CyberForge · Sovereign security

Cybersecurity AI agents, from CVE to incident response.

Offensive and defensive security. From CVE monitoring to SIEM triage and incident response — on-premise, under your control.

// BYOK · Zero-Trust · air-gap deployable

cyberforge · soc-pipeline
CVE monitoringCVSS scoring · exploited scan
SIEM triagemulti-source correlation alert
Forensic timelineIOC · lateral movement trace
Incident reportsigned · actionable sealed
770+ open-source skills indexed · continuous GitHub monitoring ISO 27001 SOC2 Zero-Trust
Scope

Domains covered

17 cybersecurity domains, from penetration testing to compliance.

Pentest Red Team Blue Team SOC / SIEM Forensics Malware Analysis Threat Intelligence Vulnerability Management Cloud Security Network Security Web Security Mobile Security IAM Compliance (ISO 27001, SOC2) Incident Response OSINT Crypto
Agents

Example agents

Specialized agents that guide you and generate concrete deliverables for your environment.

Pentest Agent

Guides the pentester at every step: proposes reconnaissance and enumeration commands, explains exploitation techniques, and generates the final report with prioritized recommendations. With an MCP connector: assisted execution of scans directly from the agent.

OffensiveMCP-ready

SOC Agent

Helps you triage SIEM alerts: guides event correlation, proposes eliminating false positives, enriches context (IP, hash, domain) and structures the escalation file. With a SIEM MCP connector: automated triage in real time.

DefensiveMCP-ready

Forensic Agent

Guides the collection of digital artifacts (logs, memory, disk), explains what to recover and how, helps build the timeline of events, identifies indicators of compromise and produces an actionable investigation report.

InvestigationDFIR

Compliance Agent

ISO 27001 compliance audit: analyzes gaps against Annex A, generates the Statement of Applicability (SoA) and proposes a costed remediation plan.

ComplianceISO 27001

CVE Monitoring Agent

Continuous monitoring of new vulnerabilities. Filters by technologies present in your IT environment, assesses CVSS criticality and alerts on actively exploited CVEs.

Threat IntelCVSS
Execution modes

Advisory mode vs MCP mode

The agent is already useful on its own. With an MCP connector, it becomes 10x more powerful.

Without an MCP connector

  • Guides the pentester step by step
  • Proposes scan and exploitation commands
  • Generates audit and remediation reports
  • Analyzes what you provide it (logs, alerts, artifacts)

With an MCP connector

  • Reads your SIEM alerts in real time
  • Automatically triages false positives
  • Enriches IOCs from your Threat Intel feeds
  • Runs SOAR playbooks in your IT environment
Custom engagement
Integrations

Possible MCP connectors

Connection to your existing tools via the MCP protocol. Each connector is configured and adapted to your environment. Integration on quote.

SIEM (Splunk / Wazuh / ELK) Vuln scanner (Nessus / Qualys) SOAR Threat Intel feeds Active Directory
Custom engagement
In the field

Use cases

Concrete scenarios where CyberForge delivers immediate value.

Internal network pentest

The Pentest Agent guides the pentester step by step on the internal network: proposes nmap commands for discovery, suggests relevant credential tests and exploits, then generates the PDF report with evidence and remediation recommendations.

OffensivePDF report

Daily SOC triage

Every morning, the analyst submits the overnight alerts to the SOC Agent. It helps correlate multi-source events, proposes closing documented false positives, and structures real incidents with enriched context. With a SIEM MCP connector: automatic alert triage in real time.

DefensiveSIEM

Ransomware incident response

The Forensic Agent guides the team in collecting artifacts on the impacted machines, helps reconstruct the attack timeline, identifies the initial vector and lateral movement, and produces the technical file for management and insurance.

DFIRTimeline

ISO 27001 compliance audit

The Compliance Agent reviews your existing documentation, identifies gaps against the 93 controls of Annex A, generates a prioritized action plan and prepares the evidence for the external auditor.

Compliance93 controls

Secure your IT environment with CyberForge

Request a demonstration tailored to your context or explore our offers.