SOC-in-a-Box: A Multi-Agent LLM-Based Security Operations Center for Threat Detection and Automated Incident Response

Authors

  • Disha S UG, Dept. of CSE, Atria Institute of Technology, Bengaluru, Karnataka, India. Author
  • Pallavi U Assistant Professor, Dept. of CSE, Atria Institute of Technology, Bengaluru, Karnataka, India. Author
  • Devika K A UG, Dept. of CSE, Atria Institute of Technology, Bengaluru, Karnataka, India. Author

DOI:

https://doi.org/10.47392/IRJAEH.2026.0684

Keywords:

Autonomous monitoring, incident response, large language models, multi-agent systems, threat detection

Abstract

Modern Security Operations Centres struggle with overwhelming alert volumes, chronic analyst shortages, and slow incident response times. This paper presents SOC-in-a-Box, a multi-agent prototype that automates the three core SOC functions—detection, investigation, and response—using specialised AI agents powered by a large language model (LLM). The Sentry agent monitors log files and flags suspicious events using either LLM classification or a built-in rule engine. The Investigator agent gathers related evidence from across the log corpus and asks the LLM to produce a structured root-cause analysis. The Responder agent selects a policy-approved containment action, executes it in a simulated or live environment, and generates a structured Markdown incident report. All three agents run as lightweight Python threads connected through in-memory queues with no external message broker. When the LLM is unavailable, a deterministic fallback engine ensures the pipeline continues to operate. Evaluation across five attack categories—brute-force, data exfiltration, privilege escalation, port scanning, and malware deployment—shows complete detection coverage with end-to-end latency below 60 seconds on a standard laptop. The system demonstrates that a self-contained, locally deployable multi-agent architecture can meaningfully reduce manual effort in routine SOC workflows while preserving human oversight on critical decisions.

Downloads

Download data is not yet available.

Downloads

Published

2026-09-03

How to Cite

SOC-in-a-Box: A Multi-Agent LLM-Based Security Operations Center for Threat Detection and Automated Incident Response. (2026). International Research Journal on Advanced Engineering Hub (IRJAEH), 4(08), 5226-5237. https://doi.org/10.47392/IRJAEH.2026.0684