The aSIEMmetry project is organised into five complementary Work Packages (WPs), each addressing a key aspect of the research, development, validation and dissemination of AI-driven cybersecurity technologies.
Together, these work packages ensure that innovative research is transformed into practical solutions capable of supporting Security Operations Centres (SOCs) across Europe.
The aSIEMmetry project produces a range of scientific, technical and management deliverables throughout its implementation. These deliverables document the progress of the project, the technologies developed and the results achieved by the consortium.
In accordance with the Horizon Europe Grant Agreement, only deliverables classified as Public (PU) are made available for download through this website. Deliverables classified as Sensitive (SEN) contain technical, operational or security-related information and are therefore not publicly accessible.
Public deliverables will be published after their submission to and approval by the European Commission.
Project Management and Coordination
The objective of WP1 is to ensure the efficient management, coordination and quality assurance of the aSIEMmetry project throughout its lifetime. The work package establishes the organisational, administrative and financial framework necessary for successful project implementation while ensuring compliance with Horizon Europe requirements.
WP1 coordinates communication between consortium partners, monitors project progress against planned objectives and milestones, manages risks, and oversees quality assurance activities. It also coordinates communication, dissemination and stakeholder engagement activities to maximise the visibility and impact of the project results across the European cybersecurity community.
Key activities
- Overall project coordination and administration
- Financial, technical and quality management
- Risk monitoring and mitigation
- Consortium collaboration and governance
- Communication, dissemination and stakeholder engagement
- Reporting to the European Commission
Deliverables
D1.2 – Project completion report
D1.3 – Communication and exploitation plan
Build the CS/AI Lab and Develop the Security Entropy Model
WP2 establishes the technological foundation of the project by designing and deploying the Cybersecurity and Artificial Intelligence (CS/AI) Laboratory. This environment provides the infrastructure required for the development, testing and validation of advanced Artificial Intelligence capabilities dedicated to Security Operations Centres (SOCs).
The work package develops the Security Entropy Framework, deploys a self-hosted Large Language Model (LLM), and integrates these technologies into the project platform. The laboratory enables secure experimentation, model development and validation using operational cybersecurity data while ensuring compatibility with existing SIEM and SOC environments.
Key activities
- Design and deployment of the CS/AI Laboratory
- Development of the Security Entropy Framework
- Deployment of a self-hosted Large Language Model
- Integration of AI technologies with SIEM and SOC platforms
- Validation of the technical infrastructure
Deliverables
D2.1 – Multi-agent asset modeler code
D2.2 – Security entropy monitor code
Model(s) training & enrichment based on live SIEM and SOC data
WP3 focuses on training, enriching and optimising the Artificial Intelligence models developed within the project using operational cybersecurity data collected from Security Information and Event Management (SIEM) platforms and Security Operations Centres (SOCs).
The work package applies machine learning techniques, behavioural analytics and entropy-driven modelling to improve cyber threat detection capabilities. It also enhances the specialised Large Language Model with cybersecurity knowledge derived from real operational environments, enabling more accurate analysis, contextual understanding and decision support for security analysts.
Key activities
- Training the Security Entropy model
- Enrichment using operational SIEM and SOC datasets
- Optimisation of AI model performance
- Integration of threat intelligence and behavioural analytics
- Training of the specialised LLM SOC Agent
Deliverables
D3.1 – Summary ML training report for the "security entropy" agent
D3.2 – Summary training report for the self-hosted "LLM SOCagent"
Develop AI enhanced novel SOC processes based on "security entropy"
WP4 develops and validates innovative Security Operations Centre (SOC) processes that leverage the Artificial Intelligence technologies created during the project. The objective is to transform advanced AI capabilities into practical operational workflows that improve the efficiency, effectiveness and resilience of cybersecurity operations.
The work package demonstrates how the Security Entropy Framework and AI-assisted analysis can support threat detection, investigation, incident response and operational decision-making within modern Security Operations Centres.
Key activities
- Development of AI-enhanced SOC operational processes
- Integration of the Security Entropy Framework into SOC workflows
- Validation of novel cybersecurity operational procedures
- Demonstration and evaluation of operational improvements
Deliverables
D4.1 – Demo for novel SOC processes developed
D4.2 – Summary report: Novel SOC processes leveraging "security entropy" model
Develop AI enhanced Next-gen SOC analysts
WP5 focuses on augmenting Security Operations Centre analysts through the combination of Human Intelligence (HI) and Artificial Intelligence (AI). The work package develops intelligent assistance capabilities that support analysts throughout the incident investigation and response lifecycle while maintaining human oversight and decision-making.
Activities include the development and evaluation of specialised Large Language Model assistants, assessment of self-hosted and cloud-based AI technologies, and the definition of best practices for the adoption of Artificial Intelligence within Security Operations Centres.
Key activities
- Development of AI-assisted SOC analyst use cases
- Training and evaluation of the specialised LLM SOC Agent
- Assessment of self-hosted and cloud-based LLM technologies
- Evaluation of Human Intelligence and AI collaboration
- Development of recommendations for AI adoption in Security Operations Centres
Deliverables
D5.1 – Demo self-hosted "LLM SOCagent"
D5.2 – Summary report: "AI adoption for SOC analysts" white paper
Working Together
The five work packages form an integrated innovation framework that transforms research into operational cybersecurity capabilities for next-generation Security Operations Centres (SOCs).
The aSIEMmetry project follows a progressive development approach in which each work package builds upon the outcomes of the previous one.
The project begins by establishing a secure Cybersecurity and Artificial Intelligence Laboratory and developing the Security Entropy Framework (WP2). These technologies are then trained and refined using operational SIEM and SOC data (WP3), enabling the development of innovative AI-enhanced Security Operations Centre processes (WP4). Finally, these capabilities are combined to support the next generation of SOC analysts through Human Intelligence and Artificial Intelligence collaboration (WP5).
Throughout the project, WP1 provides the coordination, quality assurance and governance required to ensure the successful delivery of all technical and scientific activities.
This integrated approach enables aSIEMmetry to deliver innovative, trustworthy and operationally relevant Artificial Intelligence technologies that strengthen cyber threat detection, improve incident response and enhance the resilience of Security Operations Centres across Europe.
Notes
- The dissemination level of each deliverable is defined in the Horizon Europe Grant Agreement (Annex I).
- Only deliverables classified as Public (PU) are made available through this website. Deliverables classified as Sensitive (SEN) contain technical, operational or cybersecurity-related information and are therefore not publicly accessible.
- Additional public deliverables will be published as they become available during the lifetime of the project.