The platform
AarSOC
AarSOC is a complete SOC platform built exclusively on open-source components, designed to operate in environments that demand data sovereignty and infrastructure control.
Capabilities
Detection & correlation
- ● Multi-source collection
- ● Event normalisation
- ● MITRE ATT&CK-aligned rules
- ● Real-time alerts
Threat intelligence
- ● Indicator of compromise (IOC) sharing
- ● Automatic alert enrichment
- ● TAXII/STIX feeds
- ● Standardised taxonomies
Incident response
- ● Orchestration and automation (SOAR)
- ● Endpoint investigation (EDR)
- ● Response playbooks
- ● Bilingual reports FR/EN
AI agents
- ● Automated alert triage
- ● Proactive threat hunting
- ● Incident report generation
- ● Under human control
Observability
- ● Performance metrics
- ● Operational dashboards
- ● Availability monitoring
- ● Proactive alerting
Data pipeline
- ● High-availability distributed message queue
- ● GeoIP enrichment
- ● Per-type event normalisation
- ● Configurable retention
Security by design
- ✓ TLS 1.2+ encryption across all internal and external channels
- ✓ Multi-factor authentication for operator access
- ✓ Role-based access control (RBAC) per organisation
- ✓ Complete audit trail, aligned with ISO/IEC 27001:2022
- ✓ Network isolation: SOC traffic and monitoring on separate segments
AI under human control
AarSOC integrates AI agents to accelerate analysis, not to replace the analyst. Every AI decision is traceable, reversible, and subject to human validation before any response action.
Automatic classification of alerts by severity and threat type.
Search for abnormal patterns across the event history.
Structured drafting in FR and EN from incident data.
AarView client portal
AarView gives your teams real-time visibility into SOC operations. Reports are end-to-end encrypted and accessible through a secure, VPN-only portal.
- ✓ Encrypted incident reports, AI-generated and analyst-validated
- ✓ KPI dashboard: MTTD, MTTR, alert volumes
- ✓ Real-time incident and ticket tracking
- ✓ Bilingual FR/EN PDF/CSV export
- ✓ Bilingual interface, VPN-only access
Deployment options
Operated by CyberAar
End-to-end managed infrastructure by CyberAar. Production ready, Senegal datacenter deployment in progress.
On-premise
Deployed in your own infrastructure, on private cloud or on-premise.
No vendor lock-in
No public cloud required. No dependency on proprietary vendors.
What's included
- ✓ Multi-source SIEM with MITRE ATT&CK rules
- ✓ Incident management and SOC ticketing
- ✓ Threat intelligence sharing
- ✓ Orchestration and automation (SOAR)
- ✓ Remote endpoint investigation (EDR)
- ✓ AI agents: triage, incident report, threat hunting
- ✓ Observability and availability monitoring
- ✓ AarView client portal (dashboard, incidents, encrypted reports)