Calyvex Lab

Research ideas. Build evidence. Test what works.

The Lab is the technical foundation of Calyvex, organizing applied work into research tracks, practical projects and clearly labelled prototypes.

3 Research tracks3 Projects2 Prototypes
ResearchActive research

Alert Fatigue and Explainable Triage

Researching how excessive low-quality alerts, missing context and repetitive validation affect analysts—and how assistance can help.

Security OperationsExplainable AISIEMHuman-in-the-loop
Explore research
ResearchActive research

SIEM, SOAR and Adaptive Security Operations

Examining where detection, orchestration and analyst workflows remain fragmented, rigid or difficult to maintain.

SIEMSOARSecurity AutomationDetection Engineering
Explore research
ResearchEvidence review

Large Language Models for SOC Analyst Assistance

Evaluating where language models can support summarization, investigation and reporting—and where their limitations create risk.

LLMAI SecuritySecurity OperationsExplainable AI
Explore research
ProjectCompleted prototype

AI-Based Threat Detection & SOC Dashboard

An unsupervised anomaly-detection pipeline with LLM-assisted incident explanations and an interactive SOC dashboard.

PythonIsolation ForestStreamlitLLM
View project
ProjectActive development

Security Detection & Attack Simulation Lab

A controlled Windows and Linux environment for generating telemetry, testing detections and documenting analyst investigations.

SplunkWazuhSysmonWindows
View project
ProjectResearch phase

XSAR / AXSAR Security Operations Framework

A research-led framework exploring explainable automation between SIEM detection and SOAR response.

SIEMSOARExplainable AIHuman-in-the-loop
View project
PrototypeDemo available

Browser-Based SOC Investigation Demo

A static, safe demonstration of event review, elevated signals and evidence-linked incident explanation.

JavaScriptSecurity LogsExplainable AIHuman-in-the-loop
View prototype
PrototypePlanned prototype

Detection Content Library

A structured prototype for storing detection logic together with telemetry requirements, validation steps and tuning notes.

SigmaDetection EngineeringSIEMGitHub
View prototype
Lab principles

Useful research must survive contact with real constraints.

Transparent status

We separate concepts, research, prototypes and completed work.

Documented limitations

Every result is presented with scope and known constraints.

Responsible testing

Security validation is controlled, authorized and evidence-led.

Practical transfer

Research should inform tools, services, training or operational improvement.

Build with Calyvex

Need a practical security solution?

Tell us what you are trying to detect, understand, validate or improve.