Cybersecurity SOC RAG RAG Tools
Tools for security operations center (SOC) automation, incident response, and threat analysis using RAG. Focuses on SIEM integration, log analysis, security questionnaires, and cyber threat intelligence. Does NOT include general security tools without RAG, non-SOC cybersecurity applications, or drone/network-level security systems without SOC operations context.
There are 87 cybersecurity soc rag tools tracked. 3 score above 50 (established tier). The highest-rated is LLAMATOR-Core/llamator at 59/100 with 201 stars.
Get all 87 projects as JSON
curl "https://pt-edge.onrender.com/api/v1/datasets/quality?domain=rag&subcategory=cybersecurity-soc-rag&limit=20"
Open to everyone — 100 requests/day, no key needed. Get a free key for 1,000/day.
| # | Tool | Score | Tier |
|---|---|---|---|
| 1 |
LLAMATOR-Core/llamator
Red Teaming python-framework for testing chatbots and GenAI systems. |
|
Established |
| 2 |
sleeepeer/PoisonedRAG
[USENIX Security 2025] PoisonedRAG: Knowledge Corruption Attacks to... |
|
Established |
| 3 |
kelkalot/simpleaudit
Allows to red-team your AI systems through adversarial probing. It is... |
|
Established |
| 4 |
JuliusHenke/autopentest
CLI enabling more autonomous black-box penetration tests using Large... |
|
Emerging |
| 5 |
SecurityClaw/SecurityClaw
A modular, skill-based autonomous Security Operations Center (SOC) agent... |
|
Emerging |
| 6 |
AI-secure/AgentPoison
[NeurIPS 2024] Official implementation for "AgentPoison: Red-teaming LLM... |
|
Emerging |
| 7 |
AnubhavChoudhery/cybersec-scanner
A comprehensive, modular security scanning toolkit for detecting secrets,... |
|
Emerging |
| 8 |
taladari/rag-firewall
Client-side retrieval firewall for RAG systems — blocks prompt injection and... |
|
Emerging |
| 9 |
rohansx/cloakpipe
Privacy middleware for LLM & RAG pipelines - consistent pseudonymization,... |
|
Emerging |
| 10 |
olegnazarov/rag-security-scanner
RAG/LLM Security Scanner identifies critical vulnerabilities in AI-powered... |
|
Emerging |
| 11 |
CaviraOSS/SecuPrompt
Protect your AI from Prompt Injection |
|
Emerging |
| 12 |
olegnazarov/llm-fortress
Enterprise AI Security Platform - Real-time firewall protection for LLM... |
|
Emerging |
| 13 |
clab60917/RAG-LLM-SOC_analyst
SOC Analyst Level 1 Replacement using RAG LLM |
|
Emerging |
| 14 |
LauJames/Topic-FlipRAG
[USENIX Security 2025] Topic-FlipRAG: Topic-Orientated Adversarial Opinion... |
|
Emerging |
| 15 |
toxy4ny/redteam-ai-benchmark
Red Team AI Benchmark: Evaluating Uncensored LLMs for Offensive Security |
|
Emerging |
| 16 |
Har1sh-k/SecLint
A Python-based AI agent for detecting insecure code patterns in Python... |
|
Emerging |
| 17 |
HydroXai/pii-masker
PII Masker is an open-source tool for protecting sensitive data by... |
|
Emerging |
| 18 |
jone0709/Securing-AI-ML-Maturity-Model
AI Operations Security Maturity Model and toolkit to secure AI/ML... |
|
Emerging |
| 19 |
Curtis-Thomas/junction-sentinel
Junction Sentinel is a secure, multi-agent system designed to address drone... |
|
Experimental |
| 20 |
prompt-security/RAG_Poisoning_POC
Stealthy Prompt Injection and Poisoning in RAG Systems via Vector Database Embeddings |
|
Experimental |
| 21 |
sandipkatel/Unified-InfoSec-QnA-Assistant
A full-stack RAG based AI-powered system to help InfoSec teams efficiently... |
|
Experimental |
| 22 |
StruggleY/Fo-Sentinel-Agent
企业级安全智能研判平台-多 Agent 协同与 Supervisor-Worker 深度思考架构驱动,集成全链路... |
|
Experimental |
| 23 |
javidahmed64592/cyber-query-ai
Ollama-powered cybersecurity assistant for ethical penetration testing and... |
|
Experimental |
| 24 |
bx0-0/CyberVisionAI
Cyber Vision AI is an award-winning, open-source AI assistant for... |
|
Experimental |
| 25 |
scthornton/ai-security-analyst-rag
Build an AI Security Analyst Assistant with RAG! LEARN FROM SCRATCH |
|
Experimental |
| 26 |
musabdulai-io/llm-production-safety-scanner
CLI tool for testing production safety controls in LLM/RAG apps - prompt... |
|
Experimental |
| 27 |
Privalyse/privalyse-mask
Semantic PII Masking & Anonymization for LLMs (RAG). GDPR-compliant,... |
|
Experimental |
| 28 |
gbikram/ThreatIntelRAG
Experimental RAG that consumes Cyber Security articles via RSS |
|
Experimental |
| 29 |
cisco-ai-defense/adversarial-hubness-detector
Scanner for adversarial hubs in RAG and vector databases |
|
Experimental |
| 30 |
HyeonjeongHa/MM-PoisonRAG
Official PyTorch implementation of "MM-PoisonRAG: Disrupting Multimodal RAG... |
|
Experimental |
| 31 |
deconvolute-labs/benchmarks
Reproducible security benchmarking for the Deconvolute SDK and AI system... |
|
Experimental |
| 32 |
scthornton/semantic-chameleon
Dual-Stage Temporal Poisoning Attack on RAG Systems |
|
Experimental |
| 33 |
Zyrabit-tech/zyrabit-SLM
Sovereign AI Infrastructure for Enterprise RAG. Zero-Trust PII Sanitization,... |
|
Experimental |
| 34 |
Cyberfortress-Labs/Cyberfortress-Intelligent-SOC-Ecosystem
An Intelligent SOC Ecosystem that integrates SIEM, SOAR, and SmartXDR to... |
|
Experimental |
| 35 |
DonkeyKing01/SCSI-SLM-EV-Design
Official implementation of the SCSI-SLM framework for translating EV... |
|
Experimental |
| 36 |
uuluul/AI-autonomous-SOC
AI-powered autonomous SOC pipeline featuring hybrid log ingestion,... |
|
Experimental |
| 37 |
byerlikaya/Septum
Privacy‑first AI middleware that anonymizes PII locally and only sends... |
|
Experimental |
| 38 |
McKern3l/RAGdrag-labs
Test lab for RAGdrag — vulnerable RAG target, sample results, and test suite |
|
Experimental |
| 39 |
mishabar410/RAGLeakLab
Deterministic security testing for RAG pipelines: measure retrieval-induced... |
|
Experimental |
| 40 |
gypark94/RAGprompt
Anomaly detection using RAG |
|
Experimental |
| 41 |
Jeremy0219/cloudguard-rag
AI-powered RAG pipeline for querying cloud security frameworks using Azure... |
|
Experimental |
| 42 |
MartinMilevVenelinova/rag-copilot-it-security
Internal RAG copilot for Helpdesk/SecOps: cited answers, strict “not found”... |
|
Experimental |
| 43 |
SidereusHu/RAG-Shield
Defense-in-depth security framework for RAG systems: poison detection,... |
|
Experimental |
| 44 |
45ck/llm-agent-security-skills
LLM and agent security skill pack for prompt injection, tool permissions,... |
|
Experimental |
| 45 |
112ab0058/ray
PromptGuard Research | AI Security & RAG Defense |
|
Experimental |
| 46 |
julienmerconsulting/rag-poisoning-demo
🧪 5 faux documents suffisent pour corrompre 80% des réponses d'un RAG. Démo... |
|
Experimental |
| 47 |
Kelvin295/cloakpipe
Protect LLM data by detecting, masking, and unmasking personal information... |
|
Experimental |
| 48 |
stlin256/FraudSMS_RAG_Shield
融合大模型推理与RAG检索增强的诈骗短信甄别系统 |
|
Experimental |
| 49 |
brittytino/cyber-sop-assistant
A fully local Cybercrime SOP assistant for India, combining a FastAPI... |
|
Experimental |
| 50 |
ayinedjimi/SOC-Assistant
RAG-Powered SOC Assistant - By Ayi NEDJIMI |
|
Experimental |
| 51 |
Laav0808/cybersecurity-rag-assistant
RAG-powered cybersecurity knowledge assistant using LangChain, Weaviate, and... |
|
Experimental |
| 52 |
OpenAgenticOS/asb-security-schema
A unified security event schema for LLM, RAG, and Agent applications. |
|
Experimental |
| 53 |
nimad70/VulRAG
Investigating the vulnerability of Large Language Models (LLMs) to... |
|
Experimental |
| 54 |
Sai-Chakradhar-Mahendrakar/SOC-Analyst-Automation-using-RAG-Model
SOC Analyst Automation using a RAG model integrates a knowledge retrieval... |
|
Experimental |
| 55 |
Sumukha87/aia-auditor
AI RAG system for cloud security auditing — Qwen 2.5 7B via Ollama, Qdrant... |
|
Experimental |
| 56 |
Dhy4n-117/AI_SOC_Analyst
A privacy-first, local AI assistant for SOC analysts and threat hunters.... |
|
Experimental |
| 57 |
Cyberfortress-Labs/cyberfortress-labs.github.io
A unified intelligent SOC ecosystem where SIEM, SOAR, OpenXDR, Threat... |
|
Experimental |
| 58 |
laricko/prompt-guard
Prompt-safety guards as a Python library. TF-IDF, RAG, LLM as a judge pipeline |
|
Experimental |
| 59 |
MadDataQualcommHackathon/SentinelAI
Enterprises in legal, defense, and finance cannot use AI on their most... |
|
Experimental |
| 60 |
r00tb3/RAG-Poisoning-Lab
RAG Poisoning Lab — Educational AI Security Exercise |
|
Experimental |
| 61 |
thiagov21/squad-sentinela
AI workflow automation platform using agents and RAG to transform... |
|
Experimental |
| 62 |
HameshTiwari/Secure-AI-Financial-Auditor
Enterprise GenAI framework implementing architectural guardrails and PII... |
|
Experimental |
| 63 |
ducwuyy/DocSentinel
Detect security risks in documents and questionnaires using automated... |
|
Experimental |
| 64 |
Arthurfert/SecLLM-Gen
Offensive & Defensive cybersecurity LLM application |
|
Experimental |
| 65 |
bhattaraisubal-eng/RAG-poisoning
A simple experiment on how RAG poisoning attack propagates through a... |
|
Experimental |
| 66 |
cyber-evangelists/threat-mon-rag
Threat Mon Rag to Demonstrate the Rag for security researchers. |
|
Experimental |
| 67 |
aliozen0/sentinel-io
Decentralized compute orchestration using AI agents (FastAPI, Next.js, RAG).... |
|
Experimental |
| 68 |
agloriousli/SentinelAI
A security-focused Agent that ingests raw security logs, uses RAG to query... |
|
Experimental |
| 69 |
MAEN1-prog/CVE-2025-2304
🛠️ Exploit CVE-2025-2304 in Camaleon CMS easily with this Python script for... |
|
Experimental |
| 70 |
fartlover37/CVE-2026-2441-PoC
Demonstrate a proof-of-concept exploit for CVE-2026-2441, a high-risk Chrome... |
|
Experimental |
| 71 |
YangYang-Research/whale-sentinel-controllers
The Whale Sentinel Controllers |
|
Experimental |
| 72 |
ChangYeongJeong1103/prompt-injection-gatekeeper
Multi-stage prompt injection detection pipeline for RAG-based LLM agents |
|
Experimental |
| 73 |
urcuqui/rag-poisoning-lab
A hands-on security lab demonstrating how to poison a Retrieval-Augmented... |
|
Experimental |
| 74 |
ReaperZ0v/sentinel-ai
A RAG implementation concept for law enforcement to search through their... |
|
Experimental |
| 75 |
michealimuse777/Sentinel-Bot-Showcase
Sentinel: A Level 4 Autonomous Discord Agent. Features RAG-powered web... |
|
Experimental |
| 76 |
404godd/CVE-2026-20841-PoC
🛠 Demonstrate remote code execution in Windows Notepad versions below... |
|
Experimental |
| 77 |
hamzamalik3461/CVE-2026-20841
🛠 Demonstrate remote code execution in Windows Notepad via markdown links... |
|
Experimental |
| 78 |
Ravi0529/isea-rag-attack-classification
Pipeline converts raw logs into structured session intelligence and maps... |
|
Experimental |
| 79 |
mizazhaider-ceh/Prime-PenTrix
AI Cybersecurity Learning Platform. Features Hybrid RAG (pgvector + BM25),... |
|
Experimental |
| 80 |
danifeb94/ai-log-hunter
🛡️ AI Log Hunter v5.2 | Advanced Local RAG & Hybrid OCR (Llama 3 +... |
|
Experimental |
| 81 |
ddihora1604/FINAL_year_project
A whitebox LLMOps framework designed to enhance security and transparency in... |
|
Experimental |
| 82 |
butlerem/vulnerability-scanner-UniXcoder-RAG
AI-powered browser-based vulnerability scanner using UniXcoder embeddings... |
|
Experimental |
| 83 |
MuhamedAyoub/RealTime-RAG-CyberSecurity_Analyst
A Retrieval-Augmented Generation (RAG) system for automating Security... |
|
Experimental |
| 84 |
jawadhussein462/Awesome-Rag-Attacks
A research framework for implementing and evaluating poisoning attacks on... |
|
Experimental |
| 85 |
CyberSecAI/CWE-Expert
A CWE-Expert can be built for free in a browser in less than 1 minute using... |
|
Experimental |
| 86 |
Cyberfortress-Labs/Cyberfortress-RAG-LLM
The RAG (Retrieval-Augmented Generation) system optimized for the... |
|
Experimental |
| 87 |
KnightChaser/MITREAttackRagger
A simple RAG demonstration ATT&CK CTI(Cyber Threat Intelligence) information |
|
Experimental |