PhishSlayerPHISHSLAYER
Agent-assisted SOC for MSSPs

PhishSlayer turns alert evidence into analyst-approved action.

A demo-ready security operations surface for Wazuh-based alert triage, L2 investigation, and human-approved endpoint containment.

Evidence Flow

The demo emphasizes traceable decisions, scoped blast radius, and explicit analyst control.

HITL
Alert
Wazuh event received and scoped to the current organization
L1
Verdict, confidence, MITRE mapping, and enrichment context
L2
OPPLAN, Diamond Model, critic notes, and proposed response
HITL
Analyst checks mapped endpoint before approval
AR
Wazuh execution evidence retained; rollback remains dry-run safety

Detect

Ingest Wazuh alerts with the raw payload retained for analyst review.

Investigate

Use L1 triage and L2 investigation evidence before any response decision.

Respond

Send human-approved containment only to mapped Wazuh endpoints.

Safety posture

PhishSlayer presents rollback as dry-run safety evidence only. It does not claim complete SOAR, broad SIEM coverage, or autonomous organization-wide response.