AI Agentic · Evidence First · Self Hosted

Threat Hunting
Operating System.

Connect THOS to your existing SIEM, EDR, XDR and security telemetry to start AI-powered, hypothesis-driven threat hunting—without replacing your SIEM, migrating data, or changing vendors.

Threat hunting firstOverview, detections, intelligence, risk and forensics support the hunt.
Works with your stackAdd an AI hunting layer above existing security investments.
Analyst governedRead-only actions, deterministic evidence gates and verified citations.
Agentic hunting workflow

From hypothesis to defensible findings.

THOS coordinates specialist agents and governed tools to plan hunts, retrieve bounded telemetry, correlate evidence, enrich findings, map ATT&CK coverage and produce reports only when supported signals exist.

Not an autonomous containment system. THOS does not isolate hosts, block traffic, delete evidence, deploy live rules or make attribution decisions.

1. Plan

Supervisor planning, hypothesis context and hunt memory define the investigation path.

2. Retrieve

Connectors collect bounded evidence from SIEMs, files and approved security sources.

3. Validate

Normalization, guardrails and evidence screening stop unsupported hunts before reasoning.

4. Investigate

Specialist agents adapt retrieval, correlate intelligence and verify citations.

5. Operationalize

THOS produces evidence-backed hunt reports, ATT&CK coverage, risk context and draft detection improvements for analyst review.

One hunting workspace

Everything supports the hunt.

THOS is not a broad SIEM replacement. Its supporting modules give hunters the context, evidence and operational continuity needed to investigate unknown threats.

Hunt Board

HEARTH and local hypotheses, ATT&CK mappings, live agent progress and prior-run context.

Detection Monitoring

Stable detection IDs, source-event evidence and concise AI-assisted analysis.

Threat Intelligence

Local IOC management, source freshness and correlation against hunt evidence.

Digital Forensics

Evidence hashing, chain of custody, timelines, YARA and governed artifact analysis.

Risks & Reports

Verified entity-level risks, investigation reports and Markdown/PDF export.

Ask THOS

Read-only assistance with specialist delegation for hunting and forensic questions.

Plug in, do not replace

Use the telemetry you already own.

THOS can sit alongside existing SIEM, EDR, XDR, identity, cloud, email, network and file-based sources. Live connections must pass governed connection tests before hunts or schedules can use them.

WazuhElasticsearchSplunkIBM QRadarLogRhythmEVTXCSV / JSONSyslogPCAP / PCAPNGGeneric APIs

Local-first architecture

React, FastAPI, LangGraph, FastMCP, Ollama, ChromaDB, PostgreSQL and Redis.

Deployment

Self-hosted with Docker Compose; only the analyst UI is published by default.

Security boundaries

Signed sessions, role enforcement, API keys, allowlisted evidence roots and prompt-injection screening.

License

Source-available under BUSL-1.1, with each release converting to Apache 2.0 after four years.