Cybersecurity engineering • SOC investigation • Grounded AI

Deterministic evidence first.
AI second.

ThreatLens AI is a production-style SOC investigation platform that turns heterogeneous telemetry into detections, alerts, correlated incidents, evidence-backed cases, ATT&CK context, attack graphs, threat-hunting workflows, and grounded AI investigations.

Core invariant

AI never establishes authoritative incident facts. Persisted deterministic evidence remains the source of truth; retrieval and LLM analysis operate downstream with citations, grounding, and limitations.

Deterministic analytics RBAC & authenticated workflows Evidence integrity MITRE ATT&CK Grounded RAG Auditability

Architecture

One evidence chain from telemetry to investigation

ThreatLens separates authoritative security facts from explanatory AI. Each layer adds context without rewriting the deterministic record beneath it.

01

Telemetry

Multi-source security events enter a normalized analysis pipeline.

02

Detections

Governed rules and deterministic logic establish security findings.

03

Correlation

Alerts are grouped into incidents with persisted risk and relationships.

04

Investigation

Analysts work with cases, notes, evidence, custody, ATT&CK, graphs, intel, and hunts.

05

Grounded AI

RAG retrieves persisted evidence and governed knowledge, then generates cited structured analysis.

Context rail

MITRE ATT&CK + attack graph

Technique context and graph snapshots help explain multi-stage behavior without replacing the source evidence.

Investigation rail

Threat intelligence + hunting

External intelligence and saved hunts enrich investigation while remaining clearly distinct from observed facts.

Governance rail

Audit + observability

Analyst activity, security controls, service health, metrics, and failure behavior remain visible and reviewable.

Capabilities

Built like a SOC platform, not a chatbot demo

The project combines security analytics, case management, detection engineering, investigation tooling, operational hardening, and adaptive grounded AI.

Deterministic detection engineering

Normalized events, governed rules, alerts, correlation, risk scoring, incident state, and detection feedback.

Case & evidence operations

Analyst notes, registered evidence, SHA-256 integrity, custody history, case timelines, and auditable actions.

ATT&CK & attack graphs

Governed MITRE ATT&CK mappings and correlation-backed graph snapshots for multi-stage investigations.

Threat intelligence

Feed, indicator, and hit workflows enrich investigations while preserving the boundary between external context and fact.

Threat hunting

Saved hunts and executions support evidence-driven investigation beyond triggered detections.

Grounded adaptive AI

Standard and Deep Analysis profiles use persisted evidence, pgvector retrieval, structured generation, citations, and fallback behavior.

Security boundaries

Authentication, RBAC, cross-incident isolation, prompt-injection defenses, citation-spoof rejection, and strict output handling.

Operational visibility

Container health, metrics, Prometheus/Grafana observability, queue health, recovery checks, and release-gate evidence.

Golden Demo

A recruiter-ready incident story with real persisted evidence

The accepted local Golden Demo follows a fixed heterogeneous SOC scenario through the same surfaces an analyst would use in a real investigation.

  1. 01

    Overview

    Start with the evidence-first architecture and system state.

  2. 02

    Current analysis

    Show the 10 normalized events, 8 alerts, and 5 correlated incidents.

  3. 03

    Incident queue

    Move from detection output to risk-prioritized investigation.

  4. 04

    Case details

    Review timeline, entities, correlated alerts, and persisted evidence.

  5. 05

    ATT&CK + graph

    Connect behaviors to governed technique context and multi-stage relationships.

  6. 06

    Intel + hunting

    Enrich the case with threat intelligence and saved investigative hunts.

  7. 07

    Evidence + custody

    Demonstrate analyst notes, evidence integrity, and chain-of-custody history.

  8. 08

    Grounded AI

    Summarize persisted evidence, separate fact from inference, cite assessments, and state limitations.

  9. 09

    Audit + health

    Finish with traceability, runtime health, observability, and grounded-RAG readiness.

Engineering assurance

Measured behavior, not just feature claims

These are accepted local validation results from the project’s release-gate workflow. They are benchmark evidence, not guarantees about every environment.

1,007

Indexed knowledge chunks

Grounded RAG accepted on pgvector with the governed knowledge collection.

160 / 0

Concurrent API requests / errors

Accepted local concurrency run completed with zero request errors.

8 → 1

Idempotent race convergence

Eight simultaneous identical job submissions converged to one durable job with zero HTTP 500 responses.

≈31.9s

Core restart to ready

Accepted local recovery run returned the complete core stack to READY after a controlled restart.

Adversarial AI/RAG validation

Prompt-injection handling, secret-extraction resistance, cross-incident isolation, unsupported attribution, citation-spoof rejection, overclaim hardening, strict structured output, model fallback, timeout handling, and invalid-JSON fallback were exercised during accepted hardening gates.

Technology stack

Production-style components across the SOC workflow

BackendPython • FastAPI • SQLAlchemy
FrontendReact • Vite • TypeScript • Nginx
DataPostgreSQL • pgvector • Redis
AI / RAGQwen • Ollama • embeddings • structured generation
SOC contextMITRE ATT&CK • correlation • threat intel • hunting
OperationsDocker Compose • Prometheus • Grafana • exporters
SecurityRBAC • JWT • audit • evidence integrity • policy gates
DeliveryPytest • CodeQL • Gitleaks • Trivy • SBOM • CI/CD

Project status

Golden Demo accepted. Public showcase sanitized by design.

This page presents a static portfolio view of ThreatLens AI. The operational SOC application, authentication, databases, worker, model runtime, observability consoles, telemetry upload, and live AI interfaces are intentionally not exposed here.

No login form No API calls No analytics No cookies No telemetry collection No live AI