Sitemap

🚀 AI Agent for Your Open-Source SIEM Stack Is Here — Wazuh, Velociraptor, and CoPilot Just Got Smarter

3 min readJul 28, 2025

--

I’m excited to officially announce one of the biggest updates we’ve made to SOCFortress CoPilot — the launch of our integrated AI Chat Agent for direct, natural language interaction with your Wazuh Manager, Wazuh Indexer (OpenSearch), Velociraptor, and of course, CoPilot itself.

This feature brings a massive shift in how you interact with your stack — think of it as adding an AI-powered Tier-1 SOC analyst directly inside your environment.

⚠️ Get Started with CoPilot Here: https://github.com/socfortress/CoPilot

đź’ˇ Why This Matters

Security analysts spend a lot of time pivoting between dashboards, writing search queries, filtering through event noise, and hunting for useful data across systems. This new update brings a conversational interface to the heart of your SIEM stack, allowing you to:

âś… Query Wazuh agents and status

âś… Extract and summarize Wazuh-Indexer logs

âś… Launch Velociraptor artifacts with plain English

âś… Interact with CoPilot case data and tenant-specific integrations

The result? Faster investigations, better data access, and less time lost digging through consoles.

đź”§ How It Works

With this update, we’ve introduced a new CoPilot MCP service — a dedicated container that facilitates natural language queries across Wazuh-Manager, Wazuh-Indexer (OpenSearch), Velociraptor, and CoPilot’s own backend. This service plugs directly into your Docker Compose environment and works alongside your existing stack.

The AI agent parses your request, determines intent, chooses the right tool, and executes — using carefully constructed prompt templates and inference logic tailored for each data source.

✍️ Example Use Cases

Here’s what you can now do — just by asking:

  • “How many alerts does the Lab customer have?”
  • “What third-party integrations are deployed for Customer B?”
  • “What is the cluster health of my Wazuh Indexer?”
  • “What are the most critical vulnerabilities for Agent X?”
  • “What users have RDP’d into this host recently?”
  • “Run the Windows.System.Users artifact on endpoint123”
  • “Show me SCA findings for Agent001”

In the background, the AI agent invokes the appropriate API parses results, and returns them in a readable format — sometimes even with hyperlinks back to the original records or vulnerabilities.

This current release is built and tested exclusively with OpenAI’s gpt-4o model. That’s the model I had access to during development and the only one that currently gives me the speed and reliability needed to support production use.

That said, I absolutely understand and share your interest in running self-hosted models — and that’s something I’m actively exploring for future releases. But in the meantime, GPT-4o provides a great balance of accuracy and capability for the types of structured queries this AI agent performs.

🛠️ Setup Summary

To get started with the AI Agent:

  1. Update your Docker Compose file with the new copilot-mcp service
  2. Add new environment variables in your .env file (OpenAI API key, Wazuh Manager URL, Wazuh-Indexer(OpenSearch) creds, etc.)
  3. Mount your Velociraptor API config file into the copilot-mcp container
  4. Pull the latest images and restart CoPilot

Once deployed, you’ll see a new chat icon in the CoPilot UI — from there, you can start asking questions directly to your stack.

đź’¬ Final Thoughts

This feature is still in its early days — but the results have been impressive. From querying vulnerabilities to launching live forensic artifacts, the AI Agent has become a powerful assistant in the SOCFortress ecosystem.

I’m continuing to build on this foundation and have more planned (like persistent chat history and support for more tools). But today, I’m thrilled to get this into your hands.

👉 Go check out the GitHub repo, update your stack, and let me know what you think! https://github.com/socfortress/CoPilot

👨‍💻 Got feedback or ideas? Drop a comment or reach out directly.

Thanks for reading, and stay tuned — more updates coming soon.

Need Help?

The functionality discussed in this post, and so much more, are available via the SOCFortress platform. Let SOCFortress help you and your team keep your infrastructure secure.

Website: https://www.socfortress.co/

Contact Us: https://www.socfortress.co/contact_form.html

Press enter or click to view image in full size

--

--

SOCFortress
SOCFortress

Written by SOCFortress

SOCFortress is a SaaS company that unifies Observability, Security Monitoring, Threat Intelligence and Security Orchestration, Automation, and Response (SOAR).