- Challenge
- Signature-based tools miss novel attacks, and SOC analysts drown in alerts with no context about what an attacker is actually doing. The job was a detector that catches unknown behaviour and tells the analyst what it means.
- Outcome
- Detects DDoS, brute force, port scans, web attacks, infiltration and botnet activity across the CICIDS2017 categories. The ATT&CK mapping turns each alert from a raw flag into a triage decision in seconds. Deployed live on Hugging Face Spaces with full source on GitHub.