← Calyvex Lab
ProjectResearch phase

XSAR / AXSAR Security Operations Framework

A research-led framework exploring explainable automation between SIEM detection and SOAR response.

SIEMSOARExplainable AIHuman-in-the-loopSecurity Automation

Project direction

XSAR / AXSAR explores a layer between SIEM detection and SOAR execution. The proposed direction combines alert correlation, contextual summaries, playbook guidance, explainability and human approval.

Problem space

Modern SOC workflows can suffer from excessive alerts, limited context, fragmented tools and rigid response playbooks. Automation may reduce repetitive effort, but poorly governed automation can also hide reasoning or amplify mistakes.

Proposed principles

  • Explain why an alert is prioritized.
  • Show the evidence used by the assistance layer.
  • Separate recommendations from executed actions.
  • Require approval for high-impact response steps.
  • Record analyst feedback for future tuning.

Current status

The work is in the research and framework-design phase. It should not be presented as a completed production platform.

Build with Calyvex

Need a practical security solution?

Tell us what you are trying to detect, understand, validate or improve.