Agentic SOC Dashboard
Autonomous. Adaptive. Always Defending.
LIVE · 0 alerts
Last 24 hours
2
SA
SOC Analyst
Threat Intelligence & Hunt
Run pre-built hunting queries against your live alert store · 5 alerts indexed
Repeat Attacker
IPs with 2+ alerts
Click to hunt →
Unresolved CRITICAL
CRITICAL not remediated
Click to hunt →
Credential Attacks
T1110 brute force
Click to hunt →
Ransomware Hunt
T1486/T1490 activity
Click to hunt →
Lateral Movement
T1021 lateral movement
Click to hunt →
C2 & Exfiltration
Command and Control
Click to hunt →
High Confidence Open
Confidence >85%
Click to hunt →
Recent CRITICAL (1h)
CRITICAL last hour
Click to hunt →
Threat Intelligence
IOC feed · MITRE ATT&CK coverage · Extracted from your live alerts
Active IOCs
IndicatorTypeSeveritySourceAdded
10.0.1.45IPCriticalSOC Agent11m ago
10.0.2.112IPMediumSOC Agent45m ago
185.234.56.78IPHighSOC Agent1h ago
10.0.0.15IPCriticalSOC Agent2h ago
malware-c2.evil.ruDomainHighOTX Feed27m ago
d41d8cd98f00b204MD5 HashHighVirusTotal1h ago
CVE-2024-3094CVECriticalNVD1h ago
MITRE ATT&CK Coverage
Initial Access2/9
T1566.001
Execution2/12
T1059.001
Credential Access2/16
T1110.001
Lateral Movement2/9
T1021.001
Command & Control2/18
T1071.001
Privilege Escalation2/13
T1068
Assets
Assets detected from alert data · Connect Wazuh to auto-populate inventory
Asset NameTypeIP AddressOpen AlertsLast AlertStatus
prod-dc-01Server10.0.1.45111m agoAlert
mail-gw-01ServerInternal123m agoAlert
prod-web-01Server10.0.2.112145m agoAlert
ws-dev-03Server185.234.56.7811h agoAlert
prod-app-02Server10.0.0.1512h agoAlert
ws-dev-03Workstation10.0.3.440NeverHealthy
db-primary-01Database10.0.1.100NeverHealthy
mail-gatewayGateway10.0.0.20NeverHealthy
Total Incidents
23
-24% vs yesterday
Critical Incidents
5
-16% vs yesterday
Alerts Processed
1248
+18% vs yesterday
MTTR (Agentic)
18m 42s
-32% vs yesterday
Auto-Resolved
14
+40% vs yesterday
Threat Detections
356
+22% vs yesterday
Incident Severity DistributionLast 24 hours
23Total
Critical5(22%)
High8(35%)
Medium6(26%)
Low3(13%)
Info1(4%)
Incidents Over TimeLast 24 hours
00:0004:0008:0012:0016:0020:00
Critical
High
Medium
Low
Top Threats DetectedLast 24 hours
Phishing
9828%
Credential Access
7621%
Command & Control
6418%
Privilege Escalation
4513%
Lateral Movement
3710%
Data Exfiltration
3610%
Agentic Workforce
12
12
Active Agents
Triage Agent3Active
Investigation Agent3Active
Containment Agent2Active
Threat Intel Agent2Active
Response Agent2Active
Total Agents: 12All operational ●
Recent IncidentsView all incidents →
IDTitleSeverityStatusDetectedAsset
INC-0056Suspicious PowerShell ExecutionCriticalAuto-Remediated11m agoprod-dc-01
INC-0055Phishing Email DetectedHighPending23m agomail-gw-01
INC-0054Multiple Failed LoginsMediumOpen45m agoprod-web-01
INC-0053Outbound C2 TrafficHighPending1h agows-dev-03
INC-0052Privilege Escalation AttemptCriticalApproved2h agoprod-app-02
Agent Actions (Last 24h)
284
284
Total Actions
Investigate102(35.9%)
Enrich68(23.9%)
Contain54(19.0%)
Remediate38(13.4%)
Notify22(7.7%)
View all actions →
Playbook Executions
32
Total Executions ↑ 28% vs yesterday
Top Playbooks
Phishing Triage12
Malware Containment9
C2 Traffic Response6
Privilege Escalation5
View all playbooks →
Threat Intelligence Feed
New IOCs from MISP feed
23 IOCs added
11m ago
Malicious IP 185.220.101.12
Added to blocklist
27m ago
New CVE-2024-3094
Linux Kernel Privilege Escalation
1h ago
View threat intel →
Environment Health
OpenDefenders Platform
Healthy
Wazuh SIEM
Not Configured
Cloudflare WAF
Not Configured
Redis Cache
Healthy
Slack Notifications
Not Configured