1 threatfusion_core.py [RO] 2 pipeline_telemetry.log 3 arch_spec.yaml
0102030405 0607080910 1112131415 1617181920 2122232425 2627282930 3132

# ==============================================================

# THREATFUSION: Autonomous SOC Alert Triage & Correlation Engine

# Domain: https://threatfusion.me | Engine: Claude 3.5 Sonnet

# ==============================================================

 

from secops.agents import ClaudeSonnetReasoningCore

from enrichment.vectors import ChromaDBContextIndex

from intelligence.misp import IOCMatcher

 

class ThreatFusionOrchestrator:

"""Automated Level-1 SOC Analyst eliminating alert fatigue."""

def __init__(self):

self.reasoning_core = ClaudeSonnetReasoningCore(

temperature=0.1,

prompt_caching=True,

output_schema="strict_mitre_verdict.json"

)

self.vector_store = ChromaDBContextIndex()

 

async def triage_incident_cluster(self, telemetry_burst):

# Step 1: Statistical clustering collapses burst floods

incident = deduplicate_and_cluster(telemetry_burst)

 

# Step 2: Context enrichment from MISP feeds & vectors

enriched_payload = await self.vector_store.augment(incident)

 

# Step 3: Multi-hop reasoning and kill-chain classification

verdict = await self.reasoning_core.evaluate(enriched_payload)

return verdict.dispatch_to_thehive()

NORMAL threatfusion_core.py [+]
utf-8 python 32:1 100%
LIVE TELEMETRY INGESTION BUFFER PID: 40921

[17:34:02.102] INGEST → Syslog / AWS VPC Flow

BURST DETECTED: 1,420 connection attempts from subnet 10.0.4.0/24

→ Deduplicated into Single Incident Cluster (Cluster-ID: #TF-894)

[17:34:02.340] ENRICHMENT → Vector Retrieval

• ChromaDB Cosine Match: 0.94 against CVE-2024-38812

• MISP Correlation: Known C2 staging IP match (Confidence: 89%)

[17:34:02.890] AGENT REASONING CORE (Claude 3.5 Sonnet)

> Analyzing multi-stage execution chain...

> Verdict: TRUE POSITIVE (P1 High)

> MITRE ATT&CK: T1059.004 (Unix Shell), T1071.001 (Web Protocols)

> JSON Response Payload generated in 420ms (Prompt Cached).

[17:34:03.110] DISPATCH → Autonomous Mitigation

→ TheHive Case #204 Created & Assigned

→ Generated Quarantine CLI Script ready for SOC sign-off

RUNNING triage_daemon.log
tail -f 894/894