Shadow Warden AI — Gateway v7.1 — Explore the API Reference
Home / Cyber Security / Agentic SOC

Agentic SOC

10 features

AG-01

SOVA Agent

✅ Shipped

Claude Opus 4.6 agentic loop. 30 tools. 7 ARQ cron schedules. Redis memory: 20-turn cap, 6h TTL.

Pro+ v3.0
AG-02

MasterAgent

✅ Shipped

4 specialised sub-agents (SOVAOperator, ThreatHunter, ForensicsAgent, ComplianceAgent). HMAC task tokens. Human-in-the-loop approval.

Pro v4.0
AG-03

WardenHealer

✅ Shipped

Autonomous anomaly detection. OLS trend prediction. SQLite recipe cache. Haiku incident classification.

Pro+ v4.11
AG-04

Agent Monitor

✅ Shipped

Session-level threat pattern detection including INJECTION_CHAIN. Cryptographic attestation chain.

All v3.0
AG-05

Browser Sandbox

✅ Shipped

Playwright headless Chromium. ScreencastRecorder captures video → MinIO SOC 2 evidence bundles.

Pro+ v4.0
AG-06

Visual Assert Page

✅ Shipped

In-process Claude Vision page assertion. No HTTP round-trip. Requires Playwright + Anthropic API key.

Pro+ v4.0
AG-07

Visual Diff Tool

✅ Shipped

Claude Vision baseline vs candidate screenshot comparison. Verdicts: IDENTICAL / MINOR_DIFF / REGRESSION / CRITICAL.

Pro+ v4.11
AG-08

Shadow AI Scanner (SOVA)

✅ Shipped

SOVA tool #29: calls ShadowAIDetector directly. 18 providers. Falls back gracefully without package.

Pro+ v4.2
AG-09

XAI Explain Tool (SOVA)

✅ Shipped

SOVA tool #30: causal chain retrieval from logs + XAI rationale. Used by ScenarioRunner smart_retry.

Pro+ v4.3
MO-01

Mobile SOC App — React Native push alerts for HIGH/BLOCK verdicts

✅ Shipped

iOS + Android React Native app for on-the-go SOC operators. FCM/APNs push alerts fire on every HIGH/BLOCK verdict via the SOVA alerting pipeline. Alert feed, detail view with 9-stage XAI pipeline, one-tap deep-link to full XAI report. Device token registry (SQLite, max 50/tenant). Prometheus counter for delivered notifications.

Pro+ v5.6