The Problem
SOC analysts drown in Wazuh alerts. Triaging each one means
pivoting by hand across alert history, past investigations, and
asset records — slow, repetitive, and easy to get wrong under
volume.
The Thinking
Give an autonomous agent the same read-only tools an analyst
uses and let it run the triage loop: read the alert, decide what
context it needs, call a tool, read the result, repeat — until
it reaches a verdict, with every step recorded for a human to
audit.
The Architecture
A Python/FastAPI backend polls the Wazuh Indexer on an interval;
a policy engine decides which alerts open an investigation; each
one is handed to an agentic tool-calling loop over MySQL and
OpenSearch. The LLM layer is provider-agnostic — any
OpenAI-compatible endpoint or a local Ollama model, switched with
one env variable. A Vue 3 + Pinia dashboard surfaces verdicts,
evidence, and the full action timeline.
Design Tradeoffs
The AI is deliberately walled off from all user-identifying data
— every tool query excludes it — so analyst attribution can't
bias a verdict. Hard budgets on steps, tool-result size, and
total conversation cap cost and stop indecisive loops; any
failure still records an ERROR verdict, so nothing hangs at
IN_PROGRESS.
Technical Debt & Iteration
Next: authentication and a way to cancel a running
investigation. After that, extend the tool architecture
additively — Suricata, CloudTrail, threat-intel enrichment — as
new tool classes rather than a redesign of the loop.