Open Source · MIT License · v1.0.0

HOLLOW
PURPLE

An autonomous cloud identity defense platform that watches attackers move through a maze — then moves the walls. Built with AI, deception engines, and graph intelligence.

MIT License Python 3.11+ FastAPI · PyTorch · Neo4j AWS · GCP · Azure
get started in 30 seconds
$ git clone https://github.com/Tejaswanth2406/hollow-purple.git

or download the ZIP · no account required

3
AI Layers
47s
Avg. Time to Neutralize
0
Real Records Exfiltrated (in tests)
MIT
License — Free Forever
what it does

Defense that thinks before it acts

Hollow Purple doesn't just alert. It observes, decides, deceives, and neutralises — without touching production systems until it's sure.

🕸
Identity Graph Engine
Maintains a live temporal graph of every identity, role, and privilege edge across AWS, GCP, and Azure. Watches how the graph moves in real time.
🧠
AI Threat Detection
A Graph Neural Network (GNN) trained on attack topologies spots lateral movement patterns before a human analyst would see the shape.
🎭
Deception Engine
When risk crosses 0.7, attackers are silently redirected to a convincing fake environment. They think they won. Every move is recorded.
⚖️
MAHORAGHA Governance
Zero auto-apply to production. Every mutation is proposed, explainability-scored, and gated behind a human decision. Always advisory.
🔗
Merkle Audit Log
Every event, every decision, every session is hash-chained into a tamper-evident Merkle log. Replay any point in time to the millisecond.
🤖
RL Defense Agent
A PPO-trained reinforcement learning agent continuously improves its response strategy — picking the lowest-blast-radius action every time.
the pipeline

From raw event to neutralised threat

Eight stages. One continuous loop. Attacker never reaches real data.

01
Cloud Event
AWS · GCP · Azure
02
Ingestion
Normalise · Validate
03
Graph Update
Identity · Roles · Edges
04
GNN Scores
Pattern recognition
05
Bayesian Risk
Propagate · Quantify
06
RL Agent Acts
Lowest blast radius
07
Deception / Isolate
Cage or cut
08
Merkle Sealed
Tamper-proof log

Full walkthrough in the README · Average latency from event to action: ~47ms

built with

Production-grade open-source stack

No proprietary dependencies. Swap out any layer with your own tooling.

Python 3.11+ FastAPI PyTorch PyTorch Geometric Stable-Baselines3 NetworkX PostgreSQL Redis Neo4j DuckDB InfluxDB Prometheus AWS CloudTrail GCP Audit Logs Azure Monitor
open source · free forever

Download it.
Wire it up.
Move the walls.

Hollow Purple is MIT-licensed and built to be self-hosted. No SaaS, no subscription, no vendor lock-in. Clone it, configure your cloud credentials, and run it.

MIT License · No telemetry · No phone-home · Self-hosted