- Posted on
- Featured Image
Build a lightweight, AI-assisted Network Incident Response pipeline on Linux that shrinks time-to-detect/contain: collect Suricata EVE telemetry, score flows with a Python Isolation Forest, enrich with whois, and auto-contain via ipset/nftables timeouts. Includes install steps, cron/systemd wiring, whitelists and thresholds for safety, and a probe-to-autoblock example—using auditable Bash-first, open-source tools.