MITRE ATT&CK + attack graph
Technique context and graph snapshots help explain multi-stage behavior without replacing the source evidence.
Cybersecurity engineering • SOC investigation • Grounded AI
ThreatLens AI is a production-style SOC investigation platform that turns heterogeneous telemetry into detections, alerts, correlated incidents, evidence-backed cases, ATT&CK context, attack graphs, threat-hunting workflows, and grounded AI investigations.
AI never establishes authoritative incident facts. Persisted deterministic evidence remains the source of truth; retrieval and LLM analysis operate downstream with citations, grounding, and limitations.
Architecture
ThreatLens separates authoritative security facts from explanatory AI. Each layer adds context without rewriting the deterministic record beneath it.
Multi-source security events enter a normalized analysis pipeline.
Governed rules and deterministic logic establish security findings.
Alerts are grouped into incidents with persisted risk and relationships.
Analysts work with cases, notes, evidence, custody, ATT&CK, graphs, intel, and hunts.
RAG retrieves persisted evidence and governed knowledge, then generates cited structured analysis.
Technique context and graph snapshots help explain multi-stage behavior without replacing the source evidence.
External intelligence and saved hunts enrich investigation while remaining clearly distinct from observed facts.
Analyst activity, security controls, service health, metrics, and failure behavior remain visible and reviewable.
Capabilities
The project combines security analytics, case management, detection engineering, investigation tooling, operational hardening, and adaptive grounded AI.
Normalized events, governed rules, alerts, correlation, risk scoring, incident state, and detection feedback.
Analyst notes, registered evidence, SHA-256 integrity, custody history, case timelines, and auditable actions.
Governed MITRE ATT&CK mappings and correlation-backed graph snapshots for multi-stage investigations.
Feed, indicator, and hit workflows enrich investigations while preserving the boundary between external context and fact.
Saved hunts and executions support evidence-driven investigation beyond triggered detections.
Standard and Deep Analysis profiles use persisted evidence, pgvector retrieval, structured generation, citations, and fallback behavior.
Authentication, RBAC, cross-incident isolation, prompt-injection defenses, citation-spoof rejection, and strict output handling.
Container health, metrics, Prometheus/Grafana observability, queue health, recovery checks, and release-gate evidence.
Golden Demo
The accepted local Golden Demo follows a fixed heterogeneous SOC scenario through the same surfaces an analyst would use in a real investigation.
Start with the evidence-first architecture and system state.
Show the 10 normalized events, 8 alerts, and 5 correlated incidents.
Move from detection output to risk-prioritized investigation.
Review timeline, entities, correlated alerts, and persisted evidence.
Connect behaviors to governed technique context and multi-stage relationships.
Enrich the case with threat intelligence and saved investigative hunts.
Demonstrate analyst notes, evidence integrity, and chain-of-custody history.
Summarize persisted evidence, separate fact from inference, cite assessments, and state limitations.
Finish with traceability, runtime health, observability, and grounded-RAG readiness.
Engineering assurance
These are accepted local validation results from the project’s release-gate workflow. They are benchmark evidence, not guarantees about every environment.
Grounded RAG accepted on pgvector with the governed knowledge collection.
Accepted local concurrency run completed with zero request errors.
Eight simultaneous identical job submissions converged to one durable job with zero HTTP 500 responses.
Accepted local recovery run returned the complete core stack to READY after a controlled restart.
Prompt-injection handling, secret-extraction resistance, cross-incident isolation, unsupported attribution, citation-spoof rejection, overclaim hardening, strict structured output, model fallback, timeout handling, and invalid-JSON fallback were exercised during accepted hardening gates.
Technology stack
Project status
This page presents a static portfolio view of ThreatLens AI. The operational SOC application, authentication, databases, worker, model runtime, observability consoles, telemetry upload, and live AI interfaces are intentionally not exposed here.