Part of NIT Andhra Pradesh × Wooble Hackathon Festival '26

CipherMind AI '26 banner

Wooble

Open · Closed 30 Aug 2026

CipherMind AI '26

Every Alert Tells a Story. Teach AI to Read It.

Evaluation only · Open

Build an intelligent cyber defense platform that identifies anomalies, uncovers hidden attack patterns, prioritizes critical threats, and assists analysts with AI-generated incident insights in real time.

Overview

Imagine it's 2:17 AM. Somewhere, an employee clicks what looks like a routine invoice email. It wasn't an invoice. Within seconds, malicious code is quietly running. A compromised laptop starts talking to servers it has never contacted before. Credentials are stolen. Sensitive files begin moving across the network. Every second counts. Meanwhile, inside the Security Operations Center (SOC), thousands of alerts are pouring in. A failed login. A suspicious download. A port scan. A malware signature. Another failed login. Hundreds of "low priority" notifications. By sunrise, the company has received over 4,000 security alerts. Only a handful actually matter. The problem isn't a lack of data. It's too much data. Today's attackers don't just write malware—they use AI to craft convincing phishing emails, automate reconnaissance, generate endless malware variants, and adapt faster than traditional security tools can react. The cyber battlefield has changed. Now it's no longer human versus hacker. It's AI versus AI. Your mission is to build the AI teammate every cybersecurity analyst wishes they had—one that learns normal behavior, spots hidden threats, predicts attacks before they spread, groups similar malware automatically, explains what happened in plain English, and helps defenders make faster, smarter decisions. Can your AI become the analyst that never sleeps?

The brief

You are part of the cybersecurity team protecting a fast-growing technology company.

Every day your SOC receives thousands of alerts from firewalls, endpoint protection tools, intrusion detection systems, email gateways, and authentication services.

Most are harmless.

Some are duplicates.

Many are false positives.

But hidden somewhere among them is the alert that could become tomorrow's data breach.

Unfortunately, by the time a human analyst investigates every alert, the attacker has already gained access, moved laterally across the network, escalated privileges, and exfiltrated sensitive data.

Your challenge is to change that.

Build an AI-powered Security Operations Assistant capable of detecting malicious activity before it becomes a major incident.

Your solution should intelligently analyze security data, distinguish real threats from background noise, identify suspicious user and network behavior, predict phishing attempts, discover relationships between malware samples, and provide analysts with clear, actionable insights instead of overwhelming dashboards.

Think beyond simple classification.

Imagine you're building the next generation SOC—one where AI doesn't replace security analysts, but empowers them to make better decisions in seconds instead of hours.

Your solution may include features such as:

AI-based anomaly detection for network and user behavior Phishing email prediction and risk scoring Malware clustering using behavioral similarities Attack timeline visualization AI-generated incident summaries for analysts Threat prioritization based on business impact Explainable AI that justifies every prediction Interactive SOC dashboards and visual analytics

Remember, the best cybersecurity solutions don't just detect attacks.

They help humans understand what happened, why it happened, and what to do next.

This is your opportunity to build an AI defender capable of protecting tomorrow's digital world—one intelligent decision at a time.

Primary Dataset (Mandatory): UNSW-NB15 – A modern network intrusion detection dataset containing normal and malicious network traffic across multiple attack categories, including Fuzzers, Analysis, Backdoors, DoS, Exploits, Generic, Reconnaissance, Shellcode, and Worms.

Official Dataset: https://research.unsw.edu.au/projects/unsw-nb15-dataset

You may use additional publicly available cybersecurity datasets or synthetic data to enhance your solution, provided they are clearly documented in your submission.

Deliverables

  • Working AI Prototype (Mandatory)
  • GitHub Repository with Source Code & README (Mandatory)
  • 3–5 Minute Demo Video (Mandatory)
  • Project Documentation (Mandatory)
  • AI Model Details, Training Process & Evaluation Metrics (Mandatory)
  • Presentation Deck (5–8 Slides) (Optional)
  • Bonus: Interactive Dashboard · Explainable AI (XAI) · Live Deployment · Real-Time Attack Visualization · LLM-Powered Incident Summaries · Innovative Features Beyond the Problem Statement

Evaluation criteria

  • AI Model Performance & Accuracy – 30%
  • Innovation & Technical Implementation – 25%
  • Problem Solving & Practical Impact – 20%
  • User Experience & Explainability – 15%
  • Documentation, Demo & Presentation – 10%

Frequently asked questions

  • Do I need prior cybersecurity experience to participate?

    No. Anyone with an interest in AI, machine learning, data science, cybersecurity, or software development can participate. You'll receive the problem statement and dataset to help you get started.

  • Can I use pre-trained AI models or open-source libraries?

    Yes. You may use open-source frameworks, pre-trained models, and publicly available libraries. However, your solution should clearly demonstrate your implementation, customization, and understanding of the approach.

  • Is it mandatory to use the provided dataset?

    Yes. The UNSW-NB15 dataset is the primary dataset for evaluation. You may use additional publicly available datasets to improve your solution, but you must clearly document them.

  • Can I build additional features beyond the problem statement?

    Absolutely. Innovative additions such as real-time dashboards, LLM-powered incident summaries, explainable AI (XAI), attack simulations, SIEM integrations, or deployment-ready architectures are encouraged and may strengthen your overall submission.

Results

Results expected on 7 Sept 2026.

More challenges at Wooble