LOCAL OPEN-SOURCE PLATFORM FOR CYBER INCIDENT MONITORING AND RESPONSE WITH AI SUPPORT AS AN ALTERNATIVE TO EDR/XDR SOLUTIONS

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.33.1211

Keywords:

cyber incident response, endpoint security monitoring, security analytics, threat detection systems, open-source security platform, AI-assisted analysis, SOC operations

Abstract

The paper presents an approach to designing a local cybersecurity monitoring and incident response platform based on open-source technologies with integrated artificial intelligence support. The relevance of the study is driven by the growing complexity of cyber threats, the increasing number of endpoints in modern infrastructures, and the need for continuous monitoring and rapid response within Security Operations Centers. Traditional EDR and XDR solutions provide high levels of automation and detection capabilities but rely on subscription-based models that introduce long-term operational constraints and limit flexibility in infrastructure management. The study examines the functional roles of EDR, XDR, SIEM, and SOC within enterprise environments and identifies key challenges related to scalability, data ownership, and dependency on proprietary platforms. Particular attention is given to the limitations of centralized commercial solutions when applied to distributed infrastructures with hundreds of managed endpoints. The paper proposes a model of a local cybersecurity platform that integrates endpoint monitoring, event correlation, and log management within a unified architecture. The proposed solution is based on Wazuh for endpoint detection and SIEM functions, OpenSearch-compatible indexing for event storage and analytics, and on-premises storage systems for secure and scalable log retention. A dedicated local AI analysis layer is introduced to support SOC processes by automating alert summarization, correlating related events, generating hypotheses about incident origins, and assisting analysts in decision-making without exposing sensitive data to external services. The results include a description of the system architecture, hardware configuration, data processing workflows, and storage strategies. The proposed approach emphasizes transparency, flexibility, and adaptability to specific organizational requirements. Additionally, the model incorporates a structured proof-of-concept methodology to evaluate detection coverage, system performance, and the effectiveness of AI-assisted workflows. The study demonstrates that the integration of open-source tools with local AI capabilities can enhance the efficiency of cybersecurity operations while maintaining control over data and infrastructure. The proposed platform provides a viable alternative to traditional EDR/XDR solutions in scenarios where customization, cost predictability, and data sovereignty are critical factors. 

Downloads

Download data is not yet available.

References

MITRE Corporation. (2024). MITRE ATT&CK® framework. https://attack.mitre.org

National Institute of Standards and Technology (NIST). (2022). Security and privacy controls for information systems and organizations (SP 800-53 Rev. 5). https://doi.org/10.6028/NIST.SP.800-53r5

National Institute of Standards and Technology (NIST). (2023). Guide to cyber threat information sharing (SP 800-150). https://doi.org/10.6028/NIST.SP.800-150

Srinivas, S., et al. (2025). AI-augmented SOC: A survey of LLMs and agents for cybersecurity operations. https://www.mdpi.com/2624-800X/5/4/95

Sharma, A. (2025). Explainable artificial intelligence in cybersecurity: A comprehensive review. https://www.sciencedirect.com/science/article/pii/S2405959525001584

Mohamed, N. (2025). Cutting-edge advances in AI and machine learning for cybersecurity. https://www.tandfonline.com/doi/full/10.1080/23311975.2025.2518496

Aboudrar, Y., Bouragba, K., & Ouzzif, M. (2025). AI-driven firewall log analysis: Enhancing threat detection with deep learning techniques. https://thesai.org/Downloads/Volume16No7/Paper_79-AI_Driven_Firewall_Log_Analysis.pdf

Binbeshr, F. (2025). The rise of cognitive SOCs: A systematic literature review. https://www.computer.org/csdl/journal/oj/2025/01/10858372

Singh, R., et al. (2025). LLMs in the SOC: An empirical study of human-AI collaboration in security operations centres. https://arxiv.org/abs/2508.18947

Sahay, R., et al. (2026). Policy-guided threat hunting: An LLM-enabled framework with SOC triage. https://arxiv.org/abs/2603.23966

Omar, M. (2024). Integrative approaches in cybersecurity and artificial intelligence. https://arxiv.org/abs/2408.05888

Schneuwly Purdie, M. (2025). AI-powered SOC operations: Cybersecurity incident response and management. https://www.researchgate.net/publication/389350761

Microsoft. (2024). Security Copilot: AI for cybersecurity. https://www.microsoft.com/security/copilot

Vectra AI. (2024). AI-driven threat detection platform overview. https://www.vectra.ai

Gartner Research. (2025). Continuous threat exposure management (CTEM) framework overview. https://www.gartner.com

Downloads


Abstract views: 11

Published

2026-06-25

How to Cite

Grynkevych, G., Vasylenko, V., & Rudin, D. (2026). LOCAL OPEN-SOURCE PLATFORM FOR CYBER INCIDENT MONITORING AND RESPONSE WITH AI SUPPORT AS AN ALTERNATIVE TO EDR/XDR SOLUTIONS. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 1(33), 234–241. https://doi.org/10.28925/2663-4023.2026.33.1211