Agentic SOC
AI-driven SIEM alert triage platform built under hackathon constraints.
AS
Agentic SOC
Case study visual placeholder
Architecture flow
2 layersProblem
Security teams face noisy alert queues where triage, prioritization, and remediation planning consume valuable response time.
My Role
Helped design and build the AI triage flow, security workflow framing, and full-stack prototype behavior.
Solution
Security alerts enter an agentic triage layer that classifies severity, reasons about likely causes, and proposes remediation steps for analyst review.
Stack
Case study
Problem
Security teams face noisy alert queues where triage, prioritization, and remediation planning consume valuable response time.
Proof signal
Black Pearl 24-hour Cybersecurity Hackathon · 1st place
My Role
Helped design and build the AI triage flow, security workflow framing, and full-stack prototype behavior.
Core product work
- Alert triage
- Severity classification
- Remediation suggestions
Solution
Security alerts enter an agentic triage layer that classifies severity, reasons about likely causes, and proposes remediation steps for analyst review.
Security alerts flow into a triage layer where agentic LLM workflows classify severity, reason about likely causes, suggest remediation steps, and coordinate follow-up actions.
Architecture Highlights
Alert ingestion and severity classification
Agentic reasoning over likely causes
Remediation suggestions for analyst review
Challenges and Tradeoffs
- Designing useful AI assistance while keeping analysts in control.
- Making security reasoning legible in a short-build context.
Impact / Outcome
- Built a working security-tool prototype under 24-hour hackathon constraints.
- Won 1st place at the Black Pearl Cybersecurity Hackathon, as represented in existing portfolio data.
Learnings
- Agentic security tools need clear escalation and review boundaries.
- Triage workflows benefit from concise reasoning traces.
Keep exploring