Blackhat 2025 presentation and codebase: AI SOC agent & MCP server for automated security investigation, alert triage, and incident response. Integrates with ELK, IRIS, and other platforms.
-
Updated
Dec 28, 2025 - Python
Blackhat 2025 presentation and codebase: AI SOC agent & MCP server for automated security investigation, alert triage, and incident response. Integrates with ELK, IRIS, and other platforms.
🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and auto-generate defense rules (YARA/SIGMA). DFIR & Malware Analysis Framework.
This tool runs scripts and display the result in a Web Interface.
Real-time Layer 7 DDoS detection and HTTP traffic analysis tool designed to identify bot activity, anomalous requests, and application-layer attacks with high accuracy.
AI-Driven Malware Triage & Deep Swarm Inspection Platform
Client-side AI log analysis engine. Detect volumetric brute-force threats and anomalous UA patterns locally, with zero server-side data ingestion.
Lightweight Bash-based malware hash scanner for SOC analysts to detect known malware using SHA256 hash comparison.
TheHive Modified: a Scalable, Open Source and Free Security Incident Response Platform
Command-line tool for detecting phishing emails in .eml files with rule-based analysis.
Tactics and Techniques used by Iraninan APT groups for MITRE
🛡️ Enhance network security with AEGIS-Ω, a hybrid intrusion detection system that combines signature and anomaly detection using advanced deep learning methods.
SentinelEye is a lightweight, fully local SIEM that ingests large‑scale firewall, DNS, and authentication logs to detect security threats in real time. It provides SOC‑ready alerts, rich investigations, and a dark dashboard without relying on external cloud services.
This project is a Comprehensive Vulnerability Management and Software Catalog system Dashboard.
Python-based phishing email analyzer with a web dashboard — detects spoofed headers, malicious URLs, brand impersonation, and IOCs with risk scoring 0-100
AEGIS-Omega is a high-performance, hybrid multi-layer Intrusion Detection System (IDS). It features a 4-layer detection strategy—Signature Analysis, Autoencoder Anomaly Detection, BiLSTM Deep Learning, and Ensemble Fusion—to identify attack types with 95% F1-score. Includes a FastAPI backend, React dashboard, and PCAP,Netflow analysis.
A collection of projects for enterprise security operations
Fast, SOC‑ready malicious document scanner that turns suspicious PDFs, DOC(X), XLS(X), and RTFs into IOC‑rich, SIEM‑friendly reports.
Privacy-conscious security triage and evidence review for Windows and Linux.
This is a repository for SOC tools I have made. tools may be added over time, so keep checking back for updates!
JUMAL (Junior Malware Analyst) - AI-powered tool for malware triage
Add a description, image, and links to the soc-tools topic page so that developers can more easily learn about it.
To associate your repository with the soc-tools topic, visit your repo's landing page and select "manage topics."