SOC-MIND · OPEN SOURCE · ON-PREMISE

Investigate every alert.
Never leave your network.

AI-powered alert triage. Open source. 100% on-premise. The foundation of the sovereign SOC — built for KRITIS, NIS2 and BSI IT-Grundschutz.

Alert sources via REST API: such as Splunk · Cortex XDR · QRadar · Wazuh · Sentinel  ·  Hand-off: such as to Jira · XSOAR · TheHive
The new standard

Sovereign SOC automation

100 %
On-premise

Alert data, threat intelligence and AI inference run entirely inside your infrastructure — fully air-gapped if you choose.

0 Byte
Cloud transfer

No data leaving the building, no data processing agreements, no cross-border transfer assessments. Locality by architecture, not by contract.

1 day
to production

A single Docker Compose stack on one server or VM. Offline release bundles via USB/SFTP for air-gapped sites.

SOC-Mind

Turn a thousand alerts into manageable incidents

SIEM and EDR tools generate thousands of alerts a day — most are duplicates or fragments of the same attack. SOC-Mind suppresses repeats and deterministically links related alerts into one incident before the AI runs.

  • Exact-duplicate suppression via fingerprinting
  • Entity-based correlation: attackers, hosts, users, techniques
  • Critical alerts escalate instantly — reproducible and auditable
SOC-Mind

AI investigation by your playbooks — on your hardware

A locally hosted LLM investigates every incident by playbook and writes the analyst-ready summary: what happened, evidence, kill chain, next steps. The playbooks ship with the product — carrying enough context for open-source models to master the analysis reliably.

  • The best model per task: e.g. GPT-OSS for reports, a security model for alert analysis
  • Playbooks as versioned YAML files — adaptable anytime
  • Auditable, not a black box: your team reads every investigation step
SOC-Mind

Triage that asks its own questions

If context on an alert is missing, SOC-Mind goes and gets it — via automated email to the responsible department. And through the chat interface, your analysts search customer data, alerts and the knowledge base in natural language.

  • Automated follow-up emails to business departments
  • Natural-language SOC chat across customer data, alerts and knowledge base
  • Analysis in full enterprise context — internal data and SOC processes included
SOC-Mind

Seamless in your stack — in production within a day

SOC-Mind replaces nothing, it connects: the SIEM/EDR tools you already run, your own MISP instance, your case management. Delivered as a single Docker Compose stack — multi-tenant with hard per-tenant data isolation.

  • Alert sources via REST API, hand-off to Jira, XSOAR or TheHive
  • MITRE ATT&CK context and threat intel from your MISP instance
  • Multi-tenant for group structures and MSSPs
The idea behind it

SOC-Mind is the invisible intelligence behind your SOC.

It works in the background and analyzes every alert in full enterprise context — with access to your internal data, your knowledge base and your SOC processes. That context is exactly what makes the analysis precise. And exactly why it must never leave the building.

Sovereignty guarantee

Your data never leaves your infrastructure.

SOC-Mind will be released as an open-source project: your team and your auditors can inspect every line. No vendor black box, no lock-in, no license kill-switch on critical infrastructure.

Air-gap capableNIS2-aligned data localityBSI IT-Grundschutz-alignedBuilt for critical infrastructure (KRITIS)Open source (repository public soon)
Positioning

Cloud-AI-SOC vs. SOC-Mind

Cloud AI-SOC vendorsSOC-Mind
Alert data leaves the networkNothing leaves the network — air-gap capable
AI reasoning is a black boxPlaybook-driven: your team writes the AI’s investigation steps
Pricing anxiety: per seat, per GB, per cloud callRuns on your own hardware
Compliance assessment per data flowLocality by architecture, not by contract
Closed, proprietary codeOpen source — inspectable, auditable, no lock-in
Honest framing: SOC-Mind is analysis and triage automation — it investigates and recommends, but does not execute autonomous containment actions (automated response is on the roadmap). For critical-infrastructure operators that is a feature: no AI gets the keys to your production infrastructure.
Feature set

Everything in the current release

PIPELINEMulti-stage alert pipeline with full audit trail — every step recorded and replayable
DEDUPExact-duplicate suppression via fingerprinting
CLUSTERINGEntity-based incident clustering with severity-aware timing — critical alerts escalate instantly
MODEL ROUTINGThe best model per task — e.g. GPT-OSS for reports, a security model for alert analysis
LLMPlaybook-driven local AI analysis (Ollama, model of your choice, matched to your hardware)
SCHEMASCustomer-managed alert schemas as YAML — self-service in the dashboard
PLAYBOOKSReady-made playbooks included — versioned, adaptable as YAML, with enough context for open-source LLMs
CONTEXTAnalysis in full enterprise context — with access to internal data and your SOC processes
FOLLOW-UPSAutomated email communication with departments to enrich alerts
KNOWLEDGEKnowledge base with semantic search — upload your own reference documents
THREAT INTELIntegration with your own MISP instance + MITRE ATT&CK context
DASHBOARDAnalyst dashboard incl. quarantine (dead-letter) management and platform health
SOC CHATChat interface for natural-language search across customer data, alerts and knowledge base
CASE MANAGEMENTSimple integration with ticketing and case-management systems such as Jira, XSOAR or TheHive
MULTI-TENANTStructurally isolated data per tenant — for group structures and MSSPs
DEPLOYMENTSingle-command Docker deployment · offline/air-gapped delivery
Free resource

NIS2/BSI checklist: evaluating on-premise AI in the SOC

The key criteria for assessing AI-powered alert triage under NIS2, BSI IT-Grundschutz and critical-infrastructure requirements — compact, as a PDF. Not ready for a demo yet? Start here.