TiltedLunar123/triagelens: AI-assisted SOC alert and log triage: parses security logs, maps activity to MITRE ATT&CK, scores risk, and writes analyst-style triage reports. React + TypeScript. (opens in new tab)
i've been building a thing called triagelens. you give it security logs, it finds the suspicious stuff, maps it to mitre att&ck, scores the whole run 0-100, and writes a short analyst-style report. but the feature i keep coming back to isn't a detection. it's that you can run the entire thing with no api key, no account, and no config file. sounds small. it took me two wrong turns to get there. here's what kicked it off. i showed an early build to a friend who's also grinding through security...
Read the original article