AKJ
All projects

Case study

ARGUS

The hundred-eyed watchman: an AI-powered, event-driven security event analysis platform.

Chapters

5

attack scenarios on demand

3

Kafka topics in the pipeline

0

API keys needed to run

Live

WebSocket security console

OVERVIEW

What & why!

Argus ingests a live stream of security logs, detects threats with stateless and stateful rules, correlates alerts into incidents, and explains each incident in plain language.

Everything streams to a real-time security console with an Attack Simulator, a Log Explorer and a pipeline trace view that follows one event from raw log to AI summary. The whole stack runs with zero API keys thanks to a deterministic summary fallback.

HOW IT WORKS

From raw log to AI summary!

  1. 1

    Scenario generator

    Emits benign background traffic, plus attack scenarios via /simulate.

  2. 2

    Kafka: raw.logs

    Every event enters the pipeline here.

  3. 3

    Parser

    Validates and normalizes each event against a shared Zod contract.

  4. 4

    Detection engine

    Stateless and stateful rules turn normalized events into alerts.

  5. 5

    Incident engine

    Correlates alerts by entity and time window into incidents in Postgres.

  6. 6

    AI engine

    An LLM (Groq or Gemini) writes the summary, or a deterministic template does.

  7. 7

    Realtime dashboard

    WebSocket fan-out to the Next.js console, plus REST for traces and search.

INTERESTING PROBLEMS

The fun parts!

One contract for every event

A single Zod package is the source of truth for every event shape, shared by the generator, the processing monolith and the dashboard, so a change breaks at compile time instead of in production.

Stateful detection that scales out

Rules that need history (bursts, sequences) use a detection window store. It stays in-process by default and moves to Redis for multi-instance runs, along with the internal event bus.

AI that never blocks the demo

Summaries come from an LLM when a key is configured and from a deterministic template otherwise, so the full pipeline, including the AI step, works on a fresh clone with no secrets.

A public demo that can't be abused

Token-bucket rate limits on every endpoint (tighter on login) stop scripts from draining the LLM's free tier, and auth bootstraps like Grafana: open until the first account registers, locked after.

STACK

Built with!

Pipeline
Node 24, TypeScript (strict), Fastify, Kafka (KRaft), Zod
Storage
PostgreSQL (Prisma), Elasticsearch, optional Redis
Dashboard
Next.js 16, WebSockets, shadcn/ui, TanStack Query, Recharts, Framer Motion
Tooling
Docker Compose, pnpm + Turborepo, Vitest

Next case study

HobbyHive