
SENTINEL-Ω is the first autonomous SOC agent combining probabilistic causal reasoning, Bayesian tool selection, and inductive conformal prediction. It runs as a live, browser-native command center you open with one click. Run it:*`bash run.sh` on any Linux box. Port 8000 launches a 5-mode dashboard that runs unattended: 1. *GLOBE MODE*: 3D Earth streams live attack arcs with pulsing source IPs and defender markers. 2. *BELIEF MODE*: Visualizes the agent’s causal hypotheses as a particle constellation. Watch uncertainty drop from 4.0 to 0.5 bits as evidence arrives. 3. *CAUSAL MODE*: Force-directed graph of MITRE ATT&CK techniques, built dynamically with probability-weighted nodes. 4. *TRACE MODE*: Streams every step — thoughts, tool calls, results, belief updates, final verdict with conformal severity. 5. *THEATRE MODE*: All 4 views in a 2×2 auto-cycling grid. 10 seconds tells judges what it does. *Rigorous backing*: 3 verified theorems prove - *T1*: Info-theoretic optimality of Bayesian tool selection - *T2*: Conformal severity predictor coverage at α - *T3*: Pareto-optimality of the containment planner *Results on CHIMERA benchmark* [1,200 scenarios, 12 archetypes]: F1=0.988, ECE=0.195, coverage=0.912 vs target 0.90, unnecessary containment=0.001 vs 0.679 F1 for rule-based SOAR. *Impact*: SOC analysts waste 32% of time on false positives. SENTINEL-Ω closes them automatically with a guaranteed error rate.
19 May 2026