Project direction
XSAR / AXSAR explores a layer between SIEM detection and SOAR execution. The proposed direction combines alert correlation, contextual summaries, playbook guidance, explainability and human approval.
Problem space
Modern SOC workflows can suffer from excessive alerts, limited context, fragmented tools and rigid response playbooks. Automation may reduce repetitive effort, but poorly governed automation can also hide reasoning or amplify mistakes.
Proposed principles
- Explain why an alert is prioritized.
- Show the evidence used by the assistance layer.
- Separate recommendations from executed actions.
- Require approval for high-impact response steps.
- Record analyst feedback for future tuning.
Current status
The work is in the research and framework-design phase. It should not be presented as a completed production platform.