Collect
Bring relevant security events, logs, alerts, or structured data into a workflow that can be reviewed consistently.
Security Operations Research
AI-Assisted Security Operations
A research project exploring how locally controlled AI can assist security operations through event classification, log summarization, incident-response workflows, and automation.
Overview
Security teams often work with large amounts of repetitive, technical information. Logs, alerts, event timelines, documentation, and investigation notes can consume significant analyst time.
SentinelForge is my research environment for exploring where AI might assist those workflows without pretending that a language model can replace evidence, security tooling, or analyst judgment.
The project is deliberately positioned as research. The objective is to test useful patterns, understand limitations, and build small repeatable workflows before treating anything as an operational security capability.
Workflow
Bring relevant security events, logs, alerts, or structured data into a workflow that can be reviewed consistently.
Explore whether local AI can help group, label, prioritize, or summarize events without replacing analyst judgment.
Use structured prompts and supporting context to help surface relationships, questions, and possible next investigative steps.
Explore repeatable workflows that assist documentation, containment planning, communication, and follow-up actions.
Research Areas
The first goal is understanding where AI adds useful assistance and where it adds noise, uncertainty, or unnecessary risk.
Project Status
SentinelForge is currently a research project. Planned capabilities on this page represent areas for experimentation, not production security controls.
Explore whether local models can help categorize security events into useful buckets for analyst review.
Condense large amounts of technical event data into shorter summaries while preserving the original evidence for validation.
Use AI as a supporting tool for investigative questions, documentation, timelines, and response checklists.
Develop small Python utilities for processing structured data, normalizing inputs, and connecting parts of the workflow.
Explore repeatable Windows and Microsoft security administration tasks that can be safely scripted.
Compare model behavior across security prompts while keeping sensitive lab data inside locally controlled infrastructure.
Guardrails
Model output is treated as assistance that requires verification rather than authoritative security evidence.
Original logs and event data remain available so summaries can always be checked against the underlying evidence.
Local models provide an opportunity to experiment with sensitive lab data without automatically sending it to external providers.
Automated actions should be narrow, understandable, reversible, and separated from unrestricted model decision-making.
“The useful question is not whether AI can make a security decision. It is where AI can reduce repetitive work while leaving evidence and judgment intact.”
Research Goals
Which security tasks benefit from summarization without losing important technical context.
How reliably local models can classify structured security events.
Where automation can improve consistency without creating unsafe autonomous behavior.
How local AI infrastructure can support privacy-sensitive security workflows.
Next Steps
Build a repeatable event-input format
Test classification prompts across local models
Prototype log-summary workflows
Create small Python processing utilities
Explore safe PowerShell automation
Document model limitations and failure cases
More Projects