⬡ NICE Framework v2.1 · Open Source

CIPHER Agent Directory

Cybersecurity Intelligence Personas for Human-in-the-loop Enterprise Response — 40 agent personas across 5 NICE categories

40Agent Personas
5NICE Categories
3Autonomy Tiers
0Actions Taken
Agent Personas
PD-WRL-001 T3 · Autonomous
Defensive Cybersecurity
Protection & Defense
Monitors, analyzes, and triages security events from SIEM and EDR. First responder to alerts — enriches, deduplicates, classifies severity, and escalates confirmed incidents.
0Actions
0Tasks
0/0Completed
PD-WRL-002 T2 · Copiloted
Incident Response
Protection & Defense
Manages the full incident response lifecycle: detection, analysis, containment, eradication, recovery, and post-incident review. Coordinates agents and escalates to human operators.
0Actions
0Tasks
0/0Completed
PD-WRL-003 T2 · Copiloted
Digital Forensics
Protection & Defense
Collects, preserves, and analyzes digital evidence in support of incident response and investigations. Maintains strict chain of custody and produces forensic reports.
0Actions
0Tasks
0/0Completed
PD-WRL-004 T3 · Autonomous
Infrastructure Support
Protection & Defense
Monitors and supports cybersecurity infrastructure components — firewalls, IDS/IPS, proxies, and security tooling. Identifies misconfigurations and degraded security controls.
0Actions
0Tasks
0/0Completed
PD-WRL-005 T2 · Copiloted
Insider Threat Analysis
Protection & Defense
Analyzes behavioral and technical indicators to detect and assess insider threats. Integrates UEBA data, access logs, and HR signals while maintaining privacy and legal boundaries.
0Actions
0Tasks
0/0Completed
PD-WRL-006 T3 · Autonomous
Threat Analysis
Protection & Defense
Produces finished threat intelligence by analyzing adversary TTPs, campaigns, and indicators. Enriches IOCs, tracks threat actors, and maintains the organization's threat picture.
0Actions
0Tasks
0/0Completed
PD-WRL-007 T3 · Autonomous
Vulnerability Analysis
Protection & Defense
Identifies, assesses, and prioritizes vulnerabilities in organizational systems. Correlates CVEs with asset inventory, provides risk-scored remediation recommendations.
0Actions
0Tasks
0/0Completed
IN-WRL-001 T1 · Human-Administered
Cybercrime Investigation
Investigation
Supports cybercrime investigations by gathering and analyzing digital evidence. Operates exclusively in advisory mode — all investigative actions executed by human investigators.
0Actions
0Tasks
0/0Completed
IN-WRL-002 T2 · Copiloted
Digital Evidence Analysis
Investigation
Conducts detailed analysis of digital evidence to support investigations. Applies forensic techniques to extract, examine, and interpret digital artifacts.
0Actions
0Tasks
0/0Completed
IO-WRL-001 T3 · Autonomous
Data Analysis
Implementation & Operation
Analyzes large datasets to identify patterns, anomalies, and security-relevant insights. Supports threat hunting and operational analytics across log and telemetry sources.
0Actions
0Tasks
0/0Completed
IO-WRL-002 T2 · Copiloted
Database Administration
Implementation & Operation
Administers and secures organizational databases, ensuring data integrity, access control, and monitoring for unauthorized access or exfiltration.
0Actions
0Tasks
0/0Completed
IO-WRL-003 T3 · Autonomous
Knowledge Management
Implementation & Operation
Manages the organization's cybersecurity knowledge base — maintaining playbooks, lessons learned, policy documents, and threat intelligence in accessible, structured form.
0Actions
0Tasks
0/0Completed
IO-WRL-004 T2 · Copiloted
Network Operations
Implementation & Operation
Monitors and supports secure operation of organizational networks. Identifies network anomalies, misconfigurations, and unauthorized devices or traffic patterns.
0Actions
0Tasks
0/0Completed
IO-WRL-005 T2 · Copiloted
Systems Administration
Implementation & Operation
Administers and secures operating systems and endpoints. Monitors for configuration drift, unauthorized changes, and compliance with security baselines.
0Actions
0Tasks
0/0Completed
IO-WRL-006 T2 · Copiloted
Systems Security Analysis
Implementation & Operation
Analyzes system security posture, validates security controls, and identifies gaps between policy requirements and operational reality.
0Actions
0Tasks
0/0Completed
IO-WRL-007 T3 · Autonomous
Technical Support
Implementation & Operation
Provides technical support for cybersecurity tools and processes. Triages security tool issues, maintains operational tooling, and supports end-user security queries.
0Actions
0Tasks
0/0Completed
DD-WRL-001 T2 · Copiloted
Cybersecurity Architecture
Design & Development
Designs and evaluates cybersecurity architectures for systems and networks. Assesses proposed designs against security requirements and organizational risk tolerance.
0Actions
0Tasks
0/0Completed
DD-WRL-002 T2 · Copiloted
Enterprise Architecture
Design & Development
Integrates cybersecurity requirements into enterprise IT architecture. Ensures security is embedded in enterprise technology planning and system acquisitions.
0Actions
0Tasks
0/0Completed
DD-WRL-003 T2 · Copiloted
OT Cybersecurity Engineering
Design & Development
Applies cybersecurity engineering principles to operational technology (OT), ICS, and SCADA systems. Bridges IT security practices with OT operational constraints.
0Actions
0Tasks
0/0Completed
DD-WRL-004 T2 · Copiloted
Secure Software Development
Design & Development
Develops and reviews software with security embedded throughout the SDLC. Identifies and remediates security vulnerabilities in source code and dependencies.
0Actions
0Tasks
0/0Completed
DD-WRL-005 T2 · Copiloted
Secure Systems Development
Design & Development
Ensures security requirements are defined and verified throughout the systems development lifecycle for hardware, software, and integrated systems.
0Actions
0Tasks
0/0Completed
DD-WRL-006 T2 · Copiloted
Software Security Assessment
Design & Development
Evaluates software products and applications for security vulnerabilities through structured assessment methodologies including penetration testing and code analysis.
0Actions
0Tasks
0/0Completed
DD-WRL-007 T2 · Copiloted
Systems Requirements Planning
Design & Development
Translates organizational security objectives into actionable system security requirements. Ensures security requirements are complete, testable, and traceable.
0Actions
0Tasks
0/0Completed
DD-WRL-008 T3 · Autonomous
Systems Testing and Evaluation
Design & Development
Plans and executes security testing of systems to validate that security controls function as intended and meet specified requirements.
0Actions
0Tasks
0/0Completed
DD-WRL-009 T3 · Autonomous
Technology Research and Development
Design & Development
Researches emerging technologies, attack techniques, and defensive capabilities. Produces research findings that inform strategic security decisions and tool selection.
0Actions
0Tasks
0/0Completed
OG-WRL-001 T2 · Copiloted
Communications Security Management
Oversight & Governance
Oversees communications security policies and programs. Ensures secure communications channels are available, properly configured, and protected from interception.
0Actions
0Tasks
0/0Completed
OG-WRL-002 T2 · Copiloted
Cybersecurity Policy and Planning
Oversight & Governance
Develops, reviews, and assesses cybersecurity policies, plans, and procedures. Ensures policies are current, aligned with standards, and enforced across the organization.
0Actions
0Tasks
0/0Completed
OG-WRL-003 T2 · Copiloted
Cybersecurity Workforce Management & Training
Oversight & Governance
Manages cybersecurity workforce development programs. Identifies skill gaps, tracks certifications, and ensures training program alignment with operational needs.
0Actions
0Tasks
0/0Completed
OG-WRL-004 T3 · Autonomous
Cybersecurity Curriculum Development & Instruction
Oversight & Governance
Develops and delivers cybersecurity training content. Creates instructional materials aligned with NICE framework competencies and organizational security needs.
0Actions
0Tasks
0/0Completed
OG-WRL-005 T2 · Copiloted
Cybersecurity Legal Advice
Oversight & Governance
Provides legal analysis and guidance on cybersecurity-related matters. Advises on regulatory compliance, incident disclosure obligations, and legal aspects of incident response.
0Actions
0Tasks
0/0Completed
OG-WRL-006 T2 · Copiloted
Executive Cybersecurity Leadership
Oversight & Governance
Provides strategic cybersecurity leadership and oversight. Synthesizes security program performance for executive decision-making and board-level reporting.
0Actions
0Tasks
0/0Completed
OG-WRL-007 T2 · Copiloted
Privacy Compliance
Oversight & Governance
Oversees organizational compliance with privacy regulations. Assesses data handling practices, identifies privacy risks, and advises on privacy-preserving security controls.
0Actions
0Tasks
0/0Completed
OG-WRL-008 T3 · Autonomous
Product Support Management
Oversight & Governance
Manages lifecycle and security of cybersecurity products and tools deployed in the organization. Tracks versions, licenses, EOL status, and vulnerability patches.
0Actions
0Tasks
0/0Completed
OG-WRL-009 T2 · Copiloted
Program Management
Oversight & Governance
Manages cybersecurity programs — tracking milestones, resources, risks, and outcomes across multi-initiative security programs.
0Actions
0Tasks
0/0Completed
OG-WRL-010 T2 · Copiloted
Secure Project Management
Oversight & Governance
Manages cybersecurity projects with security embedded throughout the project lifecycle. Tracks security deliverables, risks, and outcomes.
0Actions
0Tasks
0/0Completed
OG-WRL-011 T2 · Copiloted
Security Control Assessment
Oversight & Governance
Independently assesses the implementation and effectiveness of security controls. Produces findings for risk management and authorization decisions.
0Actions
0Tasks
0/0Completed
OG-WRL-012 T1 · Human-Administered
Systems Authorization
Oversight & Governance
Supports Authorizing Officials with the information needed to make risk-based authorization decisions. Prepares authorization packages and monitors system security posture continuously.
0Actions
0Tasks
0/0Completed
OG-WRL-013 T2 · Copiloted
Systems Security Management
Oversight & Governance
Manages the overall cybersecurity posture of organizational systems. Oversees security monitoring, incident response, and security control maintenance.
0Actions
0Tasks
0/0Completed
OG-WRL-014 T2 · Copiloted
Technology Portfolio Management
Oversight & Governance
Manages the cybersecurity technology portfolio — tracking investments, rationalization, and alignment of security tools with organizational needs.
0Actions
0Tasks
0/0Completed
OG-WRL-015 T2 · Copiloted
Technology Program Auditing
Oversight & Governance
Independently audits cybersecurity programs and controls for compliance with policies, standards, and regulatory requirements. Produces objective audit findings.
0Actions
0Tasks
0/0Completed