Skip to content

CoSA is a secure, conversational middleware for SIEM systems. It converts natural language into validated KQL/DSL queries using RAG, DST, and FastAPI. Designed for Elastic/Wazuh, it accelerates threat detection, protects clusters, and auto-generates PDF reports.

License

Notifications You must be signed in to change notification settings

ABHISHEKABHI52/CoSA-SIEM-Assistant

Repository files navigation

Conversational SIEM Assistant (CoSA)

Intelligent middleware for automated threat investigation and reporting using NLP.

About

CoSA is a secure, conversational middleware for SIEM systems. It converts natural language into validated KQL/DSL queries using RAG, DST, and FastAPI. Designed for Elastic/Wazuh, it accelerates threat detection, protects clusters, and auto-generates PDF reports.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published