This deliverable provides an overview of all the algorithms and models to be used in the AI-based Attack Detection (AAD) component of the SOCCRATES platform. A set of intrusion detection tools and the over-arching reasoning engine used for correlating the produced alerts are described in detail. The efficiency of the pro-posed AAD component is illustrated by means of numerical experiments on the CIDDS public dataset. Integration and deployment matters are also addressed.