Hunt the real threats.Leave the noise.
Raffkin is an agentic SOC skill suite for Exabeam New-Scale. It investigates alerts to evidence-backed verdicts, prioritizes the cases that need attention, and finds noisy detection rules. Deterministic guardrails and human approval protect every consequential action.
Three skills. One guarded connector. Every conclusion tied to evidence.
Three skills, one governance gate
Analyst. Shift lead. Detection engineer.
Each skill is named for the person whose job it does. They hand off to each other — a single case to the analyst, a noise cluster to the engineer — and share one safety spine: the same untrusted-data doctrine, the same write gate, the same audit trail.
soc-investigate
Takes one alert or case from first look to written verdict: pulls the events, pivots on the entities it finds, weighs the activity against what is normal for them, tests a benign explanation against a malicious one — and writes it up with the evidence behind every line.
"investigate alert 8f67ee43"
triage-cases
Sweeps the open queue instead of one case — clusters by attack shape, ranks by corroborated signal rather than risk score alone, and hands back a short "start here" list plus the noise worth tuning. Read-only across the sweep; it never closes in bulk.
"triage the queue"
rule-tuning
Finds the rules quietly wasting analyst attention — noisy, not merely loud — and proposes the specific change, mapped to real Exabeam mechanics. Propose-only: there is no rule-write path, and that is deliberate.
"find noisy rules"
In five minutes
Install. Connect. Hunt.
No server, no database, no approval queue — a plugin in the coding agent you already run, and the analyst at the terminal is the human-in-the-loop. The four steps and the commands ↓
Built in, not bolted on
SIEM data is untrusted input. Build like it.
An attacker can write to your logs — a user-agent string, a case note, a "baseline" pasted into an alert. If you expose that data to an agent with tools, you need a plan for what happens when it lies. Raffkin's plan is code you can read and tests you can run, at every layer between the data and an action.
- Two locks on dismiss/close, out of the box — a gate the plugin ships and the host enforces stops the call before it reaches Exabeam, and the skill asks you first. Never left to the model alone.
- Containment is recommended, never executed — isolate, disable, block: the plugin can propose them and cannot perform them. Denied at the harness as defense in depth.
- Evidence has provenance — a baseline is something the agent queried, not something the alert supplied. Planted "context" does not count.
- Reads are canonicalized — invisible-character smuggling is stripped before the model reasons about what it read.
- Writes are neutralized — formulas and clickable links are defanged, secrets and structured identifiers redacted, before anything persists to Exabeam. Deterministic code at the bridge, not a prompt.
- Every call is audited — a local, metadata-only trail of what was called, when, and with what result. Nothing phones home.
What the code stops, and what it deliberately doesn't →
The gate
A human before anything is dismissed or closed — enforced by the host, not the model
The moment the plugin is enabled, with nothing to configure: the same allow / ask / deny tiers, generated from one source, land on each host the way that host enforces them. Containment is denied outright; dismiss and close ask; reads run without a prompt; a tool nobody has classified asks rather than running.
A hook that ships in the plugin
Active the moment the plugin is enabled: ask on dismiss and close, deny on every containment verb, ask on anything unclassified — and it holds even under --dangerously-skip-permissions.
Policy that ships inside the package
The same tiers as Codex tool-approval modes. Destructive tools require a human in every mode and are canceled when nobody is present — fail closed, codex exec included.
Nothing above is a claim. Twenty-nine attack fixtures, five trials each, on the weakest supported model per host, before every release — and the dated results ship with the code. The numbers ↓
Five separable layers
A skill is a markdown file. This is a system.
Keeping the layers separate is the point: the model holds the judgment, the code holds the enforcement, and the process proves both — every release.
The procedures
Entity pivots, baselining by querying, competing hypotheses, an evidence bar, stopping conditions, an action matrix — in SKILL.md, shared across all three skills as one safety spine and enforced by invariant tests.
The Exabeam MCP, bundled
SIEM search, alerts and cases, threat timelines, rule and MITRE context — reached through a local bridge that ships with the plugin for each host, never wired by hand.
Who may do what, enforced by the host
Allow, ask, deny — generated from one source, pinned by tests, enforced by the bundled hook on Claude Code or by Codex's tool-approval policy. Not by the model.
The bridge treats telemetry as hostile
Canonicalize on read, neutralize on write, refuse containment outright, and record a metadata-only audit trail of every call. Deterministic Python you can diff.
Security evidence, included
Release testing, behavior checks, and a machine-readable ingredients list are published with every version.
Security assurance
Tested hard. Documented openly.
Raffkin is security-tested before every release, scanned to confirm that it behaves as intended, and shipped with a transparent ingredients list. Detailed results are published for anyone who wants the fine print.
Attacked before release
Raffkin is repeatedly tested against prompt injection, verdict manipulation, unsafe actions, and data exposure. A release is blocked until discovered problems are fixed and tested again.
Know what is inside
Every release includes a machine-readable list of the models, tools, software dependencies, and governance controls Raffkin uses.
Checked against its job description
Praxen compares what Raffkin is supposed to do with its code and release evidence, then reports where its behavior or controls do not match.
Fine print for security teams and reviewers: the repository includes the full methodology, dated test results, behavior remit, detailed scoring, and CycloneDX inventories.
Get started in minutes
Four steps. Two commands.
Install the plugin
One marketplace add and one install, on Claude Code or Codex. The Exabeam MCP bridge comes bundled — nothing else to wire.
Add credentials
A single ~/.exabeam-mcp.env with your New-Scale API key. The bridge refreshes the token itself.
The gate is already on
It ships inside the plugin on both hosts — a hook on Claude Code, approval policy on Codex. Reads run without a prompt. Nothing to configure.
Ask
"Investigate alert X." Raffkin gathers evidence, writes the verdict, and asks you before anything is dismissed or closed.
The commands
Raffkin runs as a plugin in your coding agent. One command adds the community marketplace and installs it. Add your Exabeam credentials and hunt — the human-in-the-loop gate is already on.
Full guide: Installation & setup · User guide
# install Raffkin in your terminal $ claude plugin marketplace add open-agent-ai-security/plugins $ claude plugin install raffkin@open-agent-ai-security # then, in Claude Code > investigate alert 8f67ee43-bfa0-4f84-a5d0-42f97d893aed
# install Raffkin in your terminal $ codex plugin marketplace add open-agent-ai-security/plugins $ codex plugin add raffkin@open-agent-ai-security # the safety gate is already on — confirm the plugin loaded $ codex plugin list # then, in Codex > investigate alert 8f67ee43-bfa0-4f84-a5d0-42f97d893aed
Put a hunter on the queue — one built for hostile data.
Open source, Apache-2.0, built in the open with the Open Agent and AI Security Community.