Using the Dashboard
Once agents or log sources are reporting in, everything happens from one dashboard. This page is a tour of the main areas.
Dashboard overview
The landing page shows active alert counts, online agent status, a platform threat score, alert trend over 24 hours, severity breakdown, and top firing rules — a snapshot of overall posture at a glance.
Alerts
Filterable by status (open/acknowledged/resolved) and severity. Each alert expands into a detail panel showing the raw log message, MITRE ATT&CK technique/tactic mapping, AI-assisted triage (if configured), investigation context (similar historical alerts, IOC hits, correlated rules), and manual response actions.
Incidents
Alerts that correlate across sources or time get grouped into incidents automatically, with a unified timeline and DFIR artifact collection.
Playbooks (SOAR)
Create branching automation chains triggered by alert conditions. Non-destructive actions (Slack notification, ticket creation, enrichment) run immediately; destructive actions (kill process, isolate host, quarantine file) queue in SOAR Approvals pending analyst sign-off.
Rules
Manage Sigma rules, YARA rules, and JA3 fingerprint blocklists from their respective pages. Rules are tenant-scoped — changes only affect your own environment.
Threat Hunt
Ad-hoc queries across endpoint telemetry, with a Hunt Workbench for tracking a hypothesis across multiple queries and findings.
Log Search
A lightweight query syntax (user:admin src_ip:10.0.0.0/8 "failed login") over stored logs, with adjustable time windows and per-agent/per-source filtering.
Risk Posture & Compliance
A composite risk score computed from open alerts, vulnerabilities, and UEBA behavioral signals. Framework compliance (CIS Controls, NIST CSF, PCI-DSS) is scored automatically from what's actually deployed — Sigma rules, YARA rules, firewall rules, agents, vulnerabilities, audit logs, playbooks — not from a manually-filled questionnaire.
Vulnerability Priority Queue
CVEs affecting installed packages, ranked by a combined score: CVSS × 10 + EPSS × 200 + KEV × 300 + asset criticality + risk bonus — so a lower-CVSS vulnerability with active known exploitation (KEV) can outrank a higher-CVSS one that isn't being exploited in the wild.