Security alerts, investigated by an AI agent you can watch think
AegisNexus pairs an agentic planner with retrieval over MITRE ATT&CK, two CNNs and an anomaly model. Every step is visible, every score can be checked by hand, and no response runs until a person approves it.
9agent tools
34knowledge passages
3ML models
8demo alerts
The 3D view needs WebGL. Every component is still listed below.
Drag to rotate. Select a node to read about it.
Open to cybersecurity and AI roles.
Email me3D threat lab
Pick a recorded investigation. The left scene shows how far the attack progressed through the kill chain. The right scene shows the file the way the CNN sees it. Drag either scene to rotate it.
The 3D view needs WebGL.
The 3D view needs WebGL.
What is inside
A complete, testable stack rather than a single model. Each part is small enough to read and replace.
- Agentic AI
- A tool-using planner with guardrails. It uses Claude when an API key is set and a deterministic plan otherwise. Tools are read-only, alert text is treated as untrusted, and actions are only proposed.
- Retrieval (RAG)
- MITRE ATT&CK, OWASP and incident-response playbooks indexed for search. Every report cites the passages it used.
- Two CNNs
- A 2-D network classifies files drawn as images, with Grad-CAM attention. A 1-D network classifies packet flows.
- Anomaly detection
- An Isolation Forest fitted on a benign baseline flags rare activity and names the features that deviate.
- Agent memory
- Similar past cases are recalled from the case database and shown alongside the verdict.
- Full stack
- FastAPI, SQLite, scrypt password hashing, signed tokens, roles, an audit log, streaming results and Markdown incident reports.
- Delivery
- Docker Compose with non-root, read-only containers, Prometheus metrics, and GitHub Actions running tests, CodeQL and an image scan.
- Honest limits
- The bundled models train on synthetic, harmless data, so their accuracy is an integration check. The README explains how to retrain on real datasets.