Skip to content

About

ML- and agent-driven SOC platform for healthcare — DICOM/HL7/FHIR detection, ML playbooks, and an autonomous AI SOC agent.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

Pink Hat — Multi-Zone SOC Platform for Healthcare

An ML- and agent-driven Security Operations Center purpose-built for clinical environments: healthcare-protocol detection (DICOM / HL7 / FHIR), ML-driven response playbooks, and an autonomous AI SOC agent that investigates alerts end to end.

🌐 Project site: https://pinkhat-soc.netlify.app 🧩 Detection-as-code: github.com/AdamChokri/pinkhat-detections 🎥 Demo: (added during the Phase 1 demo recording)

⚠️ All sample data in this project is synthetic (e.g. Synthea-generated). No PHI. Internal lab identifiers (IPs, hostnames, AD domain) are intentionally excluded from this repository.


What Pink Hat is

Pink Hat is a multi-zone SOC built around the threats specific to healthcare — the clinical protocols and patient-data workflows that most generic SOC tooling never monitors. It pairs signature and ML-based detection with a layer of automated response playbooks, all coordinated by P31, an autonomous agent (built on the Claude tool-use API) that runs Tier 1/2 investigations from alert to containment without a human in the loop.

The platform stitches open-source SOC tooling — Wazuh, Shuffle SOAR, DFIR-IRIS, IntelOwl, MISP, and Velociraptor — into a single investigation-to-containment pipeline, with a real-time React dashboard ("Pink Hat Command") on top.


Architecture

flowchart LR
  EP[Endpoints & clinical devices] -->|DICOM/HL7/FHIR + endpoint logs| W[Wazuh]
  W --> IDX[(Wazuh Indexer / OpenSearch)]
  IDX --> ML[ML detection playbooks]
  IDX --> AGENT[P31 — Autonomous SOC Agent<br/>Claude tool-use · ReAct loop]
  ML --> AGENT
  AGENT -->|IOC enrichment| IO[IntelOwl]
  AGENT -->|threat intel| MISP[MISP]
  AGENT -->|endpoint hunt| VR[Velociraptor]
  AGENT -->|case management| IRIS[DFIR-IRIS]
  AGENT -->|containment| SH[Shuffle SOAR]
  AGENT --> DASH[Pink Hat Command<br/>React + FastAPI · SSE streaming]
Loading

The lab is segmented into multiple zones (DMZ, LAN, SOC, and a deception zone) behind open-source firewalls — a realistic enterprise-style topology rather than a flat network.


Detection & response playbooks

Pink Hat ships a set of playbooks spanning signature detection, ML-driven analytics, and LLM-assisted response. The core ones:

ID Playbook Approach
P01 Ransomware detection LSTM + reinforcement learning
P02 PHI insider-threat / UEBA Isolation Forest
P05 HIPAA breach assessment LLM + RAG
P06 Clinical-protocol abuse (DICOM/HL7/FHIR) Signature + anomaly detection
P26 Clinical workflow-aware IR Patient-safety risk scoring
P34 Unified deception platform T-Pot honeypots + honeytokens
P31 Autonomous SOC agent (orchestrator) Claude tool-use · ReAct reasoning loop

The detection logic behind these — re-expressed as portable, MITRE ATT&CK-mapped Sigma rules plus model cards for the ML detections — lives in the companion repo: pinkhat-detections.


P31 — the autonomous SOC agent

P31 is the centerpiece: an LLM agent that investigates security alerts the way a Tier 1/2 analyst would, but autonomously. Driven by a ReAct (Reason + Act) loop over the Claude tool-use API, it:

  • reads incoming Wazuh alerts,
  • queries tools — IntelOwl for IOC enrichment, MISP for threat intel, Velociraptor for endpoint hunts, and Active Directory for account context,
  • opens and updates DFIR-IRIS cases,
  • triggers containment through Shuffle SOAR, and
  • produces a structured, HIPAA-aware incident report (exportable to PDF).

The dashboard ("Pink Hat Command") streams the agent's reasoning live via SSE, with a React + Vite frontend and a FastAPI backend.

🔒 Security note: P31 is an agentic LLM with tool access. Hardening it against the OWASP Agentic Top 10 and MITRE ATLAS (prompt injection, excessive agency, tool-call abuse) is the subject of a forthcoming red-team case study, at which point the agent graduates to its own dedicated, scrubbed repository.


Tech stack

Layer Tools
Detection & SIEM Wazuh · OpenSearch (Wazuh indexer)
Orchestration & response Shuffle SOAR · DFIR-IRIS
Threat intel & enrichment IntelOwl · MISP
Endpoint forensics Velociraptor
Deception T-Pot
AI / ML Claude API (agent) · LSTM/RL, Isolation Forest, RAG
Dashboard React + Vite (frontend) · FastAPI + SSE (backend)
Identity LDAP / Active Directory authentication

Roadmap

  • ✅ Platform build — multi-zone lab, playbook suite, P31 agent, Pink Hat Command dashboard
  • 🔄 Public detection-as-code — Sigma rules (incl. original DICOM/HL7/FHIR), ML model cards, ATT&CK coverage
  • ⏳ P31 red-team & hardening — OWASP Agentic Top 10 / MITRE ATLAS, with before/after results

Data & privacy

All sample data is synthetic. No PHI. This repository contains architecture, documentation, and overview material only — no credentials, no internal IPs, hostnames, or domain names.

License

MIT — see LICENSE.


Built by Adam Chokri — Network Infrastructure & Digital Security (NIDS), ESPRIT, 2026.

About

ML- and agent-driven SOC platform for healthcare — DICOM/HL7/FHIR detection, ML playbooks, and an autonomous AI SOC agent.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors