← All projects
Security

SecSight

AI-driven SOC platform

Overview

SecSight is an AI-driven security operations platform.

The system ships with a process-isolated deployment model and is aligned with MLPS 2.0.

Product impact

Pain → Solution → Value

Most small and mid SOC teams run on two analysts, a SIEM that pages them at 3 a.m., and a backlog of tickets nobody has time to triage.

Pain
Alert backlog nobody closes
Solution
Multi-agent SecOps copilot
80%
L0–L2 triage time
Pain
False positives drown signal
Solution
Verdict + evidence chain
60%
Noise-to-signal ratio
Pain
Out-of-hours staffing gaps
Solution
L0–L3 autonomous execution
24/7
Coverage without headcount
Pain
Compliance evidence trail
Solution
Signed playbooks + audit log
MLPS 2.0
Ready out of the box

What changes for the team

A wider view of the same loop. Each card zooms into the corresponding column above.

Pain

The SOC alert backlog nobody closes

  • Phishing reports, brute-force spikes, and noisy EDR signals flood the queue.
  • Two analysts spend the day triaging low-value alerts instead of hunting real intrusions.
  • The incidents that actually matter sit open until a customer reports them.
8h+
Daily triage time per analyst
Solution

A copilot that closes the routine work

  • Multi-agent SecOps Copilot handles phishing triage, FP sweep, and IOC enrichment under explicit autonomy levels.
  • 22 production playbooks ship ready to run — from L0 advisory up to L4 closed-loop.
  • Every action is replayable in a human review queue with verdict + evidence chain.
22
Production playbooks ready to run
Impact

Analysts back on the work that matters

  • Two-person team keeps coverage on nights and weekends without growing headcount.
  • Senior time shifts from queue-watching to threat hunting and detection engineering.
  • MLPS 2.0 / 等保 2.0 aligned out of the box — no audit re-architecture.
5
Autonomy levels (L0–L4)

Product architecture

Every alert moves through the same four participants.

Technical architecture

Self-hosted AI SOC platform. Click any node or relationship for details.

Capabilities

AI SecOps Copilot
Multi-agent SOC assistant over SIEM/ticket/KB.
Auto-remediation SOAR
22 production playbooks across 5 autonomy levels.
Four-layer knowledge base
Process-isolated; aligned with MLPS 2.0 (等保 2.0).
MCP & LiteLLM
Pluggable LLM backend, MCP tool bus, Qdrant RAG.

By the numbers

  • 22 production playbooks
  • 5 autonomy levels (L0–L4)
  • 234 tests · 87.8% coverage
  • 4-layer knowledge base
  • Process-isolated deployment

Try it, fork it, or hire me to extend it.

Source on GitHub · Apache-2.0 · questions to 286043314+echocc00@users.noreply.github.com