AiSOC install guide

Get AiSOC on Windows, macOS or Linux Now!

Open-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue

AiSOC one-command setup card, ai agent, for Windows and macOS and Linux, 2.4k stars on the project's repository
★ 2.4k stars WindowsmacOS and Linux

Get AiSOC with one command

Pick your system, reveal the step-by-step guide, copy the command, paste it into your terminal and press Enter. This command comes from the project's public source.

PowerShell

What AiSOC does

  • They read the alert, its correlated siblings, entity context, and prior verdicts for the same signature
  • They call typed tools — lake queries, graph traversals, enrichment lookups. The model chooses a tool and passes arguments; it never writes SQL
  • Everything is logged to the Investigation Ledger: prompts, tool calls, citations, the verdict, and token cost
  • A prompt is validated before it is sent. Raw logs, OCSF payloads and secret-shaped values are refused, not redacted after the fact
  • Nothing executes without a human. An approver must hold the required permission tier and must not be the person who requested the action
  • Not a drop-in SIEM replacement. It correlates and investigates; it does

Summarised from AiSOC's own documentation.

About AiSOC

Open-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue

CategoryAI agent
Install methodPowerShell one-liner (irm | iex)
Windowsdocumented install command available
macOS / Linuxdocumented install command available
PriceSubscription plans from $9/mo · free Starter tier · team and enterprise plans
Command verifiedFrom project source
Popularity2.4k stars on the project's public repository

On mobile

AiSOC is a command-line tool, so there is no phone app for it — a phone has no shell to run it in. You'll need a desktop, or a remote shell into a machine that has one.

AiSOC is developed by its own authors. This page is an independent reference; we are not affiliated with or sponsored by the project. The command shown here was reproduced from the project's public documentation — always check the project's own documentation before running anything.