beenuar/AiSOC:README 來源編輯指南
根據 README、倉庫資料與授權整理 beenuar/AiSOC 的安裝與核驗路徑。
專案定位
beenuar/AiSOC 的 README 將專案描述為「Open-source AI-powered Security Operations Center , alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.」。本文只整理倉庫可直接核對的內容,不把 star、Fork 或宣傳語當成品質證明。README 在「AiSOC」下寫到:An open-source, self-hostable AI SOC. The agent's prompts, tool calls, and rationale are logged step-by-step and replayable. MIT-licensed.。這說明的是專案邊界,不是已完成的生產驗證。
適用場景
從 README 的「What's in the box」與相關條目,可以先判斷它是否處理你的實際問題:End-to-end SIEM spine , a cold docker compose up ingests connector data → lands it in the ClickHouse event lake → the executable detection corpus (947 rules) fires on the live stream → a fused alert is created, all asserted by an extended。若需求不同,不應只因專案熱度就採用。本文保留原始專案名、命令與元件名,方便回到一手來源核對。 README 另外列出一項可核對的資訊:83 click-and-connect data connectors (EDR/XDR, SIEM, NDR, cloud, CNAPP, identity, SaaS, VCS, K8s audit, network) with schema-driven config, live Test connection, and vault-encrypted secrets , recently adding Qualys, GreyNoise, JumpCloud,。這類原文條目可用來設計試跑步驟,但不能取代實際環境測試。
運作方式
README 將運作方式分散在「Try AiSOC in 60 seconds」等段落。可確認的線索包括:The wedge CLI scores a batch of alerts to verdicts (escalate / review / suppress) with a deterministic engine ported from the production triage scorer , zero LLM key required.。本文不把未寫出的架構、效能或安全邊界補成結論;真正的執行鏈仍要配合目錄、設定檔與版本標籤檢查。
安裝與第一次執行
第一次安裝應從 README 指出的入口開始。目前可核對的命令是: flowchart LR subgraph Sources["Sources"] EDR["EDR / XDR"] SIEM["SIEM"] Cloud["Cloud APIs"] IDP["Identity"] Net["Network"] end subgraph Ingest["Ingest & Normalize"] Connectors["Connectors\n(Python · 78 vendors)"] OsqueryTLS["osquery-tls\n(Python · host telemetry)"] IngestSvc["Ingest worker\n(Go · OCSF)"] Enrich["Enrichment\n(Go · IOC + Shodan)"] end subgraph Spine["Event Spine"] Kafka[("Apache Ka 如果倉庫沒有命令,本文不會自行編造步驟,而是建議先閱讀「Try AiSOC in 60 seconds」,確認系統依賴、預設埠與首次初始化。