Free AI Security Analyst by SIRP
Your always-on SOC co-analyst for threat intelligence, incident analysis, and security operations.
Try SARA Open | Documentation | Discussions | Report a Bug
SARA (Security Analyst & Response Assistant) Open is a free AI-powered cybersecurity analyst built by SIRP. It provides enterprise-grade security capabilities to analysts, researchers, and SOC teams — at no cost.
- Threat Intelligence — CVE lookups, IP/domain/hash reputation, EPSS scores, MITRE ATT&CK mapping
- Incident Analysis — Triage, classification, severity assessment, and remediation guidance
- Detection Engineering — Sigma rule generation, KQL queries, YARA rules
- Knowledge Base — Continuously updated with CVEs, KEV, EPSS, Sigma rules, and GCC regulatory frameworks (SAMA CSF, NCA ECC, PDPL)
- OmniSense Integration — Connect to SIRP's SOAR platform for live incident data, playbook execution, and SOC metrics
- Web Research — Real-time web search for emerging threats and zero-days
| Feature | Free | Pro |
|---|---|---|
| Threat intelligence lookups | Unlimited | Unlimited |
| CVE / MITRE analysis | Unlimited | Unlimited |
| Sigma & detection rules | Unlimited | Unlimited |
| Web search for emerging threats | Unlimited | Unlimited |
| OmniSense SOAR integration | — | Included |
| Bring Your Own Claude API Key | — | Included |
| Priority response times | — | Included |
This repository is the community hub for SARA Open. Use it to:
- Report bugs — Found something broken? Open an issue
- Request features — Have an idea? Start a discussion
- Ask questions — Need help? Ask the community
- Share use cases — Show how you use SARA in your workflow
The SARA Open codebase is maintained in a private repository with controlled contributor access. This ensures code quality, security review, and responsible development of security tooling. If you're interested in contributing, please reach out to support@sirp.io.
- Visit sara-open.sirp.io
- Sign up with your email
- Start asking security questions — no setup required
Pro users can connect their OmniSense instance under Settings > OmniSense to unlock live incident data and playbook execution.
| Resource | URL |
|---|---|
| SARA Open | sara-open.sirp.io |
| Help & Docs | sara-open.sirp.io/help |
| SIRP Platform | sirp.io |
| OmniSense SOAR | sirp.io/omnisense |
| Privacy Policy | sara-open.sirp.io/privacy |
| Terms of Service | sara-open.sirp.io/terms |
If you discover a security vulnerability in SARA Open, please report it responsibly by emailing security@sirp.io. Do not open a public issue for security vulnerabilities.
Built with care by SIRP — Making security accessible to everyone.