ultraviolet
A security operations center you run in a terminal.
Ultraviolet is a terminal-first purple-team SOC on the BEAM. It turns a signal into a signed, chained, reproducible observation, judges it with rules that are data, and can hold or escalate. It never approves.
What it does.
- Ingests live host telemetry: the BEAM's own process signals, journald security events, and network flows through
tsharkanddumpcap. - Promotes suspicious activity into alerts, correlates and deduplicates them, and opens investigation cases.
- Keeps alerts, cases, approvals and observations as explicit, durable records in PostgreSQL, with an append-only audit trail.
- Runs the whole SOC from a terminal: over SSH, in remote shells, and where browser-first tooling is unwanted.
- Exposes its investigation tools over MCP, so an AI assistant or a script can use them.
- Lets a bounded agent help analyze, summarize and investigate, while a human operator makes the decisions.
- Masks sensitive values for screenshots and demos.
It observes, holds and escalates. It never approves.
Every collector, rule pack and composition keeps one boundary: Ultraviolet observes, labels, holds and escalates. It is never an effector, never an approver, and never writes into another system.
Its MCP tools only read or propose. An action proposal comes back marked as requiring approval; it is not stored, and nothing is executed. No AI model or external agent ships with it, and the agents inside Ultraviolet call no model.
Composed with Requisition, Ultraviolet is the independent observer: a second operator with a different threat model, whose own queries are consequential acts with receipts. The Sanction page describes the composition.
How it is built.
Terminal first
Built to work over SSH, in remote shells, and in environments where browser-first tooling is undesirable.
Durable state
Alerts, cases, approvals and observations are modeled explicitly and can be persisted and queried.
Replayable workflows
Observations are reproducible, so detections can be replayed and validated in purple-team exercises.
Auditable operations
State transitions leave inspectable records that operators can read.
Elixir and Erlang/OTP on the BEAM, PostgreSQL, Jido, MCP over beam_mcp. It starts with no database for the MCP server and the terminal interface, and adds PostgreSQL for durable alerts, cases, approvals and audit.
Private tier. The open-source release is a complete SOC on its own. A private tier, licensed from Script Kitty OS & Labs, adds the composition with Requisition, where a detection can stand as a witness and an observer's own queries carry receipts, and capabilities specified for defense security operations. It is not published; it is described in a briefing.
License.
Apache-2.0: a complete SOC on its own, with no authority plane required. Intended for possible donation.