secmon-lab/warren
AI-powered security alert management that reduces noise and accelerates response time
Builds multi-agent investigation workflows orchestrated through Slack, where specialized sub-agents (BigQuery, CrowdStrike Falcon, threat intel tools) autonomously query data sources in parallel. Uses LLM-driven reflection to extract and score investigative claims as vector-embedded memories that improve triage accuracy over time. Ingests alerts via webhook/Pub/Sub/SNS, applies Rego policies for transformation and triage decisions, and surfaces findings through Slack threads with real-time agent progress traces or a React dashboard.
Stars
96
Forks
6
Language
Go
License
Apache-2.0
Category
Last pushed
Mar 13, 2026
Commits (30d)
0
Get this data via API
curl "https://pt-edge.onrender.com/api/v1/quality/llm-tools/secmon-lab/warren"
Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.
Higher-rated alternatives
fedora-copr/logdetective
Analyze logs using Language Model (LLM) and Drain template miner.
call518/LogSentinelAI
Declarative LLM-powered analyzer for security events and all types of logs. Extracts,...
DjangoPeng/GitHubSentinel
GitHub Sentinel 是专为大模型(LLMs)时代打造的智能信息检索和高价值内容挖掘 AI...
sgInnora/sentinel-reverse
AI-Powered Autonomous Binary Reverse Engineering CLI — the native reverse engine from...
SpeyTech/c-sentinel
Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis