OpenFrame Gen1 is Here ยท AI-driven, autonomous IT management. Out of beta and ready for production.

Security Information and Event Mgmt. (SIEM)

Automated Tier-1 alert investigation with IOC extraction, threat-intel enrichment, and MITRE ATT&CK-mapped reports.
Integrated SOC case creation and tracking tied to alerts for incident workflow management.
Native connectors for Wazuh, Graylog, Velociraptor, Grafana, InfluxDB, and 40+ third-party vendors.
Multi-tenant style customer provisioning workflows aimed at MSPs managing multiple clients.
Playbook-driven automated response actions across integrated tools.
Threat detection/correlation dashboards and reporting/analytics views.
Purpose-built to sit on top of the SOCFortress open-source SOC stack, reducing integration friction for Wazuh-centric shops.
AGPL-3.0 licensed, self-hostable at no license cost, avoiding vendor lock-in typical of commercial SOC platforms.
Talon automates first-pass investigation and enrichment, potentially cutting Tier-1 analyst time on repetitive alerts.
Built-in customer onboarding and case management designed with MSP/MSSP use cases in mind.
Backed by SOCFortress with docs, Discord support, tutorials, and paid managed services as a fallback.
The project explicitly labels itself "beta," with ongoing breaking changes likely between releases.
Modest star/fork count relative to major SIEM/SOAR platforms; limited third-party plugins or contributors beyond the core team.
Best value is realized when paired with SOCFortress's specific open-source components; less turnkey standalone.
Docker Compose self-hosting only; SOCFortress's SaaS business is a separate managed-service offering.
No public SOC 2/GDPR attestations found; audit logging for analyst actions is still maturing.
Be the first to share your experience with SOCFortress CoPilot.
Reduce costs and increase revenue with OpenFrame innovative open source solutions. Coming soonโฆ
Learn More about OpenFrame