Get AiSOC on Windows, macOS or Linux Now!
Open-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue
Get AiSOC with one command
Pick your system, reveal the step-by-step guide, copy the command, paste it into your terminal and press Enter. This command comes from the project's public source.
Not available for Windows yet.
AiSOC doesn't publish an install command for Windows anywhere we can verify, so there's nothing for us to show you. We won't invent one. It does document one for macOS and Linux — switch to that tab.
Pastes into PowerShell and installs AiSOC on your Windows machine in one step — no manual setup, no build tools. It fetches the project's own install script and runs it, which is the standard way these tools ship — worth a read if you like to know what's running.
Not available for macOS yet.
AiSOC doesn't publish an install command for macOS or Linux anywhere we can verify, so there's nothing for us to show you. We won't invent one. It does document one for Windows — switch to that tab.
Pastes into your terminal and installs AiSOC on your macOS or Linux machine in one step — no manual setup, no build tools. It fetches the project's own install script and runs it, which is the standard way these tools ship — worth a read if you like to know what's running.
How to set up AiSOC, step by step
- Press Win+R to open the Run dialog.
- Press Ctrl+V to paste the command you just copied.
- Press Enter. A PowerShell window will flash; the installer runs.
The command fetches the project's own installer, marks it unblocked, and runs it from memory. You do not need to save the file. If Windows asks "Do you want to allow this app to make changes?", click Yes — the installer needs to add itself to your PATH.
What AiSOC does
- They read the alert, its correlated siblings, entity context, and prior verdicts for the same signature
- They call typed tools — lake queries, graph traversals, enrichment lookups. The model chooses a tool and passes arguments; it never writes SQL
- Everything is logged to the Investigation Ledger: prompts, tool calls, citations, the verdict, and token cost
- A prompt is validated before it is sent. Raw logs, OCSF payloads and secret-shaped values are refused, not redacted after the fact
- Nothing executes without a human. An approver must hold the required permission tier and must not be the person who requested the action
- Not a drop-in SIEM replacement. It correlates and investigates; it does
Summarised from AiSOC's own documentation.
About AiSOC
Open-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue
| Category | AI agent |
|---|---|
| Install method | PowerShell one-liner (irm | iex) |
| Windows | documented install command available |
| macOS / Linux | documented install command available |
| Price | Subscription plans from $9/mo · free Starter tier · team and enterprise plans |
| Command verified | From project source |
| Popularity | 2.4k stars on the project's public repository |
On mobile
AiSOC is a command-line tool, so there is no phone app for it — a phone has no shell to run it in. You'll need a desktop, or a remote shell into a machine that has one.
AiSOC is developed by its own authors. This page is an independent reference; we are not affiliated with or sponsored by the project. The command shown here was reproduced from the project's public documentation — always check the project's own documentation before running anything.