Get AiSOC on Windows, macOS or Linux Now!
Open-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue
Get AiSOC with one command
Pick your system, reveal the step-by-step guide, copy the command, paste it into your terminal and press Enter. This command comes from the project's public source.
Not available for Windows yet.
AiSOC doesn't publish an install command for Windows anywhere we can verify, so there's nothing for us to show you. We won't invent one. It does document one for macOS and Linux — switch to that tab.
Pastes into PowerShell and installs AiSOC on your Windows machine in one step — no manual setup, no build tools. It fetches the project's own install script and runs it, which is the standard way these tools ship — worth a read if you like to know what's running.
Not available for macOS yet.
AiSOC doesn't publish an install command for macOS or Linux anywhere we can verify, so there's nothing for us to show you. We won't invent one. It does document one for Windows — switch to that tab.
Pastes into your terminal and installs AiSOC on your macOS or Linux machine in one step — no manual setup, no build tools. It fetches the project's own install script and runs it, which is the standard way these tools ship — worth a read if you like to know what's running.
How to set up AiSOC, step by step
On Windows, open PowerShell (press Win, type PowerShell, hit Enter) and paste the command. On macOS or Linux, open Terminal — on a Mac it's in Applications ▸ Utilities, or press Cmd+Space and type Terminal — and paste the command there.
Run AiSOC --help to see the available commands, and
AiSOC --version to confirm the install worked. If your shell complains about
permissions, that project usually documents a corrected command on its own site.
This asks PowerShell to download a small installer script from the project, then execute it in memory. Nothing is saved to disk. The script is the project's own, but it's worth reading it first — that's why there's a note above.
What AiSOC does
- They read the alert, its correlated siblings, entity context, and prior verdicts for the same signature
- They call typed tools — lake queries, graph traversals, enrichment lookups. The model chooses a tool and passes arguments; it never writes SQL
- Everything is logged to the Investigation Ledger: prompts, tool calls, citations, the verdict, and token cost
- A prompt is validated before it is sent. Raw logs, OCSF payloads and secret-shaped values are refused, not redacted after the fact
- Nothing executes without a human. An approver must hold the required permission tier and must not be the person who requested the action
- Not a drop-in SIEM replacement. It correlates and investigates; it does
Summarised from AiSOC's own documentation.
About AiSOC
Open-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue
| Category | AI agent |
|---|---|
| Install method | PowerShell one-liner (irm | iex) |
| Windows | documented install command available |
| macOS / Linux | documented install command available |
| Price | Free and open source |
| Command verified | From project source |
| Popularity | 2.4k stars on the project's public repository |
On mobile
AiSOC is a command-line tool, so there is no phone app for it — a phone has no shell to run it in. You'll need a desktop, or a remote shell into a machine that has one.
AiSOC is developed by its own authors. This page is an independent reference; we are not affiliated with or sponsored by the project. The command shown here was reproduced from the project's public documentation — always check the project's own documentation before running anything.