1. The Core Idea & Purpose AttackChain AI was built as an investigation platform for SOC (Securit...1. The Core Idea & Purpose AttackChain AI was built as an investigation platform for SOC (Securit...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
1. The Core Idea & Purpose
AttackChain AI was built as an investigation platform for SOC (Security Operations Center) analysts.
When cyberattacks happen in banking and enterprise networks, they rarely trigger a single massive alert. Instead, they produce dozens of low-priority, disconnected logs across VPNs, Windows endpoints (Sysmon/EventLogs), and web firewalls.
Analysts normally spend hours manually correlating IP addresses, usernames, process GUIDs, and timestamps in spreadsheets. This project automates that end-to-end investigation process.

2. How the Engine Works (Under the Hood)
The backend pipeline operates in strict, verifiable stages:
Ingestion & Normalization: Telemetry logs (Windows Event Logs, Sysmon, network traffic) are parsed into standardized entity events (Hosts, IPs, Users, Hashes, Processes).
Threat Intelligence Enrichment: Known malicious indicators (TOR exit nodes, command-and-control servers, known attack signatures) are flagged.
MITRE ATT&CK Mapping: Each event is tagged with industry-standard tactics and techniques (e.g., T1078 Valid Accounts, T1059 Command & Scripting, T1048 Exfiltration).
Deterministic Correlation: A graph-based correlation engine links events across time windows, shared identities, and parent-child process chains without relying on AI guesswork.
100-Point Transparent Risk Scoring: Computes a verifiable risk score based on kill-chain progression, asset criticality, and tactic diversity.
Optional AI Narrative: Claude 3 Opus generates an executive briefing and incident narrative based strictly on verified findings.

3. Real Telemetry Dataset
The project demonstrates its capabilities on real-world attack data curated from the Splunk Boss of the SOC (BOTS) v1 competition dataset, simulating authentic multi-stage enterprise breaches (credential theft, lateral movement, database reconnaissance, and data exfiltration).

4. Enterprise-Grade Investigation Workspace
The frontend is designed like Tier-1 enterprise security tools (CrowdStrike Falcon, Microsoft Sentinel, Palantir):
3-Pane Investigation View:
Left Pane: Incident metadata, MITRE progression badge, severity stats, and quick actions.
Center Pane: Interactive visual Evidence Graph (powered by React Flow) and a step-by-step Attack Timeline Replay.
Right Pane: Deep-dive evidence drawer, technical IOC breakdown, SOC response playbooks (Host Isolation, Credential Revocation), and an interactive SOC AI Copilot.
MITRE Coverage Matrix: Heatmap showing covered tactics across the entire incident.
Executive PDF / Export Ready: Structured for instant reporting to CISOs and compliance teams.
Post image
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started