Cybersecurity SOC RAG RAG Tools
Tools for security operations center (SOC) automation, incident response, and threat analysis using RAG. Focuses on SIEM integration, log analysis, security questionnaires, and cyber threat intelligence. Does NOT include general security tools without RAG, non-SOC cybersecurity applications, or drone/network-level security systems without SOC operations context.
There are 87 cybersecurity soc rag tools tracked. 2 score above 50 (established tier). The highest-rated is LLAMATOR-Core/llamator at 58/100 with 201 stars and 275 monthly downloads.
Get all 87 projects as JSON
curl "https://pt-edge.onrender.com/api/v1/datasets/quality?domain=rag&subcategory=cybersecurity-soc-rag&limit=20"
Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.
| # | Tool | Score | Tier |
|---|---|---|---|
| 1 |
LLAMATOR-Core/llamator
Red Teaming python-framework for testing chatbots and GenAI systems. |
|
Established |
| 2 |
kelkalot/simpleaudit
Allows to red-team your AI systems through adversarial probing. It is... |
|
Established |
| 3 |
sleeepeer/PoisonedRAG
[USENIX Security 2025] PoisonedRAG: Knowledge Corruption Attacks to... |
|
Emerging |
| 4 |
SecurityClaw/SecurityClaw
A modular, skill-based autonomous Security Operations Center (SOC) agent... |
|
Emerging |
| 5 |
JuliusHenke/autopentest
CLI enabling more autonomous black-box penetration tests using Large... |
|
Emerging |
| 6 |
rohansx/cloakpipe
Privacy middleware for LLM & RAG pipelines - consistent pseudonymization,... |
|
Emerging |
| 7 |
AnubhavChoudhery/cybersec-scanner
A comprehensive, modular security scanning toolkit for detecting secrets,... |
|
Emerging |
| 8 |
AI-secure/AgentPoison
[NeurIPS 2024] Official implementation for "AgentPoison: Red-teaming LLM... |
|
Emerging |
| 9 |
taladari/rag-firewall
Client-side retrieval firewall for RAG systems — blocks prompt injection and... |
|
Emerging |
| 10 |
CaviraOSS/SecuPrompt
Protect your AI from Prompt Injection |
|
Emerging |
| 11 |
olegnazarov/rag-security-scanner
RAG/LLM Security Scanner identifies critical vulnerabilities in AI-powered... |
|
Emerging |
| 12 |
olegnazarov/llm-fortress
Enterprise AI Security Platform - Real-time firewall protection for LLM... |
|
Emerging |
| 13 |
toxy4ny/redteam-ai-benchmark
Red Team AI Benchmark: Evaluating Uncensored LLMs for Offensive Security |
|
Emerging |
| 14 |
clab60917/RAG-LLM-SOC_analyst
SOC Analyst Level 1 Replacement using RAG LLM |
|
Emerging |
| 15 |
LauJames/Topic-FlipRAG
[USENIX Security 2025] Topic-FlipRAG: Topic-Orientated Adversarial Opinion... |
|
Experimental |
| 16 |
cisco-ai-defense/adversarial-hubness-detector
Scanner for adversarial hubs in RAG and vector databases |
|
Experimental |
| 17 |
Curtis-Thomas/junction-sentinel
Junction Sentinel is a secure, multi-agent system designed to address drone... |
|
Experimental |
| 18 |
Har1sh-k/SecLint
A Python-based AI agent for detecting insecure code patterns in Python... |
|
Experimental |
| 19 |
StruggleY/Fo-Sentinel-Agent
企业级安全智能研判平台-多 Agent 协同与 Supervisor-Worker 深度思考架构驱动,集成全链路... |
|
Experimental |
| 20 |
jone0709/Securing-AI-ML-Maturity-Model
AI Operations Security Maturity Model and toolkit to secure AI/ML... |
|
Experimental |
| 21 |
HydroXai/pii-masker
PII Masker is an open-source tool for protecting sensitive data by... |
|
Experimental |
| 22 |
byerlikaya/Septum
Privacy‑first AI middleware that anonymizes PII locally and only sends... |
|
Experimental |
| 23 |
scthornton/semantic-chameleon
Dual-Stage Temporal Poisoning Attack on RAG Systems |
|
Experimental |
| 24 |
DonkeyKing01/SCSI-SLM-EV-Design
Official implementation of the SCSI-SLM framework for translating EV... |
|
Experimental |
| 25 |
prompt-security/RAG_Poisoning_POC
Stealthy Prompt Injection and Poisoning in RAG Systems via Vector Database Embeddings |
|
Experimental |
| 26 |
Jeremy0219/cloudguard-rag
AI-powered RAG pipeline for querying cloud security frameworks using Azure... |
|
Experimental |
| 27 |
Zyrabit-tech/zyrabit-SLM
Sovereign AI Infrastructure for Enterprise RAG. Zero-Trust PII Sanitization,... |
|
Experimental |
| 28 |
javidahmed64592/cyber-query-ai
Ollama-powered cybersecurity assistant for ethical penetration testing and... |
|
Experimental |
| 29 |
McKern3l/RAGdrag-labs
Test lab for RAGdrag — vulnerable RAG target, sample results, and test suite |
|
Experimental |
| 30 |
Cyberfortress-Labs/Cyberfortress-Intelligent-SOC-Ecosystem
An Intelligent SOC Ecosystem that integrates SIEM, SOAR, and SmartXDR to... |
|
Experimental |
| 31 |
Kartik-Katkar/Malicious-Prompt-Filter-for-RAG-Database
GitHub repository for a tool that detects and filters malicious prompts... |
|
Experimental |
| 32 |
lowwkezer/shannon
🛡️ Automate web app pentesting with AI to find real exploits before... |
|
Experimental |
| 33 |
luq12-growagarden/Adversarial-Detection-Engineering-Framework
🔍 Enhance detection accuracy by identifying and mitigating False Negatives... |
|
Experimental |
| 34 |
Kelvin295/cloakpipe
Protect LLM data by detecting, masking, and unmasking personal information... |
|
Experimental |
| 35 |
julienmerconsulting/rag-poisoning-demo
🧪 5 faux documents suffisent pour corrompre 80% des réponses d'un RAG. Démo... |
|
Experimental |
| 36 |
112ab0058/ray
PromptGuard Research | AI Security & RAG Defense |
|
Experimental |
| 37 |
45ck/llm-agent-security-skills
LLM and agent security skill pack for prompt injection, tool permissions,... |
|
Experimental |
| 38 |
sandipkatel/Unified-InfoSec-QnA-Assistant
A full-stack RAG based AI-powered system to help InfoSec teams efficiently... |
|
Experimental |
| 39 |
musabdulai-io/llm-production-safety-scanner
CLI tool for testing production safety controls in LLM/RAG apps - prompt... |
|
Experimental |
| 40 |
mishabar410/RAGLeakLab
Deterministic security testing for RAG pipelines: measure retrieval-induced... |
|
Experimental |
| 41 |
deconvolute-labs/benchmarks
Reproducible security benchmarking for the Deconvolute SDK and AI system... |
|
Experimental |
| 42 |
Privalyse/privalyse-mask
Semantic PII Masking & Anonymization for LLMs (RAG). GDPR-compliant,... |
|
Experimental |
| 43 |
uuluul/AI-autonomous-SOC
AI-powered autonomous SOC pipeline featuring hybrid log ingestion,... |
|
Experimental |
| 44 |
scthornton/ai-security-analyst-rag
Build an AI Security Analyst Assistant with RAG! LEARN FROM SCRATCH |
|
Experimental |
| 45 |
MartinMilevVenelinova/rag-copilot-it-security
Internal RAG copilot for Helpdesk/SecOps: cited answers, strict “not found”... |
|
Experimental |
| 46 |
bx0-0/CyberVisionAI
Cyber Vision AI is an award-winning, open-source AI assistant for... |
|
Experimental |
| 47 |
SidereusHu/RAG-Shield
Defense-in-depth security framework for RAG systems: poison detection,... |
|
Experimental |
| 48 |
ayinedjimi/SOC-Assistant
RAG-Powered SOC Assistant - By Ayi NEDJIMI |
|
Experimental |
| 49 |
Laav0808/cybersecurity-rag-assistant
RAG-powered cybersecurity knowledge assistant using LangChain, Weaviate, and... |
|
Experimental |
| 50 |
Cyberfortress-Labs/cyberfortress-labs.github.io
A unified intelligent SOC ecosystem where SIEM, SOAR, OpenXDR, Threat... |
|
Experimental |
| 51 |
HyeonjeongHa/MM-PoisonRAG
Official PyTorch implementation of "MM-PoisonRAG: Disrupting Multimodal RAG... |
|
Experimental |
| 52 |
gbikram/ThreatIntelRAG
Experimental RAG that consumes Cyber Security articles via RSS |
|
Experimental |
| 53 |
SecureAI-Team/asb-security-schema
A unified security event schema for LLM, RAG, and Agent applications. |
|
Experimental |
| 54 |
gypark94/RAGprompt
Anomaly detection using RAG |
|
Experimental |
| 55 |
enesdanis00/theo-hide
🔒 Protect sensitive files during streams with Theo Hide, ensuring no... |
|
Experimental |
| 56 |
Dhy4n-117/AI_SOC_Analyst
A privacy-first, local AI assistant for SOC analysts and threat hunters.... |
|
Experimental |
| 57 |
Sumukha87/aia-auditor
AI RAG system for cloud security auditing — Qwen 2.5 7B via Ollama, Qdrant... |
|
Experimental |
| 58 |
ducwuyy/DocSentinel
Detect security risks in documents and questionnaires using automated... |
|
Experimental |
| 59 |
HameshTiwari/Secure-AI-Financial-Auditor
Enterprise GenAI framework implementing architectural guardrails and PII... |
|
Experimental |
| 60 |
thiagov21/squad-sentinela
AI workflow automation platform using agents and RAG to transform... |
|
Experimental |
| 61 |
kikiuuw/CVE-2025-68921
🔍 Identify and understand the local privilege escalation vulnerability... |
|
Experimental |
| 62 |
404godd/CVE-2026-20841-PoC
🛠 Demonstrate remote code execution in Windows Notepad versions below... |
|
Experimental |
| 63 |
hamzamalik3461/CVE-2026-20841
🛠 Demonstrate remote code execution in Windows Notepad via markdown links... |
|
Experimental |
| 64 |
ChangYeongJeong1103/prompt-injection-gatekeeper
Multi-stage prompt injection detection pipeline for RAG-based LLM agents |
|
Experimental |
| 65 |
brittytino/cyber-sop-assistant
A fully local Cybercrime SOP assistant for India, combining a FastAPI... |
|
Experimental |
| 66 |
stlin256/FraudSMS_RAG_Shield
融合大模型推理与RAG检索增强的诈骗短信甄别系统 |
|
Experimental |
| 67 |
laricko/prompt-guard
Prompt-safety guards as a Python library. TF-IDF, RAG, LLM as a judge pipeline |
|
Experimental |
| 68 |
MAEN1-prog/CVE-2025-2304
🛠️ Exploit CVE-2025-2304 in Camaleon CMS easily with this Python script for... |
|
Experimental |
| 69 |
fartlover37/CVE-2026-2441-PoC
Demonstrate a proof-of-concept exploit for CVE-2026-2441, a high-risk Chrome... |
|
Experimental |
| 70 |
MadDataQualcommHackathon/SentinelAI
Enterprises in legal, defense, and finance cannot use AI on their most... |
|
Experimental |
| 71 |
nimad70/VulRAG
Investigating the vulnerability of Large Language Models (LLMs) to... |
|
Experimental |
| 72 |
Sai-Chakradhar-Mahendrakar/SOC-Analyst-Automation-using-RAG-Model
SOC Analyst Automation using a RAG model integrates a knowledge retrieval... |
|
Experimental |
| 73 |
Arthurfert/SecLLM-Gen
Offensive & Defensive cybersecurity LLM application |
|
Experimental |
| 74 |
butlerem/vulnerability-scanner-UniXcoder-RAG
AI-powered browser-based vulnerability scanner using UniXcoder embeddings... |
|
Experimental |
| 75 |
michealimuse777/Sentinel-Bot-Showcase
Sentinel: A Level 4 Autonomous Discord Agent. Features RAG-powered web... |
|
Experimental |
| 76 |
Ravi0529/isea-rag-attack-classification
Pipeline converts raw logs into structured session intelligence and maps... |
|
Experimental |
| 77 |
ddihora1604/FINAL_year_project
A whitebox LLMOps framework designed to enhance security and transparency in... |
|
Experimental |
| 78 |
danifeb94/ai-log-hunter
🛡️ AI Log Hunter v5.2 | Advanced Local RAG & Hybrid OCR (Llama 3 +... |
|
Experimental |
| 79 |
bhattaraisubal-eng/RAG-poisoning
A simple experiment on how RAG poisoning attack propagates through a... |
|
Experimental |
| 80 |
cyber-evangelists/threat-mon-rag
Threat Mon Rag to Demonstrate the Rag for security researchers. |
|
Experimental |
| 81 |
mizazhaider-ceh/Prime-PenTrix
AI Cybersecurity Learning Platform. Features Hybrid RAG (pgvector + BM25),... |
|
Experimental |
| 82 |
aliozen0/sentinel-io
Decentralized compute orchestration using AI agents (FastAPI, Next.js, RAG).... |
|
Experimental |
| 83 |
YangYang-Research/whale-sentinel-controllers
The Whale Sentinel Controllers |
|
Experimental |
| 84 |
agloriousli/SentinelAI
A security-focused Agent that ingests raw security logs, uses RAG to query... |
|
Experimental |
| 85 |
ReaperZ0v/sentinel-ai
A RAG implementation concept for law enforcement to search through their... |
|
Experimental |
| 86 |
r00tb3/RAG-Poisoning-Lab
RAG Poisoning Lab — Educational AI Security Exercise |
|
Experimental |
| 87 |
CyberSecAI/CWE-Expert
A CWE-Expert can be built for free in a browser in less than 1 minute using... |
|
Experimental |