detectflow-main  by socprime

AI-driven cybersecurity detection and enrichment platform

Created 1 week ago

New!

350 stars

Top 79.8% on SourcePulse

GitHubView on GitHub
Project Summary

Detection intelligence turbocharged with AI, DetectFlow addresses slow cyberattack detection by enabling line-speed analysis using AI trained on extensive historical data. It targets security operations teams and engineers, offering sub-second Mean Time To Detect (MTTD) and transforming daily work from SIEM tuning to comprehensive detection orchestration across diverse data pipelines.

How It Works

This project utilizes Apache Flink for real-time stream processing and Apache Kafka for data ingestion. It tags events in-flight with metadata from Sigma detection rules, sourced optionally from the SOC Prime Platform or GitHub repositories, before they reach SIEMs. This approach allows for sub-second MTTD, scales rule capacity by 10x on existing infrastructure, and operates without requiring changes to the current SIEM ingestion architecture.

Quick Start & Requirements

Highlighted Details

  • Sub-second MTTD: Achieves detection times between 0.005–0.01 seconds.
  • Enhanced Rule Capacity: Enables 10x rule capacity on existing infrastructure.
  • Real-time Operations: Features a live Dashboard for pipeline monitoring and Pipeline Management for creating/configuring ETL processes.
  • Hot-Reload Support: Allows updating rules, filters, and parsers without restarting pipelines, ensuring zero downtime for these changes.

Maintenance & Community

The provided README does not detail community channels (e.g., Discord, Slack), notable contributors, sponsorships, or a public roadmap. It mentions integration with the SOC Prime Platform for rule synchronization.

Licensing & Compatibility

  • License type: Dual licensing: European Union Public License (EUPL) v1.2 and a SOC Prime Commercial License. Users must select the appropriate license based on their intended use.
  • Compatibility: No explicit restrictions mentioned for commercial use or closed-source linking beyond the license terms.

Limitations & Caveats

Deployment demands significant Kubernetes and infrastructure expertise. The system comprises multiple interdependent services (Backend, UI, MatchNode, Schema Parser). Optional features like cloud rule synchronization necessitate internet access and API keys.

Health Check
Last Commit

6 days ago

Responsiveness

Inactive

Pull Requests (30d)
0
Issues (30d)
0
Star History
355 stars in the last 7 days

Explore Similar Projects

Starred by Chip Huyen Chip Huyen(Author of "AI Engineering", "Designing Machine Learning Systems").

SecGPT by Clouditera

0.2%
3k
Open-source LLM for cybersecurity tasks
Created 2 years ago
Updated 8 months ago
Feedback? Help us improve.