The platform

AarSOC

AarSOC is a complete SOC platform built exclusively on open-source components, designed to operate in environments that demand data sovereignty and infrastructure control.

AarSOC - Client portal and security operations

Capabilities

Detection & correlation

  • Multi-source collection
  • Event normalisation
  • MITRE ATT&CK-aligned rules
  • Real-time alerts

Threat intelligence

  • Indicator of compromise (IOC) sharing
  • Automatic alert enrichment
  • TAXII/STIX feeds
  • Standardised taxonomies

Incident response

  • Orchestration and automation (SOAR)
  • Endpoint investigation (EDR)
  • Response playbooks
  • Bilingual reports FR/EN

AI agents

  • Automated alert triage
  • Proactive threat hunting
  • Incident report generation
  • Under human control

Observability

  • Performance metrics
  • Operational dashboards
  • Availability monitoring
  • Proactive alerting

Data pipeline

  • High-availability distributed message queue
  • GeoIP enrichment
  • Per-type event normalisation
  • Configurable retention

Security by design

  • TLS 1.2+ encryption across all internal and external channels
  • Multi-factor authentication for operator access
  • Role-based access control (RBAC) per organisation
  • Complete audit trail, aligned with ISO/IEC 27001:2022
  • Network isolation: SOC traffic and monitoring on separate segments

AI under human control

AarSOC integrates AI agents to accelerate analysis, not to replace the analyst. Every AI decision is traceable, reversible, and subject to human validation before any response action.

Triage

Automatic classification of alerts by severity and threat type.

Threat hunting

Search for abnormal patterns across the event history.

Incident reports

Structured drafting in FR and EN from incident data.

AarView client portal

AarView gives your teams real-time visibility into SOC operations. Reports are end-to-end encrypted and accessible through a secure, VPN-only portal.

  • Encrypted incident reports, AI-generated and analyst-validated
  • KPI dashboard: MTTD, MTTR, alert volumes
  • Real-time incident and ticket tracking
  • Bilingual FR/EN PDF/CSV export
  • Bilingual interface, VPN-only access
AarView - SOC client portal

Deployment options

Operated by CyberAar

End-to-end managed infrastructure by CyberAar. Production ready, Senegal datacenter deployment in progress.

On-premise

Deployed in your own infrastructure, on private cloud or on-premise.

No vendor lock-in

No public cloud required. No dependency on proprietary vendors.

What's included

  • Multi-source SIEM with MITRE ATT&CK rules
  • Incident management and SOC ticketing
  • Threat intelligence sharing
  • Orchestration and automation (SOAR)
  • Remote endpoint investigation (EDR)
  • AI agents: triage, incident report, threat hunting
  • Observability and availability monitoring
  • AarView client portal (dashboard, incidents, encrypted reports)
Join the pilot program