IONSEC
Automated Threat Hunting & Evidence Neutralization Architecture
9 AI agents. 9 models. 1 mission: hunt threats faster than they spread.
Interactive demo — click, drag, explore the live dashboard.
A.T.H.E.N.A is a multi-agent digital forensics and incident response (DFIR) platform that deploys a fleet of 9 specialist AI agents — each running a different frontier open-source model via Ollama Cloud — to parallelize incident response workflows. Built on the Hermes Agent runtime with MCP tool calling to REMnux and Ghidra, it delivers a Kanban-style Mission Control dashboard for managing the entire incident lifecycle.
9 specialists. 9 different models. Zero systemic blind spots.
Decompose cases, route to specialists, supervise fleet operations.
Rapid initial assessment, artifact prioritization, preliminary IOC extraction. Speed-critical role.
Volatility 3 deep-dive, process analysis, injection detection, rootkit hunting.
Ghidra decompilation, CAPA capability extraction, FLOSS string recovery, PE/ELF analysis.
Hypothesis-driven hunting, Sigma rules, YARA sweeps, behavioral pattern matching.
plaso super timelines, EVTX analysis, multi-source log correlation, temporal anomaly detection.
MISP/IntelOwl enrichment, OSINT gathering, IOC lookup, malware family identification.
Synthesizes findings into forensically sound reports with MITRE ATT&CK mapping.
Independent verification of all findings, cross-validation, methodology rigor check. Always a different model.
Every component designed for forensically sound, high-velocity incident response.
No two agents share a model. Model diversity eliminates systemic blind spots and ensures the QA reviewer always provides a different perspective.
Drag-and-drop task management across 6 workflow columns: Intake → Triage → Analysis → Review → Report → Done.
50+ tools from REMnux (12) and GhidrAssistMCP (38) at agents' fingertips via Model Context Protocol servers.
SHA-256 hashing, read-only evidence enforcement, and full audit trail for every artifact in every case.
WebSocket streaming delivers agent findings, status changes, and alerts the instant they happen. No polling. No delay.
Each agent has its own identity (SOUL.md), memory (MEMORY.md), and skills directory via the Hermes Agent runtime.
Three layers. One unified response.
React + FastAPI — Kanban, Agent Monitor, Reports, Case Management
Orchestrator · Triage · Memory · Malware RE · Threat Hunter · Log Analyst · Intel · Writer · QA
remnux-mcp-server (12 tools) · GhidrAssistMCP (38 tools) · 300+ DFIR tools
One command installs everything — system deps, Ollama + 9 models, Hermes runtime, backend, frontend, MCP servers, and systemd services.
git clone https://github.com/ionsec/athena.git A.T.H.E.N.A
cd A.T.H.E.N.A
./scripts/install.sh