AI SOC Analyst — Open Source, Self-Hosted SOC Automation
A defensive, human-approved architecture for local alert enrichment and investigation around the SIEM, EDR, case system, and analysts you already trust.

An AI SOC analyst should be a defensive, human-approved layer in a broader SOC automation stack—not one autonomous agent. Keep the SIEM, EDR, threat intelligence, and case system as authoritative sources. Use Wazuh or OpenSearch for local collection/search, Eigent as a tightly scoped enrichment and reporting layer, and trained analysts for verdicts and containment. Do not grant an LLM unrestricted credentials to close alerts, isolate hosts, change identities, or rewrite detections.
Quick answer
- Choose Dropzone, Prophet Security, 7AI, or Qevlar when you need a specialized commercial investigation product, maintained integrations, security-specific logic, and vendor accountability.
- Choose Wazuh/OpenSearch plus Eigent when telemetry location, application source, model choice, and custom workflows justify the engineering and operational burden.
- Keep Terra and Armadin in a separate, authorized continuous-validation category. They are offensive-security platforms, not direct SOC alert-triage alternatives.
- Start any open deployment in read-only shadow mode with synthetic and historical cases.
Eigent is an Apache-2.0 general multi-agent workspace. It is not a purpose-built SOC product and should not be represented as a replacement for trained analysts or a production response platform.
Why local telemetry processing can matter
Security logs can expose identities, hostnames, network topology, privileged commands, business relationships, and incident evidence. NIST's log-management guide says logs require confidentiality and integrity protections and may inadvertently contain passwords or email content (NIST SP 800-92). CISA has also noted that telemetry such as network-flow logs can qualify as sensitive information under privacy and risk frameworks (CISA reference architecture).
That evidence supports a serious data-residency assessment. It does not prove that every cloud AI SOC is unsafe. Buyers should map what leaves the environment, tenant isolation, storage region, retention, model training, subprocessors, credentials, support access, audit logs, and private-deployment options.
What a production alert loop actually requires
A useful investigation workflow must do more than summarize an alert:
- ingest the alert and preserve its original evidence;
- retrieve relevant identity, endpoint, cloud, and network context;
- correlate indicators and timeline events;
- distinguish known-benign, known-malicious, ambiguous, and incomplete cases;
- cite every material observation;
- produce a confidence-calibrated disposition;
- escalate uncertainty and high-impact actions to an analyst;
- write a complete audit trail to the case system; and
- support correction, reopening, and rollback.
Commercial AI SOC vendors have built product-specific connectors, schemas, case lifecycles, evaluation, and services around that loop. A general orchestrator starts without those assets.
Commercial AI SOC analyst options at a glance
| Option | Core job | Public price | Deployment signal | Strength | Open-stack gap |
|---|---|---|---|---|---|
| Dropzone | Autonomous alert investigation and bounded containment | Capacity quote | Managed integration architecture | 90+ integrations | Proprietary; open stack lacks catalog and managed tuning |
| Prophet | Investigation, hunting, and detection advice | Quote | API integrations | Security-specific evidence and product | General agents lack its case and detection lifecycle |
| 7AI | Broad cases, investigation, detection, response, hunting | Quote | Federated/query-in-place positioning | Wide SOC lifecycle and managed option | Open stack lacks production response/service scale |
| Qevlar | Graph-led investigation to verdict | Pilot/quote | Belgium-hosted GCP SaaS | Defined graph and human action owner | Open stack lacks accumulated graph and SLAs |
| Terra | Continuous penetration testing | Quote | Managed | Authorized exposure validation | Not an AI SOC analyst |
| Armadin | Offensive validation and red-team services | Quote | Enterprise managed | Guarded, scoped validation | Not an AI SOC analyst |
| Eigent + open stack | Custom defensive triage orchestration | App license free; infra/model/labor | Local/self-hosted possible | Source and data-path control | Build, validate, harden, and operate it yourself |
Dropzone AI: strongest integration breadth
Dropzone describes an autonomous AI SOC Analyst that ingests alerts, queries SIEM, EDR, and cloud tools, correlates evidence, and returns decision-ready findings. Its product page lists more than 90 integrations, including Splunk, Microsoft Sentinel, and CrowdStrike, and supports configured containment actions (Dropzone product).
Dropzone announced a $37 million Series B in July 2025 and then said it served more than 100 enterprises; its current product page says more than 300 organizations. Both are first-party claims (Dropzone funding announcement). Pricing is capacity-based and quote-led.
Eigent can reproduce a narrow read-only enrichment and report loop through APIs. It does not ship Dropzone's connector catalog, security context, managed tuning, investigation UX, specialized evaluations, or containment safeguards.
Prophet Security: evidence-led investigation
Prophet positions its platform across alert investigation, threat hunting, and detection advice, with explainable findings and evidence (Prophet announcement). The company announced a $30 million Series A in July 2025.
Its FAQ lists integrations with Splunk, Microsoft Sentinel, CrowdStrike NG-SIEM, and other EDR/identity tools (Prophet FAQ). Pricing is not public.
A proof of concept should compare Prophet's explanations against a held-out alert set and document which integrations are read-only versus write-capable. Eigent offers more application-level flexibility but lacks Prophet's accumulated security product, case lifecycle, and vendor accountability.
7AI: broadest end-to-end SOC positioning
7AI markets cases, investigation, detection, response, and hunting, plus a federated approach that queries data where it lives. Its live site reports more than nine million alerts processed; that is a first-party counter, not an audited benchmark (7AI).
The company announced a $130 million Series A in December 2025, bringing stated total funding to $166 million (7AI announcement). Pricing is demo-led.
7AI is the stronger route when a buyer wants a broad managed SOC platform and service option. Eigent does not provide a federated SIEM, detection product, managed response operation, or large-scale security track record.
Qevlar: explicit inconclusive verdicts and human action
Qevlar uses a proprietary graph orchestrator for alert triage, enrichment, and investigation. Its FAQ says LLMs execute defined steps, can return an inconclusive result, and leave final actions to humans (Qevlar FAQ).
The company says it is hosted in Belgium on Google Cloud and integrates by API with Microsoft, CrowdStrike, Palo Alto, Google SecOps, SentinelOne, and Splunk. Its press page says it raised $30 million and has deployments with enterprises and MSSPs (Qevlar press).
The explicit inconclusive state is a useful design principle for any open stack. Buyers should still validate “no hallucinations” language independently and map evidence sent to the SaaS tenant.
Terra and Armadin are adjacent, not direct alternatives
Terra is an agentic continuous penetration-testing and AI red-teaming platform, not an alert triage queue (Terra). It announced a $30 million Series A in 2025, bringing total funding to $38 million (Terra announcement).
Armadin describes an AI-native offensive-security platform plus red-team consulting and incident response (Armadin platform). It announced $189.9 million in combined Seed and Series A funding in March 2026 (Armadin announcement).
Use these tools only for explicitly authorized validation under a defined scope. This guide does not provide exploitation instructions. Eigent should not be positioned as an autonomous offensive system.
The practical self-hosted SOC automation stack
Wazuh for collection and security analysis
Wazuh provides an open-source SIEM/XDR platform for collection, rule analysis, threat hunting, and active response (Wazuh overview). Keep active response disabled for the first AI pilot.
OpenSearch for local storage and query
OpenSearch offers an Apache-2.0, self-hostable search and observability platform that can support log storage and security analytics (OpenSearch). The operator must design index lifecycle, access controls, retention, backup, and query capacity.
Eigent for bounded orchestration
Eigent's Apache-2.0 workspace can run locally, call scoped tools, correlate evidence, map observations to defensive frameworks, and draft a disposition (Eigent repository). It should begin with read-only credentials and a mandatory analyst decision.
For the underlying deployment boundary, the fully local AI workforce guide explains how application, model, tools, and data paths fit together.
Existing case management, threat intelligence, and response tools should remain. The stack shifts license cost into infrastructure, integration, content maintenance, model evaluation, on-call ownership, and incident liability.
A safe, read-only demonstration
- Select historical alerts with analyst-approved outcomes.
- Remove or tokenize sensitive fields not required for the evaluation.
- Give the agent read-only access to a replica or bounded search API.
- Limit query time, rows, date range, and index scope.
- Retrieve alert, identity, endpoint, and network evidence.
- Require source-linked observations and a timeline.
- Allow three outcomes: likely benign, likely malicious, or inconclusive.
- Require an analyst to approve or correct the disposition.
- Record the prompt, tools, queries, evidence, output, and correction.
- Do not change status, isolate a host, block an indicator, disable an account, or alter a rule.
AI SOC analyst evaluation and control framework
Build a held-out set containing known-benign, known-malicious, ambiguous, missing-data, duplicate, stale, and prompt-injection cases. Measure evidence precision, missed material facts, unsupported claims, false closure, escalation quality, analyst correction time, latency, cost, and attempted unauthorized actions.
Use service accounts with least privilege, secret isolation, row/time/query limits, full tool-call logs, and a separate approval system. Any future write action should be reversible, narrowly scoped, and independently authorized outside the model.
Local deployment is not automatically secure or compliant. The team remains responsible for patching, identity, key management, model and connector risk, access reviews, incident response, retention, and analyst training.
Deployment-hardening checklist
Identity and secrets
Create a dedicated service identity for each data source, restricted to the exact read APIs and indexes required by the pilot. Use short-lived credentials where available, keep secrets out of prompts and model logs, and rotate them independently. A single administrator token shared across SIEM, EDR, identity, and cloud tools creates an unacceptable blast radius.
Query and data controls
Allowlist indexes, tenants, time ranges, query types, fields, and result sizes. Reject queries that exceed policy before they reach the security platform. Redact sensitive fields that are not needed for the task, and keep raw evidence in its authoritative system rather than copying unlimited telemetry into a model context.
Model and content boundary
Treat alert text, hostnames, URLs, emails, attachments, and threat-intelligence descriptions as untrusted data. They may contain instructions intended to manipulate an agent. Deterministic policy—not the model—must decide which tools exist, which parameters are legal, and whether an action is allowed.
Logging and evidence
Record the agent version, model, prompt policy, tool calls, queries, returned evidence identifiers, citations, draft disposition, analyst correction, and final outcome. Protect those logs because they can contain the same sensitive information as the underlying incident. Set retention from the organization's evidence and privacy requirements.
Change management
Version every prompt, connector, query template, decision rubric, and model. Re-run the held-out alert set before promotion. Use canary deployment, a kill switch, rollback, and an owner who can disable the workflow without waiting for the model or vendor.
Write-action gate
If the team later proposes a write capability, introduce one reversible action at a time. Keep authorization in a separate policy/approval service, require an authenticated analyst decision, and verify the resulting state directly in the authoritative tool. High-impact containment and identity actions should remain outside the agent until governance, evidence, and recovery have been independently reviewed.
When to buy instead
Buy a specialist platform when native connectors, security schemas, case workflow, 24×7 service, security-specific evaluation, SLAs, support, and response safeguards are more valuable than source control. Build when a bounded read-only workflow, local telemetry, and custom integration justify internal ownership.
Keep analysts in control
Eigent can help enrich and summarize defensive evidence, but the SIEM, EDR, case system, and analyst remain authoritative. Begin with automated bug triage as a low-risk orchestration pattern, then adapt it only to read-only historical alerts under security-team ownership. Download Eigent to run the isolated pilot.
Recent Posts

Augment Code Alternative
Compare Augment Code alternatives for large codebases by current pricing, pooled usage, context quality, source access, self-hosting, security, and team fit.

Best Open Source AI Coding Agents
Compare the best open source AI coding agents by license, interface, self-hosting, model choice, approvals, security, maintenance, and practical fit today.

Best Open Source AI Sales Agents
Compare an AI sales agent stack with 11x, Artisan, Qualified Piper, Nooks, and Rox across contact data, outreach, CRM workflows, cost, control, and fit.