Schedule icon
Webhook icon
Queries icon
Query icon
ChatCompletion icon
OpenAI icon
OutputValues icon
If icon
Write icon
SlackIncomingWebhook icon
Log icon

AI Security Incident Threat Advisor and MITRE ATT&CK Containment Generator

Analyze security logs with DuckDB, map threats to MITRE ATT&CK with AI, and deliver copy-paste CLI containment commands to Slack in Kestra.

Categories
AIInfrastructure

Diagram unavailable

We could not build the topology for this blueprint. The flow itself is valid, use the YAML on the left to run it.

On-call security engineers drown in thousands of routine authentication and cloud audit logs (AWS CloudTrail, Okta, CrowdStrike) every day. Sifting through failed login spikes, looking up source IPs, and manually drafting AWS Network ACL or firewall rules takes 20 to 30 minutes per incident, while real threats like credential stuffing or brute force attacks progress.

This blueprint automates Tier-1 triage in Kestra: it aggregates failed login anomalies across source IPs using embedded DuckDB in-memory SQL, passes the telemetry to an LLM advisor to map the attack to MITRE ATT&CK techniques (such as T1110 - Brute Force), persists an executive incident report, and delivers copy-paste CLI containment commands (e.g. AWS Network ACL entry rules) directly to Slack.

How it works

  1. stage_security_telemetry (io.kestra.plugin.jdbc.duckdb.Queries) loads raw security audit events into an in-memory DuckDB table with zero external database dependencies.
  2. aggregate_threat_anomalies (io.kestra.plugin.jdbc.duckdb.Query) runs group-by aggregation to isolate threat actors by source IP, counting failed login attempts, targeted usernames, and authentication methods.
  3. analyze_threat_with_ai (io.kestra.plugin.ai.completion.ChatCompletion) evaluates the aggregated intrusion vectors against the MITRE ATT&CK framework using strict JSON Schema output, determining threat severity and generating exact CLI containment commands (such as AWS Network ACL rules or IP blocks).
  4. consolidate_threat_metrics (io.kestra.plugin.core.output.OutputValues) exposes structured telemetry metrics into execution outputs.
  5. evaluate_threat_gate (io.kestra.plugin.core.flow.If) branches conditionally:
    • Threat Detected: Generates an executive Markdown report artifact (soc-incident-triage-report.md) in Kestra storage and dispatches a Slack alert with the copy-paste containment script.
    • Baseline Normal: Logs a healthy audit verification.
  6. alert_audit_failure (errors block) notifies Slack if the audit pipeline errors.

What you get

  • Instant Tier-1 SOC telemetry triage without manual SIEM query authoring.
  • Automated mapping to official MITRE ATT&CK techniques (e.g. T1110.003 Password Spraying).
  • Ready-to-execute CLI containment scripts delivered straight to Slack.
  • Publication-ready incident post-mortem artifacts stored in Kestra internal storage.

Who it's for

  • Security Operations Center (SOC) analysts and Incident Responders.
  • Cloud SecOps engineers managing AWS, GCP, or Azure IAM and network firewalls.
  • Enterprise security teams seeking automated threat containment playbooks.

Why orchestrate this with Kestra

Correlating security telemetry requires linking analytical SQL aggregations, frontier LLM reasoning, storage persistence, and incident communication channels. Kestra coordinates DuckDB, AI models, and Slack into a single auditable, declarative pipeline with complete execution lineage.

Prerequisites

  • OpenAI API key or any OpenAI-compatible LLM endpoint (Groq, Ollama, vLLM).
  • Slack incoming webhook URL for SecOps alerts.

Secrets

  • OPENAI_API_KEY: API key for the AI threat analysis task.
  • SLACK_WEBHOOK_URL: Slack incoming webhook endpoint for SOC incident alerts.
  • SECOPS_WEBHOOK_KEY: Authentication key for event-driven SIEM triggers.

Quick start

  1. Configure OPENAI_API_KEY and SLACK_WEBHOOK_URL in your Kestra namespace.
  2. Import this blueprint into your Kestra instance.
  3. Click Execute with default audit samples to inspect the simulated brute-force detection and generated containment script.
  4. Enable the schedule or route your SIEM audit webhook at the flow endpoint.

How to extend

  • Add automated AWS VPC Network ACL update tasks to auto-block malicious CIDRs.
  • Chain automated Jira or PagerDuty incident creation for CRITICAL threats.
  • Connect to AWS CloudTrail or Okta log shippers via Kestra HTTP or SQS triggers.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.