Security Operations Centers handle a continuous stream of security incidents. While AI can help analysts investigate these incidents, there is an important limitation with many AI-based systems: every new incident can effectively become a fresh start.
What if an AI incident-response assistant could remember what happened before?
This idea led us to build RECALL-X, an AI-powered SOC incident response assistant designed around persistent organizational memory.
The Problem
During incident response, security teams accumulate valuable knowledge. They learn which containment techniques worked, which approaches failed, what the actual root cause was, and which remediation ultimately resolved the incident.
An AI system without persistent memory may not automatically carry those lessons into the next incident.
RECALL-X attempts to bridge this gap.
Our Solution
RECALL-X integrates Hindsight by Vectorize as its persistent memory layer.
When an analyst submits a security incident, RECALL-X searches its organizational memory for semantically similar historical incidents. It can retrieve information about previous symptoms, root causes, unsuccessful containment attempts and successful remediation strategies.
This historical context is supplied to the AI reasoning pipeline, allowing the system to generate a response informed by previous organizational experience.
When an incident is resolved, its confirmed root cause and lessons learned can be retained in Hindsight so they become useful context for future incidents.
Memory OFF vs Memory ON
One of the core demonstrations in RECALL-X compares the same security scenario with persistent memory disabled and enabled.
Consider an incident involving hundreds of failed login attempts, followed by a successful login from an unknown IP and suspicious outbound network traffic.
Without historical memory, an AI assistant may recommend a conventional response such as blocking the suspicious IP.
With organizational memory available, RECALL-X can recall a previous incident where IP-only blocking was ineffective because the attacker rotated proxies. It can therefore incorporate previously successful measures such as account disablement, session revocation and stronger authentication into its recommendations.
This illustrates the central idea behind RECALL-X:
AI shouldn't just process incidents. It should learn from organizational experience.
Architecture and Technology
RECALL-X uses a React-based SOC dashboard connected to a FastAPI backend.
The incident-response pipeline combines:
React + Vite for the frontend
FastAPI + Python for backend APIs
Groq LLM for AI reasoning
Hindsight by Vectorize for persistent memory
SQLite for operational incident records
Operational data and AI memory are intentionally separated. SQLite maintains information such as incident status and timestamps, while Hindsight stores organizational experience and lessons.
Responsible AI
RECALL-X is designed as a defensive security assistant. It provides recommendations for investigation, containment and remediation rather than autonomously executing network actions.
Human security analysts remain responsible for evaluating and applying recommendations.
Conclusion
RECALL-X explores how persistent memory can transform an AI assistant from a system that simply responds to prompts into one that can benefit from an organization's accumulated incident-response experience.
Every resolved incident can become knowledge for the next one.
GitHub: https://github.com/sasidhark23-svg/RECALL-X
Top comments (0)