What is HIKMA?
HIKMA (Arabic: حكمة — wisdom) is a Cyber Defense Platform — a unified operating model for modern security operations teams. It is not a single tool. It is the infrastructure layer that connects your people, processes, and technologies into one coherent defense posture.
Traditional security stacks accumulate over years: a SIEM here, a SOAR there, separate case management, disconnected threat intel feeds. The result is tool fatigue, context loss, and blind spots. HIKMA replaces this fragmentation with a structured operating model.
"Not a tool. An intelligence platform."
Platform Architecture
HIKMA is organized around three horizontal layers and a scope-aware permission system that spans from platform-wide configuration down to individual users.
Control Plane
The administrative layer. Platform operators, company admins, and department leads configure the system here. No operational data lives in the Control Plane.
Module Layer
The capability layer. Each module is independently deployed and scoped. Modules share a common data model but can be activated per-tenant or per-department.
Data Plane
The operational layer. Analysts, incident responders, and threat hunters live here. Real-time events, alerts, and case data flow through the Data Plane.
Capability Modules
Security Orchestration, Automation & Response. Build playbooks, automate response workflows, and coordinate actions across your security stack.
Aggregate, normalize, and correlate threat data from multiple sources. IOC management, threat actor tracking, and intelligence-driven detections.
Full evidence chain management, investigation workflows, timeline reconstruction, and analyst assignment with full audit trail.
Complete asset inventory with risk scoring, vulnerability tracking, ownership assignment, and lifecycle management.
Framework mapping (NIST, ISO 27001, SOC 2, PCI DSS), automated evidence collection, audit trails, and gap analysis reporting.
AI-powered behavioral analysis, anomaly detection, risk scoring, and executive-level reporting dashboards.
Account compromise detection, privilege abuse monitoring, impossible travel alerts, and identity threat scoring.
Multi-tenant administration, RBAC configuration, department management, integration registry, and platform health monitoring.
Getting Started
HIKMA is invite-only during the current access phase. If your organization has been onboarded, follow these steps.
Request credentials from your platform administrator
Log in at the platform URL provided to your organization
Complete the onboarding wizard to configure your tenant
Activate the modules relevant to your security program
Connect your data sources via the Integration Registry
Configure your first SOAR playbook or create a case
Scope-Aware RBAC
HIKMA implements a hierarchical, scope-aware Role-Based Access Control system. Permissions cascade down the hierarchy — a role at a higher scope can be restricted but not expanded at a lower scope.
API Reference
HIKMA exposes a RESTful API built on FastAPI with automatic OpenAPI documentation. All endpoints require authentication via JWT bearer tokens.
Open Interactive API Docshttp://2.25.184.240:8000/api/v1/auth/loginAuthenticate and receive JWT tokens/tenants/List accessible tenants/modules/List available platform modules/healthPlatform health status