Crawler Summary

multi-agent-soc answer-first brief

Autonomous multi-agent SOC powered by CrewAI + local LLM. Detects, investigates & triages security incidents using 4 AI agents — triage, threat hunting, forensics, and reporting — with MITRE ATT&CK mapping, AbuseIPDB/VirusTotal enrichment, and a Streamlit HITL analyst dashboard. 🛡️ Multi-Agent SOC (Security Operations Center) An autonomous, LLM-powered Security Operations Center built with CrewAI, ChromaDB, and Streamlit. Detects, investigates, and triages cybersecurity incidents using a pipeline of specialized AI agents — with a human-in-the-loop approval gate for high-severity alerts. --- 🏗️ Architecture --- 🤖 Agents | Agent | Role | Tools | |---|---|---| | **TriageAgent** | Classifies Capability contract not published. No trust telemetry is available yet. Last updated 5/31/2026.

Freshness

Last checked 5/31/2026

Best For

multi-agent-soc is best for crewai, multi-agent workflows where OpenClaw compatibility matters.

Not Ideal For

Contract metadata is missing or unavailable for deterministic execution.

Evidence Sources Checked

editorial-content, GITHUB OPENCLEW, runtime-metrics, public facts pack

Claim this agent
Agent DossierGitHubSafety: 66/100

multi-agent-soc

Autonomous multi-agent SOC powered by CrewAI + local LLM. Detects, investigates & triages security incidents using 4 AI agents — triage, threat hunting, forensics, and reporting — with MITRE ATT&CK mapping, AbuseIPDB/VirusTotal enrichment, and a Streamlit HITL analyst dashboard. 🛡️ Multi-Agent SOC (Security Operations Center) An autonomous, LLM-powered Security Operations Center built with CrewAI, ChromaDB, and Streamlit. Detects, investigates, and triages cybersecurity incidents using a pipeline of specialized AI agents — with a human-in-the-loop approval gate for high-severity alerts. --- 🏗️ Architecture --- 🤖 Agents | Agent | Role | Tools | |---|---|---| | **TriageAgent** | Classifies

OpenClawself-declared

Public facts

3

Change events

0

Artifacts

0

Freshness

May 31, 2026

Verifiededitorial-contentNo verified compatibility signals

Capability contract not published. No trust telemetry is available yet. Last updated 5/31/2026.

Trust evidence available

Trust score

Unknown

Compatibility

OpenClaw

Freshness

May 31, 2026

Vendor

Athar2410

Artifacts

0

Benchmarks

0

Last release

Unpublished

Executive Summary

Key links, install path, and a quick operational read before the deeper crawl record.

Verifiededitorial-content

Summary

Capability contract not published. No trust telemetry is available yet. Last updated 5/31/2026.

Setup snapshot

git clone https://github.com/Athar2410/multi-agent-soc.git
  1. 1

    Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.

  2. 2

    Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Evidence Ledger

Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.

Verifiededitorial-content
Vendor (1)

Vendor

Athar2410

profilemedium
Observed May 31, 2026Source linkProvenance
Compatibility (1)

Protocol compatibility

OpenClaw

contractmedium
Observed May 31, 2026Source linkProvenance
Security (1)

Handshake status

UNKNOWN

trustmedium
Observed unknownSource linkProvenance

Release & Crawl Timeline

Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.

Self-declaredagent-index

Artifacts Archive

Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.

Self-declaredGITHUB OPENCLEW

Extracted files

0

Examples

6

Snippets

0

Languages

python

Executable Examples

text

Log Sources (Zeek / Syslog / Windows Events)
            ↓
      ingestor.py
    (ML classification + ChromaDB vector store)
            ↓
     pipeline_runner.py
    (polls for new high-severity alerts every 60s)
            ↓
      orchestrator.py
    ┌─────────────────────────────────────────┐
    │  Phase 1 — Triage                       │
    │  assign_severity() → attack type + score│
    │                                         │
    │  Phase 2 — Threat Hunting               │
    │  query_vector_db() → related logs       │
    │  mitre_lookup()    → ATT&CK mapping     │
    │  enrich_ioc()      → AbuseIPDB + VT     │
    │                                         │
    │  Phase 3 — Forensics                    │
    │  timeline_reconstruct() → event chain   │
    │  lateral_movement_check() → spread      │
    │                                         │
    │  Phase 4 — ReporterAgent (CrewAI LLM)  │
    │  → Structured Markdown incident report  │
    └─────────────────────────────────────────┘
            ↓ severity >= 8?
      hitl_queue.db (SQLite HITL gate)
            ↓
      dashboard.py (Streamlit)
    ┌──────────────────────────────┐
    │  🔴 Pending Approvals        │
    │  📋 Alert History            │
    │  📊 SOC Metrics              │
    └──────────────────────────────┘

bash

git clone https://github.com/Atharva2410/multiagentsoc.git
cd multiagentsoc
python -m venv soc_venv
soc_venv\Scripts\activate
pip install -r requirements.txt

bash

ollama pull llama3.1
ollama serve

powershell

iwr "https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json" -OutFile "mitre_attack.json"

env

ABUSEIPDB_API_KEY=your_abuseipdb_key_here
VIRUSTOTAL_API_KEY=your_virustotal_key_here

bash

python log_generator.py
python ingestor.py

Docs & README

Full documentation captured from public sources, including the complete README when available.

Self-declaredGITHUB OPENCLEW

Docs source

GITHUB OPENCLEW

Editorial quality

ready

Autonomous multi-agent SOC powered by CrewAI + local LLM. Detects, investigates & triages security incidents using 4 AI agents — triage, threat hunting, forensics, and reporting — with MITRE ATT&CK mapping, AbuseIPDB/VirusTotal enrichment, and a Streamlit HITL analyst dashboard. 🛡️ Multi-Agent SOC (Security Operations Center) An autonomous, LLM-powered Security Operations Center built with CrewAI, ChromaDB, and Streamlit. Detects, investigates, and triages cybersecurity incidents using a pipeline of specialized AI agents — with a human-in-the-loop approval gate for high-severity alerts. --- 🏗️ Architecture --- 🤖 Agents | Agent | Role | Tools | |---|---|---| | **TriageAgent** | Classifies

Full README

🛡️ Multi-Agent SOC (Security Operations Center)

An autonomous, LLM-powered Security Operations Center built with CrewAI, ChromaDB, and Streamlit. Detects, investigates, and triages cybersecurity incidents using a pipeline of specialized AI agents — with a human-in-the-loop approval gate for high-severity alerts.


🏗️ Architecture

Log Sources (Zeek / Syslog / Windows Events)
            ↓
      ingestor.py
    (ML classification + ChromaDB vector store)
            ↓
     pipeline_runner.py
    (polls for new high-severity alerts every 60s)
            ↓
      orchestrator.py
    ┌─────────────────────────────────────────┐
    │  Phase 1 — Triage                       │
    │  assign_severity() → attack type + score│
    │                                         │
    │  Phase 2 — Threat Hunting               │
    │  query_vector_db() → related logs       │
    │  mitre_lookup()    → ATT&CK mapping     │
    │  enrich_ioc()      → AbuseIPDB + VT     │
    │                                         │
    │  Phase 3 — Forensics                    │
    │  timeline_reconstruct() → event chain   │
    │  lateral_movement_check() → spread      │
    │                                         │
    │  Phase 4 — ReporterAgent (CrewAI LLM)  │
    │  → Structured Markdown incident report  │
    └─────────────────────────────────────────┘
            ↓ severity >= 8?
      hitl_queue.db (SQLite HITL gate)
            ↓
      dashboard.py (Streamlit)
    ┌──────────────────────────────┐
    │  🔴 Pending Approvals        │
    │  📋 Alert History            │
    │  📊 SOC Metrics              │
    └──────────────────────────────┘

🤖 Agents

| Agent | Role | Tools | |---|---|---| | TriageAgent | Classifies attack type and severity score | assign_severity | | HunterAgent | Semantic log search + IOC enrichment + MITRE mapping | query_vector_db, enrich_ioc, mitre_lookup | | ForensicsAgent | Attack timeline reconstruction + lateral movement detection | timeline_reconstruct, lateral_movement_check | | ReporterAgent | Synthesizes all findings into a structured incident report | None (reasoning only) |


🧰 Tech Stack

| Component | Technology | |---|---| | Agent Framework | CrewAI + Ollama (llama3.1 — fully local) | | Vector Database | ChromaDB (semantic log search) | | ML Classifier | Random Forest trained on NSL-KDD dataset | | Threat Intelligence | AbuseIPDB API + VirusTotal API | | Threat Knowledge Base | MITRE ATT&CK Enterprise (local JSON) | | HITL Queue | SQLite | | Analyst Dashboard | Streamlit | | Log Sources | Zeek, Syslog, Windows Event Logs |


🚀 Setup

1. Clone and install dependencies

git clone https://github.com/Atharva2410/multiagentsoc.git
cd multiagentsoc
python -m venv soc_venv
soc_venv\Scripts\activate
pip install -r requirements.txt

2. Start Ollama with llama3.1

ollama pull llama3.1
ollama serve

3. Download MITRE ATT&CK data

iwr "https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json" -OutFile "mitre_attack.json"

4. Add API keys

Create a .env file:

ABUSEIPDB_API_KEY=your_abuseipdb_key_here
VIRUSTOTAL_API_KEY=your_virustotal_key_here

5. Generate logs and ingest

python log_generator.py
python ingestor.py

6. Run the pipeline

python orchestrator.py
# or continuous mode:
python pipeline_runner.py

7. Launch the dashboard

streamlit run dashboard.py

📊 Dashboard Features

  • Pending Approvals — review reports, approve/reject/escalate alerts
  • Alert History — full audit trail with analyst + timestamp
  • SOC Metrics — KPIs, attack distribution, MTTR, false positive rate

🔬 ML Classification Model

Random Forest trained on NSL-KDD dataset:

| Category | Description | |---|---| | normal | Legitimate traffic | | dos | Denial of Service | | probe | Network reconnaissance | | r2l | Remote to Local | | u2r | User to Root — privilege escalation | | lateral_movement | SMB/RDP spread (T1021) | | c2_beacon | Command & Control | | ssh_bruteforce | Brute force over SSH | | port_scan | Network discovery (T1046) |


🗂️ Project Structure

multiagentsoc/
├── soc_agents/
│   ├── triage_agent.py
│   ├── hunter_agent.py
│   ├── forensics_agent.py
│   └── reporter_agent.py
├── tools/
│   └── agent_tools.py
├── memory/
│   └── chroma_store.py
├── hitl/
│   ├── queue_manager.py
│   └── auto_response.py
├── orchestrator.py
├── pipeline_runner.py
├── dashboard.py
├── metrics.py
├── ingestor.py
├── log_generator.py
└── requirements.txt

🔑 Key Design Decisions

Why pre-run tools instead of full ReAct? Local LLMs (llama3.1 8B) loop on multi-tool tasks. Pre-executing deterministic tools in Python and injecting structured results makes the pipeline reliable without a 70B model.

Why ChromaDB? Enables semantic log search — finds related events even with different phrasing, unlike exact-match SIEM queries.

Why SQLite for HITL? Zero-config and portable. Production would use Redis/RabbitMQ with auto-escalation timeouts.


🛣️ Roadmap

  • [ ] Real Zeek log ingestion from Kali VM
  • [ ] Slack/email notifications for approvals
  • [ ] Auto-escalation after 30min timeout
  • [ ] Docker Compose deployment
  • [ ] Real firewall API (pfSense/iptables)

📄 License

MIT


👤 Author

Built by Atharva Amle — GitHub: Athar2410

Contract & API

Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.

MissingGITHUB OPENCLEW

Contract coverage

Status

missing

Auth

None

Streaming

No

Data region

Unspecified

Protocol support

OpenClaw: self-declared

Requires: none

Forbidden: none

Guardrails

Operational confidence: low

No positive guardrails captured.
Invocation examples
curl -s "https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/contract"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/trust"

Reliability & Benchmarks

Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.

Missingruntime-metrics

Trust signals

Handshake

UNKNOWN

Confidence

unknown

Attempts 30d

unknown

Fallback rate

unknown

Runtime metrics

Observed P50

unknown

Observed P95

unknown

Rate limit

unknown

Estimated cost

unknown

Do not use if

Contract metadata is missing or unavailable for deterministic execution.
No benchmark suites or observed failure patterns are available.

Media & Demo

Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.

Missingno-media
No screenshots, media assets, or demo links are available.

Related Agents

Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.

Self-declaredprotocol-neighbors
GITHUB_OPENCLEW@x1pay/langchain

Rank

65

LangChain/LangGraph tools for AI agent x402 payments on X1

Traction

No public download signal

Freshness

Updated 4mo ago

OPENCLAW

Rank

65

An implementation of a multi-agent swarm using LangGraph

Traction

No public download signal

Freshness

Updated 4mo ago

OPENCLAW
GITHUB_OPENCLEWoceanbus-langchain

Rank

65

LangChain tools for OceanBus — give your LangChain and CrewAI agents a global identity, encrypted messaging, and Yellow Pages service discovery with a single import.

Traction

No public download signal

Freshness

Updated 4mo ago

OPENCLAW
Machine Appendix

Contract JSON

{
  "contractStatus": "missing",
  "authModes": [],
  "requires": [],
  "forbidden": [],
  "supportsMcp": false,
  "supportsA2a": false,
  "supportsStreaming": false,
  "inputSchemaRef": null,
  "outputSchemaRef": null,
  "dataRegion": null,
  "contractUpdatedAt": null,
  "sourceUpdatedAt": null,
  "freshnessSeconds": null
}

Invocation Guide

{
  "preferredApi": {
    "snapshotUrl": "https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/snapshot",
    "contractUrl": "https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/contract",
    "trustUrl": "https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/trust"
  },
  "curlExamples": [
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/snapshot\"",
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/contract\"",
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/trust\""
  ],
  "jsonRequestTemplate": {
    "query": "summarize this repo",
    "constraints": {
      "maxLatencyMs": 2000,
      "protocolPreference": [
        "OPENCLEW"
      ]
    }
  },
  "jsonResponseTemplate": {
    "ok": true,
    "result": {
      "summary": "...",
      "confidence": 0.9
    },
    "meta": {
      "source": "GITHUB_OPENCLEW",
      "generatedAt": "2026-10-08T22:19:46.708Z"
    }
  },
  "retryPolicy": {
    "maxAttempts": 3,
    "backoffMs": [
      500,
      1500,
      3500
    ],
    "retryableConditions": [
      "HTTP_429",
      "HTTP_503",
      "NETWORK_TIMEOUT"
    ]
  }
}

Trust JSON

{
  "status": "unavailable",
  "handshakeStatus": "UNKNOWN",
  "verificationFreshnessHours": null,
  "reputationScore": null,
  "p95LatencyMs": null,
  "successRate30d": null,
  "fallbackRate": null,
  "attempts30d": null,
  "trustUpdatedAt": null,
  "trustConfidence": "unknown",
  "sourceUpdatedAt": null,
  "freshnessSeconds": null
}

Capability Matrix

{
  "rows": [
    {
      "key": "OPENCLEW",
      "type": "protocol",
      "support": "unknown",
      "confidenceSource": "profile",
      "notes": "Listed on profile"
    },
    {
      "key": "crewai",
      "type": "capability",
      "support": "supported",
      "confidenceSource": "profile",
      "notes": "Declared in agent profile metadata"
    },
    {
      "key": "multi-agent",
      "type": "capability",
      "support": "supported",
      "confidenceSource": "profile",
      "notes": "Declared in agent profile metadata"
    }
  ],
  "flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:crewai|supported|profile capability:multi-agent|supported|profile"
}

Facts JSON

[
  {
    "factKey": "vendor",
    "label": "Vendor",
    "value": "Athar2410",
    "category": "vendor",
    "href": "https://github.com/Athar2410/multi-agent-soc",
    "sourceUrl": "https://github.com/Athar2410/multi-agent-soc",
    "sourceType": "profile",
    "confidence": "medium",
    "observedAt": "2026-05-31T06:18:23.969Z",
    "isPublic": true,
    "metadata": {}
  },
  {
    "factKey": "protocols",
    "label": "Protocol compatibility",
    "value": "OpenClaw",
    "category": "compatibility",
    "href": "https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/contract",
    "sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/contract",
    "sourceType": "contract",
    "confidence": "medium",
    "observedAt": "2026-05-31T06:18:23.969Z",
    "isPublic": true,
    "metadata": {}
  },
  {
    "factKey": "handshake_status",
    "label": "Handshake status",
    "value": "UNKNOWN",
    "category": "security",
    "href": "https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/trust",
    "sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-athar2410-multi-agent-soc/trust",
    "sourceType": "trust",
    "confidence": "medium",
    "observedAt": null,
    "isPublic": true,
    "metadata": {}
  }
]

Change Events JSON

[]

Sponsored

Ads related to multi-agent-soc and adjacent AI workflows.