Omniculus fuses your security telemetry into a living knowledge graph, surfaces dangerous activity with explainable detections, and routes every consequential call to a person. Powerful sight — accountable decisions.
Every stage is explainable and inspectable. Data you're authorized to use goes in; ranked, evidence-backed recommendations come out.
Synthetic generator by default, plus authorization-gated connectors and public threat-intel feeds.
Entities and observations woven into a knowledge graph — the substrate for correlation and attack-path analysis.
Explainable rules and statistical anomalies. Every alert carries the rule that fired and its evidence.
Alerts ranked and routed. Consequential findings require human review. Nothing is auto-executed.
Analyst dispositions retune detection thresholds — bounded, logged, and auditable. Vigilance without black boxes.
The feedback loop closes back onto detection — the system grows more vigilant over time while staying explainable.
authorized + synthetic
knowledge graph
explainable alerts
human-in-the-loop
retune & loop back
Omniculus is built to be powerful and responsible by design. These constraints aren't disclaimers — they're encoded in the architecture.
The system recommends and explains; a person decides and acts. There is intentionally no response-execution module.
Developed and validated on generated data and lab replicas — never pointed at infrastructure you don't own.
Every alert references its rule and evidence. Every learned change is logged with the precision that justified it.
A core research question: how little can we collect and still answer the security question?
Synthetic data, knowledge-graph core, four explainable detections, human-in-the-loop decision support, and the feedback loop — running end to end.
Alert correlation & dedup, per-entity behavioral baselines, and an evaluation harness for precision / recall / time-to-detect.
Attack-path discovery, centrality and community detection, and a temporal view of the evolving attack graph.
Anomaly models plus a Stackelberg / SUQR allocator that focuses limited analyst attention against an adaptive adversary.
Public-dataset replay and adversary emulation, an optional Neo4j backend and investigation UI, and the omniculus.com public sandbox.
Clone, install, and run the full pipeline on synthetic data — no sensitive data, no setup beyond Python.