Base → v6 → current v8
1,000 identical events · 200 malicious / 800 benign · sample IDs hash-verified
NanoSOC1 is a gated 8B SOC copilot for structured event triage, evidence correlation, MITRE ATT&CK attribution and reversible response recommendations.
Both comparisons use the same frozen holdout and deterministic generation. These are narrow laboratory results—not production guarantees.
1,000 identical events · 200 malicious / 800 benign · sample IDs hash-verified
200 malicious · 800 benign · in-domain offline triage
independent attribution diagnostic · separate from detection
Select a fictional, sanitized scenario to inspect the structured evidence path. These are illustrative fixtures, not live model predictions or benchmark samples.
NanoSOC keeps untrusted logs, model reasoning and high-impact actions behind explicit boundaries.
Normalize events and remove secrets or tenant identifiers.
Select single-log or correlation adapter by task contract.
Retrieve pinned MITRE, CISA KEV and Sigma evidence.
Check provenance, confidence, injection and drift signals.
Route consequential actions to a human with rollback context.
The 1,000-event v8 diagnostic has 32.125% FPR versus a 3% product target. The gate is not passed.
The independent 24-technique diagnostic scores 0% exact. Detection and attribution remain separate quality gates.
The eight-source 3090 development run held macro FPR at 2.888%, but macro recall was only 8.729%. Failed weights were not released.
The stateful engine passed its authored 1,068-event fixture. Independent PCAP, line-rate, failover and customer shadow tests remain open.
Only F0 currently passes all Excel gates. Customer pilot, independent red-team and legal approval remain open; no autonomous action is allowed.