Back to SYED's profile
2views

CipherMind SOC

CipherMind SOC doesn’t drown analysts in alerts—it searches the entire telemetry landscape for the strongest suspicious signal, connects the evidence behind it,

SYED HUZAIFA NIT ANP
  • Expert reviewed
CipherMind SOC

16,238

Network flows globally analyzed

93.1/100

Strongest investigation lead identified

0.7121

Behavioral clustering silhouette score

Overview

Every SOC receives thousands of security alerts, but only a few deserve immediate attention. Traditional systems often treat each network event as an isolated classification problem, creating alert fatigue and fragmented investigations.

CipherMind SOC takes a different approach: instead of asking “Is this row malicious?”, it asks “What activity across the entire telemetry set deserves investigation first?”

The system analyzes the complete available network telemetry using supervised attack-family classification, novelty detection, and behavioral analysis. It then globally ranks suspicious activity, identifies the strongest investigation lead, correlates related events across time and entities, and reconstructs the evidence chronologically through a live replay and interactive evidence graph.

A core safety principle drives the platform: no evidence means no claim. The system distinguishes suspicion, model confidence, direct evidence, and verification, and it never claims endpoint actions or attack stages that the available telemetry cannot establish.

Gemini is used only as an incident-level explanation layer after the evidence has been gathered, keeping the high-volume detection pipeline local and evidence-driven.

What I learned

Building CipherMind SOC taught us that effective cybersecurity AI is not just about maximizing classification accuracy—it is about turning massive volumes of disconnected telemetry into trustworthy investigative context.

We learned how to combine supervised machine learning with novelty detection and behavioral clustering, how to perform global threat prioritization instead of simply analyzing the newest events, and how temporal and entity-based correlation can reveal relationships hidden across individual network flows.

We also learned the importance of evidence discipline. A model being confident does not mean an incident is verified. Designing the system around “no evidence → no claim” forced us to distinguish what was directly observed from what was inferred.

Finally, we learned that LLMs are most valuable when used as an analyst-support layer rather than as the primary detector. The strongest workflow became: classify → correlate → investigate → explain.

AI tools used

GeminiChatGPT

chatgpt: Used as the development/reasoning assistant to design the architecture, implement and debug the ML pipeline, build the UI/UX, structure the Evidence Graph and Global Threat Hunt, and iterate on the project during development. gemini:Used inside the actual product as the incident-level AI analyst. It takes already-correlated evidence and generates human-readable incident summaries, reasoning, and recommended investigative actions. ChatGPT → helped us BUILD the system Gemini → is PART OF the system ML + Evidence Engine → actually DRIVE detection and investigation

Links & files

Artifacts

5