{"id":"978aac9a-ab23-44a8-86f7-2f90ca0f9522","slug":"crewai-athar2410-multi-agent-soc","name":"multi-agent-soc","description":"Autonomous multi-agent SOC powered by CrewAI + local LLM. Detects, investigates & triages security incidents using 4 AI agents — triage, threat hunting, forensics, and reporting — with MITRE ATT&CK mapping, AbuseIPDB/VirusTotal enrichment, and a Streamlit HITL analyst dashboard.","canonicalUrl":"https://www.xpersona.co/skill/crewai-athar2410-multi-agent-soc","sourceUrl":"https://github.com/Athar2410/multi-agent-soc","homepage":null,"source":"GITHUB_OPENCLEW","vendor":{"slug":"athar2410","label":"Athar2410","url":"https://github.com/Athar2410/multi-agent-soc"},"protocols":["OPENCLEW"],"capabilities":["crewai","multi-agent"],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":null,"freshnessAt":"2026-05-31T06:18:23.969Z","freshnessLabel":"May 31, 2026","securityReviewed":true,"openapiReady":false,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"OpenClaw"},{"label":"Freshness","value":"May 31, 2026"},{"label":"Vendor","value":"Athar2410"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"Unpublished"}],"factsPreview":[{"factKey":"vendor","label":"Vendor","value":"Athar2410","category":"vendor","href":"https://github.com/Athar2410/multi-agent-soc","sourceUrl":"https://github.com/Athar2410/multi-agent-soc","sourceType":"profile","confidence":"medium","observedAt":"2026-05-31T06:18:23.969Z","isPublic":true,"metadata":{}},{"factKey":"protocols","label":"Protocol compatibility","value":"OpenClaw","category":"compatibility","href":"https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-05-31T06:18:23.969Z","isPublic":true,"metadata":{}},{"factKey":"handshake_status","label":"Handshake status","value":"UNKNOWN","category":"security","href":"https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true,"metadata":{}}],"highlights":["Trust evidence available"],"agentCard":{"name":"multi-agent-soc","description":"Autonomous multi-agent SOC powered by CrewAI + local LLM. Detects, investigates & triages security incidents using 4 AI agents — triage, threat hunting, forensics, and reporting — with MITRE ATT&CK mapping, AbuseIPDB/VirusTotal enrichment, and a Streamlit HITL analyst dashboard.","source":"GITHUB_OPENCLEW","sourceId":"crewai:1229798016","repository":"https://github.com/Athar2410/multi-agent-soc","documentation":"https://www.xpersona.co/skill/crewai-athar2410-multi-agent-soc/agent/crewai-athar2410-multi-agent-soc","protocols":["OPENCLEW"],"capabilities":["crewai","multi-agent"],"languages":["python"],"install":{"command":"git clone https://github.com/Athar2410/multi-agent-soc.git","ecosystem":"git"},"examples":[{"kind":"example","language":"text","snippet":"Log Sources (Zeek / Syslog / Windows Events)\n            ↓\n      ingestor.py\n    (ML classification + ChromaDB vector store)\n            ↓\n     pipeline_runner.py\n    (polls for new high-severity alerts every 60s)\n            ↓\n      orchestrator.py\n    ┌─────────────────────────────────────────┐\n    │  Phase 1 — Triage                       │\n    │  assign_severity() → attack type + score│\n    │                                         │\n    │  Phase 2 — Threat Hunting               │\n    │  query_vector_db() → related logs       │\n    │  mitre_lookup()    → ATT&CK mapping     │\n    │  enrich_ioc()      → AbuseIPDB + VT     │\n    │                                         │\n    │  Phase 3 — Forensics                    │\n    │  timeline_reconstruct() → event chain   │\n    │  lateral_movement_check() → spread      │\n    │                                         │\n    │  Phase 4 — ReporterAgent (CrewAI LLM)  │\n    │  → Structured Markdown incident report  │\n    └─────────────────────────────────────────┘\n            ↓ severity >= 8?\n      hitl_queue.db (SQLite HITL gate)\n            ↓\n      dashboard.py (Streamlit)\n    ┌──────────────────────────────┐\n    │  🔴 Pending Approvals        │\n    │  📋 Alert History            │\n    │  📊 SOC Metrics              │\n    └──────────────────────────────┘"},{"kind":"example","language":"bash","snippet":"git clone https://github.com/Atharva2410/multiagentsoc.git\ncd multiagentsoc\npython -m venv soc_venv\nsoc_venv\\Scripts\\activate\npip install -r requirements.txt"}]}}