Overview
Security posture, active hunts, detections and operational activity in one focused view.
Connect THOS to your existing SIEM, EDR, XDR and security telemetry to start AI-powered, hypothesis-driven threat hunting—without replacing your SIEM, migrating data, or changing vendors.
THOS coordinates specialist agents and governed tools to plan hunts, retrieve bounded telemetry, correlate evidence, enrich findings, map ATT&CK coverage and produce reports only when supported signals exist.
Supervisor planning, hypothesis context and hunt memory define the investigation path.
Connectors collect bounded evidence from SIEMs, files and approved security sources.
Normalization, guardrails and evidence screening stop unsupported hunts before reasoning.
Specialist agents adapt retrieval, correlate intelligence and verify citations.
THOS produces evidence-backed hunt reports, ATT&CK coverage, risk context and draft detection improvements for analyst review.
THOS is not a broad SIEM replacement. Its supporting modules give hunters the context, evidence and operational continuity needed to investigate unknown threats.
HEARTH and local hypotheses, ATT&CK mappings, live agent progress and prior-run context.
Stable detection IDs, source-event evidence and concise AI-assisted analysis.
Local IOC management, source freshness and correlation against hunt evidence.
Evidence hashing, chain of custody, timelines, YARA and governed artifact analysis.
Verified entity-level risks, investigation reports and Markdown/PDF export.
Read-only assistance with specialist delegation for hunting and forensic questions.
THOS can sit alongside existing SIEM, EDR, XDR, identity, cloud, email, network and file-based sources. Live connections must pass governed connection tests before hunts or schedules can use them.
React, FastAPI, LangGraph, FastMCP, Ollama, ChromaDB, PostgreSQL and Redis.
Self-hosted with Docker Compose; only the analyst UI is published by default.
Signed sessions, role enforcement, API keys, allowlisted evidence roots and prompt-injection screening.
Source-available under BUSL-1.1, with each release converting to Apache 2.0 after four years.