An ML- and agent-driven Security Operations Center purpose-built for clinical environments: healthcare-protocol detection (DICOM / HL7 / FHIR), ML-driven response playbooks, and an autonomous AI SOC agent that investigates alerts end to end.
🌐 Project site: https://pinkhat-soc.netlify.app
🧩 Detection-as-code: github.com/AdamChokri/pinkhat-detections
🎥 Demo: (added during the Phase 1 demo recording)
⚠️ All sample data in this project is synthetic (e.g. Synthea-generated). No PHI. Internal lab identifiers (IPs, hostnames, AD domain) are intentionally excluded from this repository.
Pink Hat is a multi-zone SOC built around the threats specific to healthcare — the clinical protocols and patient-data workflows that most generic SOC tooling never monitors. It pairs signature and ML-based detection with a layer of automated response playbooks, all coordinated by P31, an autonomous agent (built on the Claude tool-use API) that runs Tier 1/2 investigations from alert to containment without a human in the loop.
The platform stitches open-source SOC tooling — Wazuh, Shuffle SOAR, DFIR-IRIS, IntelOwl, MISP, and Velociraptor — into a single investigation-to-containment pipeline, with a real-time React dashboard ("Pink Hat Command") on top.
flowchart LR
EP[Endpoints & clinical devices] -->|DICOM/HL7/FHIR + endpoint logs| W[Wazuh]
W --> IDX[(Wazuh Indexer / OpenSearch)]
IDX --> ML[ML detection playbooks]
IDX --> AGENT[P31 — Autonomous SOC Agent<br/>Claude tool-use · ReAct loop]
ML --> AGENT
AGENT -->|IOC enrichment| IO[IntelOwl]
AGENT -->|threat intel| MISP[MISP]
AGENT -->|endpoint hunt| VR[Velociraptor]
AGENT -->|case management| IRIS[DFIR-IRIS]
AGENT -->|containment| SH[Shuffle SOAR]
AGENT --> DASH[Pink Hat Command<br/>React + FastAPI · SSE streaming]
The lab is segmented into multiple zones (DMZ, LAN, SOC, and a deception zone) behind open-source firewalls — a realistic enterprise-style topology rather than a flat network.
Pink Hat ships a set of playbooks spanning signature detection, ML-driven analytics, and LLM-assisted response. The core ones:
| ID | Playbook | Approach |
|---|---|---|
| P01 | Ransomware detection | LSTM + reinforcement learning |
| P02 | PHI insider-threat / UEBA | Isolation Forest |
| P05 | HIPAA breach assessment | LLM + RAG |
| P06 | Clinical-protocol abuse (DICOM/HL7/FHIR) | Signature + anomaly detection |
| P26 | Clinical workflow-aware IR | Patient-safety risk scoring |
| P34 | Unified deception platform | T-Pot honeypots + honeytokens |
| P31 | Autonomous SOC agent (orchestrator) | Claude tool-use · ReAct reasoning loop |
The detection logic behind these — re-expressed as portable, MITRE ATT&CK-mapped Sigma rules plus model cards for the ML detections — lives in the companion repo:
pinkhat-detections.
P31 is the centerpiece: an LLM agent that investigates security alerts the way a Tier 1/2 analyst would, but autonomously. Driven by a ReAct (Reason + Act) loop over the Claude tool-use API, it:
- reads incoming Wazuh alerts,
- queries tools — IntelOwl for IOC enrichment, MISP for threat intel, Velociraptor for endpoint hunts, and Active Directory for account context,
- opens and updates DFIR-IRIS cases,
- triggers containment through Shuffle SOAR, and
- produces a structured, HIPAA-aware incident report (exportable to PDF).
The dashboard ("Pink Hat Command") streams the agent's reasoning live via SSE, with a React + Vite frontend and a FastAPI backend.
🔒 Security note: P31 is an agentic LLM with tool access. Hardening it against the OWASP Agentic Top 10 and MITRE ATLAS (prompt injection, excessive agency, tool-call abuse) is the subject of a forthcoming red-team case study, at which point the agent graduates to its own dedicated, scrubbed repository.
| Layer | Tools |
|---|---|
| Detection & SIEM | Wazuh · OpenSearch (Wazuh indexer) |
| Orchestration & response | Shuffle SOAR · DFIR-IRIS |
| Threat intel & enrichment | IntelOwl · MISP |
| Endpoint forensics | Velociraptor |
| Deception | T-Pot |
| AI / ML | Claude API (agent) · LSTM/RL, Isolation Forest, RAG |
| Dashboard | React + Vite (frontend) · FastAPI + SSE (backend) |
| Identity | LDAP / Active Directory authentication |
- ✅ Platform build — multi-zone lab, playbook suite, P31 agent, Pink Hat Command dashboard
- 🔄 Public detection-as-code — Sigma rules (incl. original DICOM/HL7/FHIR), ML model cards, ATT&CK coverage
- ⏳ P31 red-team & hardening — OWASP Agentic Top 10 / MITRE ATLAS, with before/after results
All sample data is synthetic. No PHI. This repository contains architecture, documentation, and overview material only — no credentials, no internal IPs, hostnames, or domain names.
MIT — see LICENSE.
Built by Adam Chokri — Network Infrastructure & Digital Security (NIDS), ESPRIT, 2026.