OpenAI 2026 hackathon

ScreamSIEM

ScreamSIEM is an SSH-native incident-response platform for small Linux fleets. It continuously detects suspicious changes, like unexpected network listeners, then uses GPT-5.6 to explain the evidence.

Solo project by Damon Bree · 1 likes · 0 comments

Archive position — measured, not model output

1 like on Devpost

506 of the 7,856 archived projects have more likes, and 1,758 share exactly 1 — so this project's #1,882 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

What the company appears to be

ScreamSIEM is an SSH-native incident-response platform for small Linux fleets. The description states that it connects over SSH to Linux hosts, detects suspicious changes using deterministic methods and GPT-5.6, and explains findings in plain English with human approval required for any action.

What changed

The author reports building an end-to-end MVP in four days, including installation via curl, host enrolment, detection of a deliberately created HTTP listener, AI investigation, and presentation of approval-gated remediation steps.

Single most important open question

Is there evidence that this product has been adopted or tested beyond the author’s own deployment? The description states no revenue, customers or traction data are available beyond what the author reports.

Back to contents

What The Product Actually Is

The description states that ScreamSIEM:

  • Connects to Linux servers, VMs and containers over SSH.
  • Uses a constrained, read-only MCP bridge for process, socket, service, journal, log, and system metrics.
  • Learns a baseline of normal host behaviour and uses deterministic detectors to identify changes such as unexpected listening ports.
  • Uses GPT-5.6 to investigate evidence, explain findings, cite events, describe uncertainty, and propose manual or approval-gated actions.
  • Provides a dashboard with live findings, confidence scores, host health, SSE updates, sound alerts, copy-pasteable commands, and human approval before mutating actions.
  • Can use either an OpenAI API key or headless Codex ChatGPT authentication.
  • Is built with FastAPI, SQLite, Pydantic, AsyncSSH, MCP, systemd, and a Cloudflare Worker.

Inference The product is described as a lightweight, self-contained security monitoring tool that integrates AI for explanation and limited automation, designed for small Linux fleets.

Back to contents

Positioning & Claim Evolution

The description states:

  • The platform was built to address the difficulty of monitoring small Linux fleets.
  • It aims to provide a practical solution for self-hosted infrastructure.
  • It is positioned as an alternative to SIEM tools that require manual coding or lack integration with SSH access.
  • It emphasizes plain English explanations and safe AI interaction without unrestricted shell access.

Inference The positioning evolved from a hackathon MVP to a potential tool for teams lacking enterprise-grade SOC/CERT capabilities, but the description does not indicate any prior market positioning or customer feedback.

Back to contents

Target Customer & ICP

The description states:

  • The target is small Linux fleets.
  • It is designed for self-hosted infrastructure.
  • The long-term goal is to make high-quality incident response accessible to teams that have Linux infrastructure but do not have the budget or operational complexity of a full enterprise SOC or CERT.

Inference The ICP appears to be small teams or individuals managing Linux-based infrastructure, with no evidence of prior customer segmentation or market validation.

Back to contents

Business Model & Pricing Evidence

Not evidenced. The description does not state anything about pricing, monetization, or business model.

Back to contents

Technical & Delivery Signals

The description states:

  • Built with FastAPI, SQLite, Pydantic, AsyncSSH, MCP, systemd, and a Cloudflare Worker.
  • Uses ChatGPT with GPT-5.6 for specification, implementation tickets, security boundaries, and architecture diagrams.
  • Codex helped implement the system using a test-driven workflow.
  • Includes a public curl command for controller installation.
  • Enrols remote hosts via SSH.
  • Supports headless ChatGPT authentication.
  • Uses structured output schemas and validation.
  • Has a dashboard with live updates and sound alerts.

Inference The technical stack suggests a lightweight, developer-focused solution built with modern tools. The use of GPT-5.6 for design and implementation indicates an AI-assisted development approach.

Back to contents

Traction & Maturity Signals

Not evidenced. The description states:

  • An end-to-end working MVP was completed in four days.
  • It works on real machines, not just mock demos.
  • No revenue, customers or traction data are available beyond the author’s own account.

Inference There is no evidence of adoption, usage metrics, or customer feedback. The product is described as a hackathon submission with no indication of market traction.

Back to contents

Competitive Context

Not evidenced. The description does not mention any competitors or how ScreamSIEM compares to existing solutions like Splunk, Wazuh, or other SIEM tools.

Back to contents

Key Risks & Red Flags

  • No evidence of adoption or usage beyond the author’s own deployment.
  • No revenue or customer data.
  • The use of GPT-5.6 is self-reported; no validation of performance or accuracy.
  • The system relies on SSH access, which may not be available in all environments.
  • The description does not clarify how the AI's recommendations are validated or audited.
  • No mention of compliance, scalability, or production hardening beyond a demo.

Back to contents

Diligence Questions To Ask The Founders

  1. Has ScreamSIEM been tested in any real-world environments beyond the author’s own?
  2. What is the actual performance and accuracy of GPT-5.6 in detecting and explaining threats?
  3. How does the system handle false positives or uncertain findings?
  4. Are there any plans for integrating with existing alerting systems (e.g., SMS, PagerDuty)?
  5. What are the limitations of the current MVP that would need to be addressed before production use?
  6. Is there a plan to support more complex Linux environments or containerized infrastructure?
  7. How does the system ensure secure handling of API keys and authentication tokens?

Back to contents

Investment/Partnership Verdict

Not evidenced. The description states that no revenue, customer or traction data is available beyond what the author reports. There is no indication of market demand, competitive positioning, or business model viability.

Confidence Level Low — based on self-reported evidence only, with no independent validation or traction data.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.