Surgical Threat Intelligence
Without the Noise.

VANTAGE is an open-source, fast, and explainable verdicts platform for SOC teams. Stop guessing. Start acting.

vantage-soc/terminal
[14:22:01] INFO Parallel routing initiated for suspicious payload...
[14:22:02] QUERY VirusTotal, AbuseIPDB, Shodan responding...
[14:22:03] ALERT Verdict: HIGH RISK. Ransomware IOCs detected.
[14:22:03] DONE Natural-language summary generated. Triaged in 2.3s.
> _

Built for the Modern Operator

More than just a lookup tool. An entire workspace to triage feeds, recon, manage watchlists, and control exposure.

Parallel Analysis & Reports

Queries multiple sources simultaneously with streaming reports and batch processing support for near-instant enrichment.

Enterprise Grade IAM

Complete RBAC, TOTP MFA, Active Session Revocation, and rigorous audit trails integrated directly into the core.

Transparent & Auditable

Open-core logic (AGPLv3) ensures transparency. You verify the models, inspect the codebase, and manage the deployment.

Shift Handoff & TrackingNew

Structured shift transitions with incident auto-capture, acknowledgment flows, and CTI modeling readiness.

Optional Companion

Meet SOCC

SOC Copilot (SOCC) is a local-first helper explicitly designed to integrate with VANTAGE. We didn't want to force AI into the core product, so it lives as an optional, installable CLI & API plugin. Run it locally via Ollama to orchestrate threat feeds, parse complex EDR payloads, and automatically draft operational summaries for your alerts without sending sensitive telemetry to the cloud.

Multi-Provider (Gemini, OpenAI, Ollama) Agentic Investigation MCP & Tool Orchestration VS Code & gRPC Integration
╔███████╗ ██████═╗ ╔███████╗ ╔███████╗ ██╔═════╝ ██╔═══██║ ██╔═════╝ ██╔═════╝ ║██████═╗ ██║ ██║ ██║ ██║ ╚════╗██║ ██║ ██║ ██║ ██║ ███████ ║ ║██████ ║ ║███████╗ ║███████╗ ╚═══════╝ ╚═══════╝ ╚═══════╝ ╚═══════╝
Provider: Ollama Model: gemma4:latest Endpoint: http://localhost:11434/v1
local Ready
socc v0.1.18