Skip to content

Repository files navigation

NetCortex

An Agentic AI Platform for Autonomous Network Operations

5G control-plane capture analysis: decode NGAP/NAS (N2), PFCP (N4), and SBI (HTTP/2) captures, map per-UE flows, compute KPIs, triage failed procedures with an LLM agent, and run incidents through a human-gated remediation pipeline.

The dispatch pipeline

Dispatch pipeline — raise or detect, handle, human-gated execution, close + learn

One incident, end to end: an Alarm event (human-raised or synthesized from KPI degradation) fans out to three specialist evidence agents, their findings are correlated, a LATS root-cause search runs, and a remediation proposal from a fixed five-action vocabulary waits at the Human approval gate — with the Outcome feeding a gated learning loop. The committed end-to-end sample Incident Record shows a real n4_upf_timeout run: detected from KPI degradation, investigated by the live specialists, left pending at the gate. The same run is rendered as an interactive incident page — The Blackholed UPF, hosted on GitHub Pages from demo/index.html. The diagram's source of truth is dispatch/docs/diagrams/pipeline.json.

The impact advisory

impact — pre-change advisory, end to end

Before a Change lands: a proposed NF upgrade or config change is assessed read-only against the platform's evidence — the episode stores, the Change History, prior captures' dependency structure, the 3GPP specgraph, and an optional human test plan — and graded HIGH, MEDIUM, LOW, or INSUFFICIENT EVIDENCE by a fixed rubric whose every factor is cited in the report. The Impact Report ends with pre-checks and rollback criteria; a human decides and applies, then records the Outcome — applied, rejected, or rolled-back — through the annotation loop, which alone writes the Change History. A new Change matching a past failed record grades HIGH. See impact/README.md; the diagram's source of truth is impact/docs/diagrams/impact-flow.json.

Layout

  • 5gcap/ — the analyzer itself (5gcap analyze <file.pcap>), one binary ladder N2 → N4 → SBI; given all three captures, one merged JSON export correlated by strict key equality (ADR-0007). See 5gcap/README.md for usage and v1 scope.
  • triage/ — LLM-agent root-cause hypothesis generation over 5gcap's decode output (LATS search, episodic memory, 3GPP spec graph; on the merged export, joined SBI/N4 Incidents carry their flow id), a deterministic post-incident report writer, and an offline eval harness scored against labeled sandbox fixtures. A sample post-incident report from a live run is in triage/examples/. See triage/README.md.
  • sandbox/ — local Open5GS + UERANSIM lab that generates real captures for 5gcap and labeled failure-injection scenario fixtures (./capture.sh --scenario <name>) for triage's evals. See sandbox/README.md.
  • dispatch/ — event-driven incident orchestration over the stack: a KPI-degradation detector or a human raises an Alarm event, PCAP/Log/KPI specialist agents ground evidence against the decode, core logs and the Golden baseline, a root-cause search correlates it, and a remediation proposal from a fixed five-action vocabulary waits at a Human approval gate. A real end-to-end sample Incident Record is committed. See dispatch/README.md.
  • impact/ — pre-change advisory over the stack: a proposed Change (NF upgrade or config change) is assessed read-only against the platform's evidence — episode stores, the Change History, captures, the specgraph, an optional human test plan — and graded by a fixed cited rubric into an Impact Report with pre-checks and rollback criteria. A human decides and applies, then records the Outcome through the annotation loop that alone writes the Change History. See impact/README.md.
  • CONTEXT.md — 5gcap domain glossary (Capture, Flow, Procedure, KPI, Partial Flow); triage/CONTEXT.md — triage domain glossary; dispatch/CONTEXT.md — dispatch domain glossary; impact/CONTEXT.md — impact domain glossary. CONTEXT-MAP.md maps the four contexts and their relationships.
  • docs/adr/ — architecture decision records.
  • Diagrams — docs/diagrams/ holds the 5gcap pipeline diagram from the Medium article (fireworks-tech-graph IR + rendered SVG + PNG, style 2 Dark Terminal; the regeneration recipe, including the no-system-fonts PNG trap, is in its README); dispatch/docs/diagrams/ holds the dispatch pipeline's set — the same IR + SVG + PNG trio plus LangGraph's own mermaid view of the compiled graph for comparison — with the same recipe in its README; and triage/docs/diagrams/ holds the triage invocation-flow diagram (IR + SVG); impact/docs/diagrams/ holds the impact advisory-flow diagram (IR + SVG + PNG) with the same recipe in its README.

Roadmap

Planned as sibling projects on this platform: a Cross-Domain Incident Correlation project and a Digital Twin — each will land as its own top-level directory alongside 5gcap/, triage/, dispatch/, and impact/.

Development

cd 5gcap
uv sync
uv run pytest
cd triage
uv sync
uv run pytest
cd dispatch
uv sync
uv run pytest
cd impact
uv sync
uv run pytest

About

Event-driven 5G incident orchestrator: multi-agent evidence gathering (PCAP/log/KPI), LATS root-cause analysis, and human-gated remediation. LangGraph, with an offline eval harness.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages