Aegis ingests security alerts, enriches their indicators, correlates them into incidents, and routes containment through a human approval gate. Every derived fact links back to the n8n execution that produced it. These are the reference documents.
Every threat the demo can inject: what it is, how it works on the wire and in code, where that code lives, and which console it runs on — each with a clickable architecture diagram.
Node-by-node specs for ingest, enrichment, correlation, triage, containment approval and the digest — including failure branches and test cases.
The entities the pipeline reasons over — alerts, assets, indicators, incidents, actions — and the relationships that make correlation possible.
How an incident moves from detection to containment, where humans decide, and what each state transition requires.