Intelligent Active Directory Security Analytics

Project Overview

This platform implements centralized Active Directory security log analytics and AI-assisted triage to improve visibility into Windows security events. The architecture collects logs from domain controller DC01.lab.local, forwards them via Grafana Alloy to a Loki repository, and uses n8n with a local Phi-4 reasoning model to generate operational summaries and notifications.

Problem Statement

Active Directory generates hundreds of security events per hour, which are difficult to interpret in raw form. Manual analysis in Event Viewer is time-consuming, repetitive, and requires specialized knowledge of Windows Event IDs.

Technical Solution

The solution utilizes a layered architecture: