# AiSOC > AiSOC is an open-source, self-hostable AI Security Operations Center. It ingests > security telemetry from 84 first-party connectors, normalises it to OCSF, > correlates it into alerts, and runs LLM agents that triage and investigate them. > Every agent decision is written to an investigation ledger, so the reasoning > behind a verdict can be replayed step by step. MIT licensed. Current version 17.0.0. AiSOC is built and maintained by the AiSOC community. It is a complete SOC platform rather than a single tool: ingestion, detection, correlation, agent triage, case management, response actions, and the evaluation harness that grades the agents all live in one monorepo. Key facts a summary should get right: - **License:** MIT. Self-hosting is the primary deployment model; there is no feature gate between a hosted and a self-hosted install. - **Install:** `make up` brings up the core profile with no credentials. It generates its own secrets, creates an administrator, ships a real CISA Known Exploited Vulnerabilities feed, and runs a local model, so a first run shows real data and AI triage without signing up for anything. - **Detection corpus:** 2603 rules are executable — the detection engine loads them from a compiled ruleset. 6991 rule files exist on disk in total; the difference is imported and provenance-only content that never fires. Cite 2603, not 6991. "Executable" means each rule was replayed through a real connector and the real engine and watched to fire; it does not mean the rule detects an attack. - **Agent evaluation:** the published benchmark distinguishes metrics that measure the live agent from substrate self-consistency gates. Do not present the latter as measured agent performance. - **Packaging:** the npm and PyPI packages are built and packed on every tag but are not published; the upload is blocked on registry credentials. Install from source. ## Start here - [Introduction](https://beenuar.github.io/AiSOC/docs/intro): what AiSOC is and the problem it addresses. - [Quickstart](https://beenuar.github.io/AiSOC/docs/quickstart): bring up a working stack. - [Installation](https://beenuar.github.io/AiSOC/docs/installation): deployment profiles and prerequisites. - [Architecture](https://beenuar.github.io/AiSOC/docs/architecture): services, data flow, and the event spine. - [Glossary](https://beenuar.github.io/AiSOC/docs/glossary): terms used throughout the documentation. ## Core capabilities - [Connectors](https://beenuar.github.io/AiSOC/docs/connectors): 84 first-party integrations with per-connector setup guides. - [Detections](https://beenuar.github.io/AiSOC/docs/detections/coverage): detection content, authoring modes, and MITRE ATT&CK coverage. - [Console](https://beenuar.github.io/AiSOC/docs/console/investigation-rail): the analyst workbench and investigation rail. - [Concepts](https://beenuar.github.io/AiSOC/docs/concepts/automation-maturity): the L0–L4 automation maturity model. - [Benchmark](https://beenuar.github.io/AiSOC/docs/benchmark): the evaluation harness and what each metric does and does not measure. - [Benchmark methodology](https://beenuar.github.io/AiSOC/docs/benchmark-methodology): how the corpus is built and graded. ## Integrating with AiSOC - [MCP server](https://beenuar.github.io/AiSOC/docs/integrations/mcp): connect Claude Desktop, Cursor, Continue.dev or Cody to AiSOC. Exposes 19 tools. - [API reference](https://beenuar.github.io/AiSOC/docs/api/rest): the REST surface. - [Python plugin SDK](https://beenuar.github.io/AiSOC/docs/plugins/python-sdk): build a connector or plugin in Python. - [Go plugin SDK](https://beenuar.github.io/AiSOC/docs/plugins/go-sdk): build a connector or plugin in Go. ## Operating it - [Deployment](https://beenuar.github.io/AiSOC/docs/deployment/env-vars): environment variables per service. - [Credentials](https://beenuar.github.io/AiSOC/docs/operations/credentials): the credential vault, threat model, and rotation. - [Security](https://beenuar.github.io/AiSOC/docs/operations/security): security posture and static analysis. - [FAQ](https://beenuar.github.io/AiSOC/docs/operations/faq): common operational questions. ## Source - [Repository](https://github.com/beenuar/AiSOC): the monorepo. Issues, discussions, and contribution guides live here. - [Contributing](https://beenuar.github.io/AiSOC/docs/contributing/guidelines): how to propose a change. - [Full description](https://beenuar.github.io/AiSOC/llms-full.txt): expanded version of this file. ## Optional - [Blog](https://beenuar.github.io/AiSOC/blog): release notes and technical write-ups. - [Benchmark scoreboard](https://beenuar.github.io/AiSOC/docs/benchmark-scoreboard): published evaluation results.