Inspiration

Security Operations Center (SOC) analysts need to monitor large volumes of network activity while quickly identifying suspicious behavior. Manual analysis of network logs can make it difficult to prioritize high-risk events and investigate them efficiently.

We built CyberSentinel AI to create a lightweight Blue Team environment where network telemetry can be monitored, suspicious activity can be detected, and alerts can be investigated through a centralized SOC dashboard.

What it does

CyberSentinel AI monitors network metadata and analyzes network logs to identify potentially suspicious activity.

Key capabilities include:

  • Live packet metadata monitoring using Scapy
  • Network traffic and protocol visualization
  • Detection of elevated and high-rate source activity
  • Local IOC watchlist matching
  • Alert severity classification
  • MITRE ATT&CK technique mapping
  • Alert lifecycle management: New, Investigating, Resolved
  • Investigation timeline and analyst notes
  • Offline CSV network log analysis
  • JSON investigation report export

The project focuses on security metadata and does not capture credentials or raw packet payloads.

How we built it

CyberSentinel AI was built using Python, Flask, Scapy, HTML5, CSS3, JavaScript, Chart.js, and REST APIs.

The backend handles packet monitoring, network-log analysis, detection rules, IOC matching, and API endpoints. Scapy is used for live packet metadata collection, while CSV logs can be analyzed offline.

The frontend provides a SOC-style dashboard with traffic charts, alert tables, severity filters, investigation status, timelines, and analyst notes.

Detection rules were implemented for IOC matches, elevated source rates, high-rate activity, large packets, and high-volume sources. Detected events are converted into alerts that can be investigated through the dashboard.

Challenges we ran into

One of the main challenges was designing detection logic that could identify suspicious network behavior without relying on raw packet payloads.

We also had to handle both live packet monitoring and offline CSV analysis while keeping the alert structure consistent.

Another challenge was designing a practical SOC workflow where alerts could be prioritized, investigated, updated, and documented rather than simply displayed.

Accomplishments that we're proud of

We are proud of building a complete Blue Team / SOC workflow instead of only a network monitoring dashboard.

CyberSentinel AI combines network telemetry, rule-based detection, local IOC intelligence, MITRE ATT&CK mapping, alert triage, investigation notes, timelines, and report generation in one interface.

We also created a safe demo network dataset so the project can be tested without requiring access to real malicious traffic.

What we learned

Through this project, we gained practical experience with network monitoring, packet metadata analysis, IOC matching, alert triage, SOC workflows, and security dashboard design.

We also learned that effective security monitoring requires more than detecting an event. Analysts need context, severity, investigation state, evidence, and a way to document their findings.

What's next for CyberSentinel AI

Future improvements could include:

  • Integration with external threat-intelligence feeds
  • More advanced behavioral detection
  • Additional MITRE ATT&CK mappings
  • Persistent backend storage for alerts and investigations
  • Role-based access for SOC analysts
  • Automated alert enrichment
  • Integration with SIEM and security monitoring platforms
  • More advanced anomaly detection models

Built With

Share this project:

Updates

Submission history