

AiSOC 工作流的设计遵循"最小配置,最大复用"原则:核心逻辑已经封装好,用户只需配置自己的 API Key 和业务参数即可快速上手。工作流内置错误处理和重试机制,在网络波动或 API 限速等情况下仍能稳定运行,适合作为生产环境的自动化基础设施。

在实际部署时,建议先在测试环境中运行 3-5 次,验证各个环节的输出结果符合预期,再部署到生产环境。AI Skill Hub 评分 8.0 分,是同类 Agent 工作流中的精选推荐。

📋 工具概览

AiSOC 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。

GitHub Stars
⭐ 1.1k
开发语言
Python
支持平台
Windows / macOS / Linux
维护状态
正常维护,社区驱动
开源协议
MIT
AI 综合评分
8.0 分
工具类型
Agent工作流
Forks
104

📖 中文文档

以下内容由 AI Skill Hub 根据项目信息自动整理,如需查看完整原始文档请访问底部「原始来源」。

AiSOC 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。

📌 核心特色
  • 可视化 Agent 工作流编排,无需编写复杂代码
  • 支持多步骤自动化任务链,实现全流程无人值守
  • 与外部 API、数据库和第三方服务无缝集成
  • 内置错误处理与自动重试机制,保障稳定运行
  • 提供可复用的自动化模板,快速在同类场景部署
🎯 主要使用场景
  • 自动化日常重复性工作,将精力集中于创造性任务
  • 构建数据采集 → 处理 → 输出的完整自动化管线
  • 实现跨平台、跨系统的数据流转和业务协同
以下安装命令基于项目开发语言和类型自动生成,实际以官方 README 为准。
安装命令
# 方式一:pip 安装(推荐)
pip install aisoc

# 方式二:虚拟环境安装(推荐生产环境)
python -m venv .venv
source .venv/bin/activate  # Windows: .venv\Scripts\activate
pip install aisoc

# 方式三:从源码安装(获取最新功能)
git clone https://github.com/beenuar/AiSOC
cd AiSOC
pip install -e .

# 验证安装
python -c "import aisoc; print('安装成功')"
📋 安装步骤说明
  1. 访问 GitHub 仓库获取工作流文件
  2. 在对应平台(Dify / Flowise / Make 等)中找到「导入工作流」功能
  3. 上传工作流文件
  4. 按照提示配置必要的环境变量和 API Key
  5. 运行测试确认流程正常后投入使用
以下用法示例由 AI Skill Hub 整理,涵盖最常见的使用场景。
常用命令 / 代码示例
# 命令行使用
aisoc --help

# 基本用法
aisoc input_file -o output_file

# Python 代码中调用
import aisoc

# 示例
result = aisoc.process("input")
print(result)
以下配置示例基于典型使用场景生成,具体参数请参照官方文档调整。
配置示例
# aisoc 配置文件示例(config.yml)
app:
  name: "aisoc"
  debug: false
  log_level: "INFO"

# 运行时指定配置文件
aisoc --config config.yml

# 或通过环境变量配置
export AISOC_API_KEY="your-key"
export AISOC_OUTPUT_DIR="./output"
📑 README 深度解析 真实文档 完整度 25/100 含工作流图 查看 GitHub 原文 →
以下内容由系统直接从 GitHub README 解析整理,保留代码块、表格与列表结构。

简介

<img src="apps/web/public/logo-mark.svg" alt="AiSOC" width="120" />

What's in the box

A handful of headline capabilities — the rest are catalogued in apps/docs/docs/features/ and indexed at the top of apps/docs/docs/intro.md:

Maturity (v7.7.0 — Fully-Operational release). The end-to-end spine is wired and CI-gated: ingest → ClickHouse lake → live detection → fused alert → auto-triage → governed response. Connectors, Investigation Rail + Ledger, Hunt-as-Code, live-stream detection, and copilot auto-triage are GA. Autonomous response defaults to copilot/dry-run (an autonomy policy governs every real execution). The live-agent LLM benchmark is preview (the deterministic-tier scoreboard is CI-gated per PR); substrate eval suites are GA. Every product claim is backed by a failing test — claim-to-gate matrix: 46 GATED / 9 PARTIAL / 0 NO GATE. Full per-claim status: docs/audit/REALITY_REPORT.md. v7.7.0 adds three detection-authoring modes (Python framework + AI builder + no-code), least-privilege invoking-identity scoping for response actions, self-service data lifecycle (retention + a ReDoS-proof transform DSL + custom parsers), an agentless CSPM scanner with compliance auto-evidence and Opsgenie/email/SOAR destinations, and a customizable report builder — all tested, all landed on main.
  • 83 click-and-connect data connectors (EDR/XDR, SIEM, NDR, cloud, CNAPP, identity, SaaS, VCS, K8s audit, network) with schema-driven config, live Test connection, and vault-encrypted secrets — recently adding Qualys, GreyNoise, JumpCloud, Darktrace, and Imperva alongside IBM QRadar, Netskope, Zeek/Suricata NDR, and more. One query runs SIEM-agnostic federated search across Splunk SPL / Sentinel KQL / Elastic ES&#124;QL / QRadar AQL. Walkthrough: apps/docs/docs/connectors/index.md.
  • End-to-end SIEM spine — a cold docker compose up ingests connector data → lands it in the ClickHouse event lake → the executable detection corpus (947 rules) fires on the live stream → a fused alert is created, all asserted by an extended integration gate. Fuse-time threat-intel + CISA-KEV enrichment now feeds the confidence score and exploit-in-wild boost, and stateful/windowed detections (brute-force, password-spray, port-scan) run alongside the corpus. apps/docs/docs/architecture.md.
  • Autonomous triage + governed response — every fused alert is auto-triaged by the agent (copilot/read-only by default) with a prompt-injection guard that demotes tampered evidence to manual review; a unified confidence × blast-radius × reversibility policy authorizes auto-execution only for reversible, low-blast actions at high confidence (everything else stays gated to a human), with real rollback + post-action verification. apps/docs/docs/concepts/automation-maturity.md.
  • Advanced Data Explorer — one investigation surface (NL + SQL over the lake, plus pivots to identity/graph/intel), replacing the SIEM context-switch. /explore.
  • Investigation Rail + replayable Investigation Ledger — every prompt, tool call, evidence chip, and rationale stored against a case, replayable in the UI and shareable as a redacted public permalink (live demo replay). apps/docs/docs/console/investigation-rail.md.
  • Detection-as-Code lifecycle — propose → review → eval-gate → promote; CI rejects any candidate that fails its own positive/negative fixtures (the non-circular gate) or regresses MITRE accuracy. Analyst false-positive feedback now feeds a self-improving tuner that proposes scoped rule exceptions / severity changes (human-approved, never auto-applied). apps/docs/docs/concepts/detections.md — and the 869 native rules live in detections/.
  • Three-model AI + tool-using agents — Semantic (graph-at-ingest), Behavioral (UEBA fused into alert scoring), and Knowledge (LLM), with fuse-time attack-chain grouping. The agent calls real tools (IOC enrichment, MITRE lookup, graph blast-radius) through an LLM tool-calling loop, and a scored planner routes each alert to the right specialist instead of fanning out to all four.
  • Cost-governed LLM routing — per-tenant budgets + circuit breaker, token/cost telemetry, a content-addressed response cache, a cheap-first cost cascade (escalate to the strong model only on low confidence), multi-model gateway fallbacks, and per-tenant BYOK keys. services/agents/app/routing/.
  • Hunt-as-Code — YAML hypotheses with MITRE tags, cron schedules, and natural-language /hunt workbench. hunts/ + apps/docs/docs/console/rule-tuning.md. Plus free, login-free browser tools: a Sigma/SPL/KQL/ES&#124;QL rule translator, an ATT&CK coverage grader, NL→Sigma, and a noise calculator.
  • Public weekly benchmark scoreboard — the same harness that gates PRs; the deterministic-tier row is CI-gated for freshness on every PR, and the funded weekly job appends live-LLM rows. A new groundedness/hallucination axis flags any indicator the agent asserts that isn't in the evidence it was given. apps/docs/docs/benchmark-scoreboard.mdx.

---

How AiSOC compares

CapabilityAiSOCWazuhSplunk ESClosed-source AI SOC
Open-source licenseMITGPL-2proprietaryproprietary
Self-hostableyesyesenterprise-onlycloud-only
Autonomous AI investigationLangGraphnopartial (Splunk AI)yes
Agent decision audit trailpublic Investigation Ledgern/an/anot published
Public substrate eval harnessCI-gated, reproducible, with synthetic telemetry corpus + per-template macrosn/an/anot published
Detection content947 executable (869 native) firing on the live stream + 6 000-rule provenance-tracked imported library ([truth table](docs/detections/truth-table.md))1 200+ rules1 000+ appscurated
Plugin SDKPython / TypeScript / GoYAML rules onlyappsproprietary
Data residencyyour infrayour infrapartialvendor cloud
Pricing$0 (self-host)$0 (self-host)per ingest GBenterprise

Closed-source AI SOC vendors ship working products. AiSOC's contribution is making the agent itself open, the per-step decision trail readable, and the substrate gated by a public eval harness on every PR targeting main / develop.

---

🇨🇳 中文文档镜像 AI 翻译 2026-06-19
英文原文章节由系统翻译为中文摘要,便于快速理解。完整原文见上方 "📑 README 深度解析"。
📌 简介

AiSOC 是一个集成化的安全运营中心(SOC)解决方案,旨在打破传统 SOC 需要从多个供应商处拼凑组件的局限。它将数据连接、分析与响应能力整合进统一的平台,帮助安全团队实现高效的威胁检测与自动化处置。

⚡ 功能介绍

AiSOC 提供强大的数据集成能力,内置包含 50 多个连接器的目录,支持通过简单的点击操作快速接入 EDR/XDR(如 CrowdStrike Falcon、SentinelOne、Microsoft Defender XDR 等)以及 SIEM(如 Splunk、Microsoft Sentinel、Elastic 等)平台。最新版本已强化安全性与稳定性,通过升级 cryptography 等核心依赖,确保能够抵御最新的 CVE 漏洞威胁。

📋 环境依赖

AiSOC 提供了一键式安装程序(One-click installer),即使您的系统中尚未安装 Docker、Node、pnpm 或 git,也可以通过 bootstrap 安装程序实现自动化部署。该工具会自动检测您的操作系统,并以幂等(idempotent)的方式完成所有环境配置与仓库克隆。

🛠 安装步骤(Docker/pip/源码)

项目支持多种极速部署路径。对于本地开发,您可以使用 Docker Compose,通过一条命令即可拉取预构建的镜像并启动包含 Postgres、Redis、Kafka、api、agents 等组件的演示环境,系统会自动运行数据种子脚本,让您直接进入 LockBit 3.0 勒索软件调查案例进行体验。此外,项目还为 Fly.io、Render 和 Railway 等云平台提供了经过测试的配置文件,支持快速上线。

🚀 使用教程

项目内置了预设的演示场景(如 INC-RT-001 案例),用户在通过 Docker Compose 启动后,浏览器会自动跳转至对应的调查页面,并实现自动登录,方便开发者快速上手并理解 AiSOC 的实际工作流。

⚙️ 配置说明(含 MCP / env)

除了基础配置外,AiSOC 支持通过环境变量进行功能增强。您可以配置 CYBLE_API_KEY、VIRUSTOTAL_API_KEY、SHODAN_API_KEY 等第三方安全 API 来丰富威胁情报。此外,系统还支持接入可选的 TAXII feeds 以获取最新的威胁数据,并支持通过 SAML 2.0 进行 SSO 单点登录配置。

🎯 aiskill88 AI 点评 A 级 2026-05-29

AiSOC是一个高质量的开源AI安全项目

📚 实用指南(长尾问题)
适合谁
  • 需要让 Claude / Cursor 操作本地工具的 AI 工程师
  • 构建多智能体协作系统的 Agent 开发者
  • 构建企业知识库 / RAG 检索应用的团队
  • 跨境业务、多语言内容运营团队
最佳实践
  • 配置 MCP 服务器时建议使用 stdio 传输 + JSON-RPC,避免暴露公网
  • 生产部署优先使用 Docker Compose 隔离依赖,并挂载 volume 持久化数据
  • 本地部署优先选 GGUF 量化模型,节省显存并保持响应速度
  • 分块大小建议 256-512 tokens,向量库优选 pgvector 或 Qdrant
  • Agent 任务先做 dry-run 验证工具调用链,再开启自主执行
常见错误
  • API key 直接提交到 git 仓库(请用 .env 并加入 .gitignore)
  • MCP 配置路径拼错或权限不足,重启 Claude Desktop 才生效
  • 容器内无法访问宿主机 localhost — 使用 host.docker.internal
  • embedding 模型与查询模型不一致导致检索失效
  • 显存不足直接 OOM — 优先降低 context 或换更小的量化模型
  • Python 依赖冲突:建议用 venv / uv 隔离环境
部署方案
  • Docker:AiSOC 提供官方镜像,docker compose up 一键启动
  • CLI:直接 npm install -g / pip install,命令行调用
  • 本地部署:CPU 8GB 起,GPU 推荐 16GB+ 显存
  • 云端托管:可放在 Vercel / Railway / Fly.io 等 PaaS 平台
相关搜索
AiSOC 中文教程AiSOC 安装报错怎么办AiSOC MCP 配置AiSOC Docker 部署AiSOC Agent 工作流AiSOC 与同类工具对比AiSOC 最佳实践AiSOC 适合谁用

⚡ 核心功能

👥 适合谁
  • 需要让 Claude / Cursor 操作本地工具的 AI 工程师
  • 构建多智能体协作系统的 Agent 开发者
  • 构建企业知识库 / RAG 检索应用的团队
  • 跨境业务、多语言内容运营团队
⭐ 最佳实践
  • 配置 MCP 服务器时建议使用 stdio 传输 + JSON-RPC,避免暴露公网
  • 生产部署优先使用 Docker Compose 隔离依赖,并挂载 volume 持久化数据
  • 本地部署优先选 GGUF 量化模型,节省显存并保持响应速度
  • 分块大小建议 256-512 tokens,向量库优选 pgvector 或 Qdrant
⚠️ 常见错误
  • API key 直接提交到 git 仓库(请用 .env 并加入 .gitignore)
  • MCP 配置路径拼错或权限不足,重启 Claude Desktop 才生效
  • 容器内无法访问宿主机 localhost — 使用 host.docker.internal
  • embedding 模型与查询模型不一致导致检索失效

👥 适合人群

自动化工程师和运维人员项目经理和业务分析师希望减少重复性工作的专业人士数字化转型团队

🎯 使用场景

  • 自动化日常重复性工作,将精力集中于创造性任务
  • 构建数据采集 → 处理 → 输出的完整自动化管线
  • 实现跨平台、跨系统的数据流转和业务协同

⚖️ 优点与不足

✅ 优点
  • +MIT 协议,可免费商用
  • +大幅减少重复性人工操作
  • +可视化流程,清晰直观
  • +可扩展性强,支持复杂场景
⚠️ 不足
  • 初始配置和调试需投入一定时间
  • 强依赖外部服务的稳定性
  • 复杂场景需具备一定技术基础
⚠️ 使用须知

AI Skill Hub 为第三方内容聚合平台,本页面信息基于公开数据整理,不对工具功能和质量作任何法律背书。

建议在沙箱或测试环境中充分验证后,再部署至生产环境,并做好必要的安全评估。

📄 License 说明

✅ MIT 协议 — 最宽松的开源协议之一,可自由商用、修改、分发,仅需保留版权声明。

🔗 相关工具推荐

📰 相关 AI 新闻
🍿 AI 圈相关吃瓜
🗺️ 相关解决方案
🧩 你可能还需要
基于当前 Skill 的能力图谱,自动补全的工具组合

❓ 常见问题 FAQ

AiSOC 是一款Python开发的AI辅助工具。开源AI工作流:Open-source AI-powered Security Operations Center — alert fusion, purple-team dr。⭐1.1k · Python 主要应用场景包括:安全运营中心自动化。
💡 AI Skill Hub 点评

总体来看,AiSOC 是一款质量优秀的Agent工作流,在同类工具中具备一定竞争力。AI Skill Hub 将持续追踪其更新动态,建议收藏备用,结合自身场景选择合适时机引入使用。

⬇️ 获取与下载
⬇ 下载源码 ZIP

✅ MIT 协议 · 可免费商用 · 直接从 aiskill88 服务器下载,无需跳转 GitHub

📚 深入学习 AiSOC
查看分步骤安装教程和完整使用指南,快速上手这款工具
🌐 原始信息
原始名称 AiSOC
原始描述 开源AI工作流:Open-source AI-powered Security Operations Center — alert fusion, purple-team dr。⭐1.1k · Python
Topics ai-securitycybersecuritydetection-engineering
GitHub https://github.com/beenuar/AiSOC
License MIT
语言 Python
🔗 原始来源
🐙 GitHub 仓库  https://github.com/beenuar/AiSOC 🌐 官方网站  https://tryaisoc.com

收录时间:2026-05-29 · 更新时间:2026-05-30 · License:MIT · AI Skill Hub 不对第三方内容的准确性作法律背书。

📺 订阅 AI Skill Hub Daily Telegram 频道
每天 8 条精选 AI Skill、MCP、Agent 与自动化工具推送
加入频道 →