Open source · self-hosted · local AI

Investigate
on your terms.

SOC case management with a copilot that asks first

sochub is a multi-tenant incident-response workbench. Triage cases, link IOCs across investigations and run MITRE-mapped playbooks, with an AI copilot on your model that never writes without your confirm.

Self-hosted
100% Self-hosted
Bytes sent to a 3rd-party LLM
0 Bytes sent to a 3rd-party LLM
Every feature, every tenant
$0 Every feature, every tenant
Case management Investigation copilot
MITRE playbooks Multi-tenant SSO
localhost / dashboard
sochub operations dashboard with case trends, severity heatmap and MTTR
Built on FastAPIReact 19PostgreSQLOllamaDocker
Features

Built around how investigations actually work

Not a ticketing system wearing a security costume. Cases, artifacts and IOCs are first-class objects that link across investigations.

Investigation copilot

A context-aware assistant on a local Ollama model (or your own provider). It proposes actions; nothing is written until you confirm.

AI triage

Every new case gets a suggested severity, tags, playbook, related cases and next steps — before an analyst opens it.

Playbook marketplace

MITRE-mapped IR playbooks that fill a case with phase-grouped task checklists, from identification to lessons learned.

Investigation graph

A force-directed map of cases, artifacts and IOCs that surfaces the campaign hiding across "unrelated" cases.

Multi-tenant by design

One account, many tenants, a role per tenant. Row-level isolation and per-tenant SAML SSO for MSSPs and multi-entity orgs.

Automations

A visual workflow builder with conditions, loops, HTTP calls and Slack "ask a person" steps. Dry-run before you ship.

Incident reports

AI-drafted, analyst-edited reports with TTD/TTC/TTR and swimlane timelines. Export to TLP-marked PDF or JSON.

Security first

Argon2, TOTP MFA, session revocation, host-bound workflow secrets, SSRF guards and full audit logging.

Product tour

See it before you deploy it

Real screenshots from the current build. Every one of these runs on your own infrastructure.

localhost · recorded session
sochub Cases: AI triage, SLA status, follow toggle and @mentions on every case.
CasesAI triage, SLA status, follow toggle and @mentions on every case.
sochub Copilot: Chat about a case; approve or cancel each proposed action.
CopilotChat about a case; approve or cancel each proposed action.
sochub Graph: Dashed bridges show where the same indicator links cases.
GraphDashed bridges show where the same indicator links cases.
sochub Playbooks: Import MITRE-mapped playbooks and own editable copies.
PlaybooksImport MITRE-mapped playbooks and own editable copies.
sochub Automations: Typed node inspectors, dry runs and full run history.
AutomationsTyped node inspectors, dry runs and full run history.
sochub Reports: Detection → containment → recovery timelines, TLP-marked export.
ReportsDetection → containment → recovery timelines, TLP-marked export.
sochub IOCs: Enriched via VirusTotal, URLhaus, ThreatFox, RDAP and crt.sh — TLP-aware.
IOCsEnriched via VirusTotal, URLhaus, ThreatFox, RDAP and crt.sh — TLP-aware.
Quick start

Running locally in three commands

Clone the repo, copy the two .env.example files, and go. Then open http://localhost and sign in.

FastAPISQLAlchemy asyncPostgreSQLReact 19TypeScriptTanStack QueryTailwindCelery + RedisOllamaSAML SSODocker Compose

Going to production? Set ENVIRONMENT=production and strong secrets — the app refuses to boot with defaults. Full guide →

~/soc-hub
  1. 01 Bring up the stack
    $ docker compose up -d --build
  2. 02 Apply migrations
    $ docker compose exec backend alembic upgrade head
  3. 03 Create the first admin
    $ docker compose exec backend python -m app.scripts.create_super_admin --email admin@example.com --name "Super Admin"
Pricing

Free. Self-hosted. Yours.

There is no paid tier. You run it, you own the data, and you can fork it if the roadmap stops matching yours.

sochub SaaS
Read every line making decisions about your incidents
Case data, IOCs and prompts stay on your network
AI on a local model — no third-party API required
Multi-tenant with per-tenant SSO, no "enterprise tier"
Per-seat pricing that grows with your team
Community edition
$0

Every feature. Every tenant. Forever.

  • Unlimited tenants & users
  • Copilot, triage & reports
  • Playbooks & automations
  • SAML SSO & MFA
Clone the repo
From the build log

Articles

How sochub gets built, and the detection, response and AI-security thinking behind it.

· Engineering

Vibecoding an Open-Source SOC Platform: What Held Up and What Didn't

sochub is now open source. The latest round was built mostly by describing features in plain English to an AI agent — here's what that actually looked like, including the parts where the vibe broke and judgment had to take over.

8 min read Read
Contact

Tell us what your SOC needs

Questions, feature ideas, bug reports or "we tried it and here's what broke" — all welcome. Submitting opens a pre-filled GitHub issue so the conversation happens in the open.

Issues are public — don't paste case data or secrets. Requires a GitHub account.