فرق الأمن تغرق في تنبيهات SIEM، معظمها ضجيج يستهلك مع ذلك دقائق للتحقيق يدوياً في كلٍّ منه. هذه الأتمتة تجري بحث المرحلة الأولى قبل أن ينظر إنسان أصلاً.
sonnetأسبوع واحدSplunkVirusTotalAbuseIPDBMISP
Claude
100ROI
81Scale
$3.4k92Saved
ROI for
README.md
لماذا هذا الوكيل تحديدًا
فرق الأمن تغرق في تنبيهات SIEM، معظمها ضجيج يستهلك مع ذلك دقائق للتحقيق يدوياً في كلٍّ منه. هذه الأتمتة تجري بحث المرحلة الأولى قبل أن ينظر إنسان أصلاً.
تُثري كل مؤشّر باستخبارات التهديدات وملكية الأصل والأحداث المرتبطة، ثم تسجّل التنبيه بدرجة. المحلّلون لا يُنبَّهون إلا للتنبيهات المهمّة فعلاً، والأدلّة مرفقة سلفاً؛ فيبدأ الفرز من سياق، لا من شاشة فارغة.
كيف يعمل
Used at step 01 to kick off the pipeline.
Write
Used at step 01 to kick off the pipeline.
WebFetch
Used at step 01 to kick off the pipeline.
WebSearch
Used at step 01 to kick off the pipeline.
يبحث عن كل مؤشّر في خلاصات استخبارات التهديدات وخدمات السمعة بحثاً عن تطابقات معروفة الخطورة.
pending
يضيف مالك الأصل وسجلّ الدخول الأخير وأي تنبيهات مرتبطة، كي يرى المحلّل السياق الكامل.
pending
يسجّل التنبيه المُثرى، يوجّه الضجيج منخفض الثقة إلى طابور، ولا ينبّه البشر إلا عند خطر حقيقي.
pending
نموذج للمخرجات
json
// Sample output
// (generated when the pipeline finishes)
Take a raw SIEM alert, enrich every indicator with threat-intel and asset context, then return a triage verdict (escalate or suppress) with a confidence score and the evidence behind it.
Unlock the rest
The full agent definition, install snippet, and starter task are gated for community members.
Members get the full `.md` agent file, the npm / pnpm install one-liners, a starter prompt that we've tuned against real runs, and the open-source repo when this automation ships there. One email, magic link, done.