secmon-lab/warren

AI-powered security alert management that reduces noise and accelerates response time

40
/ 100
Emerging

Builds multi-agent investigation workflows orchestrated through Slack, where specialized sub-agents (BigQuery, CrowdStrike Falcon, threat intel tools) autonomously query data sources in parallel. Uses LLM-driven reflection to extract and score investigative claims as vector-embedded memories that improve triage accuracy over time. Ingests alerts via webhook/Pub/Sub/SNS, applies Rego policies for transformation and triage decisions, and surfaces findings through Slack threads with real-time agent progress traces or a React dashboard.

No Package No Dependents
Maintenance 13 / 25
Adoption 9 / 25
Maturity 9 / 25
Community 9 / 25

How are scores calculated?

Stars

96

Forks

6

Language

Go

License

Apache-2.0

Last pushed

Mar 13, 2026

Commits (30d)

0

Get this data via API

curl "https://pt-edge.onrender.com/api/v1/quality/llm-tools/secmon-lab/warren"

Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.