← Back to Projects

Security Operations Research

SentinelForge

AI-Assisted Security Operations

A research project exploring how locally controlled AI can assist security operations through event classification, log summarization, incident-response workflows, and automation.

Security OperationsLocal AILog AnalysisIncident ResponseAutomationPythonPowerShellResearch

Overview

Why I'm Exploring It

Security teams often work with large amounts of repetitive, technical information. Logs, alerts, event timelines, documentation, and investigation notes can consume significant analyst time.

SentinelForge is my research environment for exploring where AI might assist those workflows without pretending that a language model can replace evidence, security tooling, or analyst judgment.

The project is deliberately positioned as research. The objective is to test useful patterns, understand limitations, and build small repeatable workflows before treating anything as an operational security capability.

Workflow

Where AI Might Assist

01

Collect

Bring relevant security events, logs, alerts, or structured data into a workflow that can be reviewed consistently.

02

Classify

Explore whether local AI can help group, label, prioritize, or summarize events without replacing analyst judgment.

03

Investigate

Use structured prompts and supporting context to help surface relationships, questions, and possible next investigative steps.

04

Respond

Explore repeatable workflows that assist documentation, containment planning, communication, and follow-up actions.

Research Areas

Questions Before Automation

The first goal is understanding where AI adds useful assistance and where it adds noise, uncertainty, or unnecessary risk.

Project Status

SentinelForge is currently a research project. Planned capabilities on this page represent areas for experimentation, not production security controls.

Research

Event Classification

Explore whether local models can help categorize security events into useful buckets for analyst review.

Research

Log Summarization

Condense large amounts of technical event data into shorter summaries while preserving the original evidence for validation.

Research

Incident Assistance

Use AI as a supporting tool for investigative questions, documentation, timelines, and response checklists.

Planned

Python Automation

Develop small Python utilities for processing structured data, normalizing inputs, and connecting parts of the workflow.

Planned

PowerShell Automation

Explore repeatable Windows and Microsoft security administration tasks that can be safely scripted.

Planned

Local Model Testing

Compare model behavior across security prompts while keeping sensitive lab data inside locally controlled infrastructure.

Guardrails

AI Assistance Still Needs Evidence

01

Human Validation

Model output is treated as assistance that requires verification rather than authoritative security evidence.

02

Source Preservation

Original logs and event data remain available so summaries can always be checked against the underlying evidence.

03

Local Processing

Local models provide an opportunity to experiment with sensitive lab data without automatically sending it to external providers.

04

Controlled Automation

Automated actions should be narrow, understandable, reversible, and separated from unrestricted model decision-making.

“The useful question is not whether AI can make a security decision. It is where AI can reduce repetitive work while leaving evidence and judgment intact.”

Research Goals

What I Want to Learn

01

Which security tasks benefit from summarization without losing important technical context.

02

How reliably local models can classify structured security events.

03

Where automation can improve consistency without creating unsafe autonomous behavior.

04

How local AI infrastructure can support privacy-sensitive security workflows.

Next Steps

From Research to Prototype

01

Build a repeatable event-input format

02

Test classification prompts across local models

03

Prototype log-summary workflows

04

Create small Python processing utilities

05

Explore safe PowerShell automation

06

Document model limitations and failure cases

More Projects

Explore the rest of the lab.

Back to Projects →