beenuar/AiSOC:README 来源编辑指南
基于 README、仓库元数据和许可证整理 beenuar/AiSOC 的安装与核验路径。
项目定位
beenuar/AiSOC 的 README 将项目描述为"Open-source AI-powered Security Operations Center , alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable."。本文只整理仓库能直接核验的内容,不把星标、Fork 或宣传语当成质量证明。README 在"AiSOC"下的说明是:An open-source, self-hostable AI SOC. The agent's prompts, tool calls, and rationale are logged step-by-step and replayable. MIT-licensed.。这给出的首先是项目边界,而不是已经完成的生产验证。
适用场景
从 README 的"What's in the box"和相关条目看,读者可以先判断它是否解决自己的具体问题:End-to-end SIEM spine , a cold docker compose up ingests connector data → lands it in the ClickHouse event lake → the executable detection corpus (947 rules) fires on the live stream → a fused alert is created, all asserted by an extended。如果你的目标与这段说明不一致,就不应仅凭项目热度采用它。这里保留原项目名、命令和组件名,方便回到一手来源核对。 README 还列出了另一条可核对的信息:83 click-and-connect data connectors (EDR/XDR, SIEM, NDR, cloud, CNAPP, identity, SaaS, VCS, K8s audit, network) with schema-driven config, live Test connection, and vault-encrypted secrets , recently adding Qualys, GreyNoise, JumpCloud,。这类原文条目可以帮助读者设计试运行步骤,但不能代替自己的环境测试。
工作方式
README 把工作方式分散写在"Try AiSOC in 60 seconds"等段落中。可确认的线索包括:The wedge CLI scores a batch of alerts to verdicts (escalate / review / suppress) with a deterministic engine ported from the production triage scorer , zero LLM key required.。这篇整理没有把未写出的架构、性能或安全边界补成结论;真正的运行链仍应结合仓库目录、配置文件和版本标签检查。
安装与第一次运行
第一次安装应从 README 给出的入口开始。当前可复核的命令是: flowchart LR subgraph Sources["Sources"] EDR["EDR / XDR"] SIEM["SIEM"] Cloud["Cloud APIs"] IDP["Identity"] Net["Network"] end subgraph Ingest["Ingest & Normalize"] Connectors["Connectors\n(Python · 78 vendors)"] OsqueryTLS["osquery-tls\n(Python · host telemetry)"] IngestSvc["Ingest worker\n(Go · OCSF)"] Enrich["Enrichment\n(Go · IOC + Shodan)"] end subgraph Spine["Event Spine"] Kafka[("Apache Ka 如果仓库没有提供命令,本文不会替它编造安装步骤,而是建议先打开 README 的"Try AiSOC in 60 seconds"部分,确认系统依赖、默认端口和首次初始化动作。