The open source AI SOC you own
Vigil is the leading open source AI SOC: Apache 2.0, skills-native, and built by the team behind StackStorm. Run it on a laptop in minutes with a local model or the provider you choose, then grow it into the autonomic layer of your SOC.
git clone https://github.com/Vigil-SOC/vigil.git cd vigil ./start.sh # then open http://localhost:6988
Docker must be running. No LogLM and no cloud API key are needed to reach a running console; a local Ollama model works.
A SOC in readable code
Agents you can read, workflows you edit as Markdown, and integrations on an open standard. Your team owns each layer and extends any one without touching the others.
Starts with 13 specialized agents: author your own in seconds
Triage, investigation, hunting, correlation, response, reporting, MITRE mapping, forensics, threat intel, compliance, malware and network analysis.
Workflows as Markdown
Each playbook is a WORKFLOW.md file: agent sequence, tool access, and instructions per phase, under your change control.
30+ integrations over MCP
Splunk, Sentinel, CrowdStrike, Defender, SentinelOne, Okta, Cribl, Jira, Slack, PagerDuty, and more. Add one by wrapping an API in an MCP server.
The detections you already trust, plus LogLM awareness
7,200+ community rules across Sigma, Splunk, Elastic, and KQL, plus your existing and federated detections in Splunk and Elastic. Vigil manages the rules an environment runs, which makes coverage assessment routine.
Autonomy is earned, and only people grant it
The lesson from a decade of StackStorm deployments: the system may demote itself, and only humans promote it. Since release 0.5 the harness applies that rule continuously. Before an automation runs, Vigil checks projected cost and confidence against thresholds your team sets. When either drifts, Vigil steps back and asks a person.
Your model, your boundary
Vigil works with a local model through Ollama, or with Anthropic Claude or OpenAI through a gateway you control. Teams that cannot send data to a hosted provider run entirely local, and nothing leaves the machine. Teams that use a hosted model choose the endpoint and decide what crosses it.
Ollama models run with no API key and no egress.
Claude or OpenAI with your keys, through your gateway.
Release images are signed keyless and verifiable with cosign.
Authentication is on from first start; no default credentials ship with the repository.
Four layers, each yours to change
Contracts endure while implementations change: finding, case, and approval tools sit behind frozen API schemas, and LogLM connects as an MCP integration you enable, not a prerequisite.
Investigate what rules never fire on
Vigil runs your rules-based detections on its own. Enable the LogLM integration and it also receives compound detections from the behavior of your telemetry: the concerning sequences that no signature describes. Together they form a detection and response loop your team owns end to end.
LogLM scores the full telemetry stream and emits MITRE-mapped findings.
Vigil agents assemble evidence, context, and a recommended action.
Red team your own environment, turn what you learn into detections, and measure efficacy inside the loop.
Human on the loop, not in it
Vigil 1.0 performs substantially all of a SOC's day-to-day work while your analysts supervise the system rather than staff its queue. The roadmap is public on GitHub.
Stable contracts
Versioned APIs and MCP tool schemas that integrations can depend on for the long term.
Batteries included, not required
A full console and workflow library out of the box; every piece replaceable by your own.
Policy as code
Declared intent and policies stored as Markdown under change control, per environment.
Detection coverage
Vigil manages the rules an environment runs and reports what they cover and what they miss.
Closed loop
Red team results feed new detections, with efficacy measured in the same loop.
Agent-vendor neutral
The development loop is not tied to any one coding agent or model provider.
Current and past releases, with signed images and changelogs.
Running Vigil in production?
Vigil stays free under Apache 2.0. Vigil Assured is the maintained, hardened track for teams that run it where it matters, delivered as part of the Intelligent Defense Platform.
Talk to us about Vigil AssuredRun it, read it, change it
Clone Vigil and reach a running console in minutes. Star the repository to follow releases, and join the community at vigilsoc.org.
