| Time | Host | Event | Severity | Score | Details |
|---|---|---|---|---|---|
No alerts yet | |||||
Incidents
Security incidents requiring attention
| Time | Host | Event | MITRE | Tactic | Rule | Severity | Score | Details |
|---|
Endpoints
All enrolled endpoints
| Hostname | IP | OS | Status | Last Seen | Actions |
|---|
Agent Detail
| Time | Type | MITRE | Rule | Severity | Score | Detail |
|---|
Threat Hunting
Search across all endpoint telemetry
| Time | Host | Type | MITRE ID | Tactic | Rule | Severity | Score | Details |
|---|
Detection Rules
MITRE ATT&CK detection rules
| ID | Name | MITRE | Tactic | Severity | Score | Type | Status | Actions |
|---|
Entities
Unified identity resolution — users and hosts across all data sources
UEBA
User and Entity Behavior Analytics
| Time | User | Type | Score | MITRE |
|---|
Vulnerability Detection
CVE matching against installed software inventory
| Package | Version | CVE | Severity | CVSS | Description |
|---|---|---|---|---|---|
Click Scan Now | |||||
CIS Compliance
CIS Benchmark security configuration assessment (Linux)
| Check ID | Title | Severity | Status | Output |
|---|---|---|---|---|
Click Run Checks | ||||
AI Security Analyst
AI-powered threat analysis and real-time security assistant
Examples:
"What are the most critical threats right now?"
"Explain what T1110 attack is happening"
"Write a PowerShell script to block IP 45.33.32.156"
"Is the suspicious port scan a false positive?"
"What should I investigate first?"
Dark Web Monitor
Monitor for breaches, leaked credentials and mentions of your organization
Threat Intelligence
VirusTotal (Wazuh) + AbuseIPDB + AlienVault OTX — API quota, IP lookup, enrichment log
Active Response
Issue commands to enrolled agents
SOAR — Automated Response
Security Orchestration, Automation and Response
Firewall Management
Server-side IP blocking, fail2ban integration, and threat IP intelligence
Agents
Enrolled security agents
| Hostname | Agent ID | OS | IP | Status | Last Seen | Actions |
|---|
Users
Dashboard user accounts
| User | Role & Permissions | Status | Last Login | Actions |
|---|
Wazuh Integration
Connect Cibervault to your Wazuh SIEM for unified threat visibility
| ID | Name | IP | OS | Status | Last Seen |
|---|---|---|---|---|---|
Connect Wazuh to see agents | |||||
| Time | Agent | Rule | Level | Description |
|---|---|---|---|---|
No alerts | ||||
systemctl status wazuh-managerDefault API port: 55000
Default user: wazuh-wui
/var/ossec/etc/ossec.conf:<integration> <name>custom-cibervault</name> <hook_url>http://CIBERVAULT_IP:8081/api/v1/wazuh/alert</hook_url> <level>7</level> <alert_format>json</alert_format> </integration>
Settings
Configuration