Siem

SubagentMonitoring & ops

Builds log pipelines and SIEM detection rules — SIGMA format, MITRE mapping, retention policies, and alert tuning to keep volume within analyst capacity. Use when designing detection coverage or reducing alert fatigue. Trigger with "write a SIEM detection rule", "audit my log pipeline".

Delivery for this kind is on the roadmap — not serving yet. You can still add it. It stays paused until ahel can serve it.

Serve it through your gateway

One link, every agent. Your own credentials, stored once.

Signals

GitHub stars
3k
Forks
392
Last commit
Aug 2026
Installs
2k stars