aSIEMmetry is being developed as an enhancement for existing Security Operations Centre environments. Its objective is not to replace SIEM platforms or established detection controls, but to add AI-driven capabilities that improve anomaly recognition, investigation and analyst decision support.
This integration-oriented approach is important because SOC environments are already built around multiple data sources, procedures and security products. Introducing a new capability must therefore respect existing operational workflows and avoid creating another isolated tool.
Using the data already available to the SOC
SIEM systems collect events from endpoints, networks, applications, identities and cloud services. aSIEMmetry aims to use this telemetry as the basis for behavioural analysis and security entropy calculations.
\n\n
To make the information suitable for AI processing, the project must address normalization, asset identification, timing and data quality. Incomplete or inconsistent telemetry can reduce the reliability of any model, regardless of how advanced the underlying algorithm may be.
Returning useful results to analysts
Integration is not complete when data reaches the AI pipeline. The results must also return to the analyst in a practical format. Entropy scores, anomaly explanations and SOCagent summaries should be connected to the underlying evidence and presented within a workflow that supports investigation.
\n\n
The project is exploring how these outputs can complement existing alerts, cases and response procedures. The goal is to reduce the effort required to connect events while avoiding unnecessary duplication.
Preserving human control
AI-assisted SOC operations still require human oversight. Analysts must be able to inspect the evidence behind a recommendation and decide whether an escalation or response action is appropriate.
This requirement influences both the technical architecture and the user-facing design. Explainability, permissions, auditability and clear separation between suggestions and approved actions are essential for trusted adoption.
\n\n
By focusing on integration with existing SOC capabilities, aSIEMmetry aims to provide organizations with a realistic path toward NextGen SOC operations. The project’s value will depend not only on model performance, but also on how effectively the models can become part of everyday security monitoring and incident response.