AI assistant for SOC
AI assistant for the security team (KUMA / KIRA)
For companies with Kaspersky SIEM/XDR without a full SOC: AI triages incidents, drafts reports and escalates critical cases into client workflows.
What the client buys
- — Faster alert triage without growing SOC headcount
- — Timeline, IoCs and response recommendations
- — Auto tickets and escalations
- — RAG over internal security playbooks
- — Weekly security digests
Bober AI Systems
- — Source and workflow integration around KUMA
- — Alert → LLM/KIRA analysis
- — Auto ticket and assignee
- — Critical incident escalation
- — DOCX/PDF report
- — Weekly security digest
- — RAG knowledge base of client procedures
- — Channels: Bitrix24 / Telegram / email / helpdesk
Kaspersky
- — Kaspersky KUMA / Next XDR — events and alerts
- — KIRA — summary, IoCs, timeline, recommendations
- — Optional external LLM provider per KUMA docs
- — Natural-language SIEM queries where product allows
Architecture
- 01KUMA / XDR → alert or incident
- 02KIRA / private LLM → translate, timeline, risk, actions, report
- 03Bober automation → Bitrix24 / Telegram / email / helpdesk
When SIEM already exists or is planned, but SOC analysts are the bottleneck.