Work Packages & Deliverables

Developing the Next Generation of AI-powered Security Operations
5Work Packages
11Deliverables

The aSIEMmetry project is organised into five complementary Work Packages (WPs), each addressing a key aspect of the research, development, validation and dissemination of AI-driven cybersecurity technologies.

Together, these work packages ensure that innovative research is transformed into practical solutions capable of supporting Security Operations Centres (SOCs) across Europe.

The aSIEMmetry project produces a range of scientific, technical and management deliverables throughout its implementation. These deliverables document the progress of the project, the technologies developed and the results achieved by the consortium.

In accordance with the Horizon Europe Grant Agreement, only deliverables classified as Public (PU) are made available for download through this website. Deliverables classified as Sensitive (SEN) contain technical, operational or security-related information and are therefore not publicly accessible.

Public deliverables will be published after their submission to and approval by the European Commission.

The objective of WP1 is to ensure the efficient management, coordination and quality assurance of the aSIEMmetry project throughout its lifetime. The work package establishes the organisational, administrative and financial framework necessary for successful project implementation while ensuring compliance with Horizon Europe requirements.

WP1 coordinates communication between consortium partners, monitors project progress against planned objectives and milestones, manages risks, and oversees quality assurance activities. It also coordinates communication, dissemination and stakeholder engagement activities to maximise the visibility and impact of the project results across the European cybersecurity community.

Key activities

  • Overall project coordination and administration
  • Financial, technical and quality management
  • Risk monitoring and mitigation
  • Consortium collaboration and governance
  • Communication, dissemination and stakeholder engagement
  • Reporting to the European Commission

Deliverables

Report (R) Public (PU)

D1.1 – Intermediate dissemination and adoption report

Report (R) Public (PU)

D1.2 – Project completion report

Report (R) Public (PU)

D1.3 – Communication and exploitation plan

WP2 establishes the technological foundation of the project by designing and deploying the Cybersecurity and Artificial Intelligence (CS/AI) Laboratory. This environment provides the infrastructure required for the development, testing and validation of advanced Artificial Intelligence capabilities dedicated to Security Operations Centres (SOCs).

The work package develops the Security Entropy Framework, deploys a self-hosted Large Language Model (LLM), and integrates these technologies into the project platform. The laboratory enables secure experimentation, model development and validation using operational cybersecurity data while ensuring compatibility with existing SIEM and SOC environments.

Key activities

  • Design and deployment of the CS/AI Laboratory
  • Development of the Security Entropy Framework
  • Deployment of a self-hosted Large Language Model
  • Integration of AI technologies with SIEM and SOC platforms
  • Validation of the technical infrastructure

Deliverables

Demonstrator (DEM) Sensitive (SEN)

D2.1 – Multi-agent asset modeler code

Not publicly available
Demonstrator (DEM) Sensitive (SEN)

D2.2 – Security entropy monitor code

Not publicly available

WP3 focuses on training, enriching and optimising the Artificial Intelligence models developed within the project using operational cybersecurity data collected from Security Information and Event Management (SIEM) platforms and Security Operations Centres (SOCs).

The work package applies machine learning techniques, behavioural analytics and entropy-driven modelling to improve cyber threat detection capabilities. It also enhances the specialised Large Language Model with cybersecurity knowledge derived from real operational environments, enabling more accurate analysis, contextual understanding and decision support for security analysts.

Key activities

  • Training the Security Entropy model
  • Enrichment using operational SIEM and SOC datasets
  • Optimisation of AI model performance
  • Integration of threat intelligence and behavioural analytics
  • Training of the specialised LLM SOC Agent

Deliverables

Report (R) Sensitive (SEN)

D3.1 – Summary ML training report for the "security entropy" agent

Not publicly available
Report (R) Sensitive (SEN)

D3.2 – Summary training report for the self-hosted "LLM SOCagent"

Not publicly available

WP4 develops and validates innovative Security Operations Centre (SOC) processes that leverage the Artificial Intelligence technologies created during the project. The objective is to transform advanced AI capabilities into practical operational workflows that improve the efficiency, effectiveness and resilience of cybersecurity operations.

The work package demonstrates how the Security Entropy Framework and AI-assisted analysis can support threat detection, investigation, incident response and operational decision-making within modern Security Operations Centres.

Key activities

  • Development of AI-enhanced SOC operational processes
  • Integration of the Security Entropy Framework into SOC workflows
  • Validation of novel cybersecurity operational procedures
  • Demonstration and evaluation of operational improvements

Deliverables

Demonstrator (DEM) Sensitive (SEN)

D4.1 – Demo for novel SOC processes developed

Not publicly available
Report (R) Sensitive (SEN)

D4.2 – Summary report: Novel SOC processes leveraging "security entropy" model

Not publicly available

WP5 focuses on augmenting Security Operations Centre analysts through the combination of Human Intelligence (HI) and Artificial Intelligence (AI). The work package develops intelligent assistance capabilities that support analysts throughout the incident investigation and response lifecycle while maintaining human oversight and decision-making.

Activities include the development and evaluation of specialised Large Language Model assistants, assessment of self-hosted and cloud-based AI technologies, and the definition of best practices for the adoption of Artificial Intelligence within Security Operations Centres.

Key activities

  • Development of AI-assisted SOC analyst use cases
  • Training and evaluation of the specialised LLM SOC Agent
  • Assessment of self-hosted and cloud-based LLM technologies
  • Evaluation of Human Intelligence and AI collaboration
  • Development of recommendations for AI adoption in Security Operations Centres

Deliverables

Demonstrator (DEM) Public (PU)

D5.1 – Demo self-hosted "LLM SOCagent"

Report (R) Sensitive (SEN)

D5.2 – Summary report: "AI adoption for SOC analysts" white paper

Not publicly available

Working Together

The five work packages form an integrated innovation framework that transforms research into operational cybersecurity capabilities for next-generation Security Operations Centres (SOCs).

WP1Management & CoordinationProject Management & Coordination
WP2CS/AI Lab & Security EntropyBuild CS/AI lab. Develop "security entropy" model
WP3Model TrainingModels training & enrichment using live SIEM / SOC data
WP4AI-Enhanced SOC ProcessesDevelop AI enhanced novel SOC processes based on "security entropy"
WP5Next-Gen SOC AnalystsDevelop AI enhanced Next-gen SOC analysts

The aSIEMmetry project follows a progressive development approach in which each work package builds upon the outcomes of the previous one.

The project begins by establishing a secure Cybersecurity and Artificial Intelligence Laboratory and developing the Security Entropy Framework (WP2). These technologies are then trained and refined using operational SIEM and SOC data (WP3), enabling the development of innovative AI-enhanced Security Operations Centre processes (WP4). Finally, these capabilities are combined to support the next generation of SOC analysts through Human Intelligence and Artificial Intelligence collaboration (WP5).

Throughout the project, WP1 provides the coordination, quality assurance and governance required to ensure the successful delivery of all technical and scientific activities.

This integrated approach enables aSIEMmetry to deliver innovative, trustworthy and operationally relevant Artificial Intelligence technologies that strengthen cyber threat detection, improve incident response and enhance the resilience of Security Operations Centres across Europe.

Notes

  • The dissemination level of each deliverable is defined in the Horizon Europe Grant Agreement (Annex I).
  • Only deliverables classified as Public (PU) are made available through this website. Deliverables classified as Sensitive (SEN) contain technical, operational or cybersecurity-related information and are therefore not publicly accessible.
  • Additional public deliverables will be published as they become available during the lifetime of the project.
Back to top