AI-Powered Insider Threat Detection & Investigation Platform
Built an end-to-end SOC platform that detects insider threats through machine-learning behavioural analytics and guides analysts from alert to investigation, featuring MITRE ATT&CK mapping, adaptive risk scoring, and VirusTotal/Talos threat-intel enrichment.
~0
REST endpoints
~0
Tests
~0%
Coverage
0
core technologies
The platform guides an analyst from raw signal to a documented case, surfacing evidence along the way.
Risk scores adapt to behaviour and reconstruct the kill chain, so analysts see how an incident developed rather than a single static number.
Pluggable LLM, vector-store, and enrichment providers. Runs with zero network dependencies — nothing leaves the environment unless you want it to.
Role-based access control and audit logging throughout, so every action in an investigation is attributable.
Around 90 REST endpoints backed by ~190 tests at ~85% coverage. Delivered as containers via Docker Compose, Kubernetes, and Helm, with Prometheus/Grafana observability.