{{ pageTitle }}
{{ pageCrumb }}
{{ okCount }}ok {{ warnCount }}warn {{ critCount }}crit
Current posture
{{ clock }}
{{ clockDate }} UTC
Context {{ c.k }} {{ c.v }} FIM 24h {{ fimKpi.value }} · {{ fimKpi.sub }} {{ timeRange }} window
Open by severityCases →
{{ s.label }}
{{ s.count }}
Threat activity · {{ timeRange }} ▲ SPIKEThreat intel →
{{ g.label }} {{ g.count }}
-{{ timeRange }}{{ threatTotal }} detectionsnow
{{ topThreeTitle }}
{{ t.rank }}
{{ t.name }}
{{ t.meta }}
{{ t.count }}
MITRE ATT&CK · observed techniques · {{ timeRange }} heat = detection volume · live from rule.mitre
{{ ta.tactic }} {{ ta.total }}
{{ te.id }} {{ te.count }}
{{ te.name }}
Users & Access
Map each Cloudflare Access login (email) to a role + tenant scope. Who can log in is controlled in the Cloudflare Zero Trust dashboard; this page controls what they can do here. Roles: soc_admin (full + manage users), soc_analyst (respond, cases), read_only (view only).
Users & Access is soc_admin only. Your role: {{ myRole }}.
{{ userFormTitle }}
All tenants {{ t.label }}
{{ usersMsg }}
USERROLECONTACTTENANT SCOPE
{{ u.name }}
{{ u.emailLabel }}
{{ u.role }}
{{ u.contactLine1 }}
{{ u.contactLine2 }}
{{ u.tenants }}
Edit Remove
Agent Installer
Generate a ready-to-run monitoring agent for your endpoints. Each installer is pre-keyed to {{ instTenantName }} and connects out to the 365 Security gateway on port 443 — no inbound firewall changes and no VPN. Run it as Administrator (Windows) or root/sudo (Linux/macOS) on the machine you want monitored.
{{ instMsg }}
Installer ready — {{ instResName }}
Endpoint ID: {{ instResId }}
Agent group: {{ instResGroup }}
Gateway: {{ instResManager }}
Run as: {{ instResRunAs }}
{{ instResCmd }}
{{ instEdrNote }}
← All tenants
{{ tv.name }}
Grafana org {{ tv.org }} · {{ tv.siteCount }} sites monitored
{{ tv.healthLabel }}
Open org in Grafana ↗
{{ tv.isoNote }}
Client Profile
Organization
{{ r.k }} {{ r.v }}
Authorization
{{ r.k }} {{ r.v }}
Primary contact
Primary Report recipient
{{ tv.primaryName }}
{{ tv.primaryEmail }} {{ tv.primaryPhone }}
Escalation path
{{ tv.escalationPath }}
Sites
← {{ sd.tenantName }}
{{ sd.domain }}
{{ sd.tenantName }} · org {{ sd.org }}
{{ sd.statusLabel }}
{{ p.label }}
Per-site dashboard ↗
{{ s.label }}
{{ s.value }}
{{ s.sub }}
{{ sd.panelTitle }} Open in Grafana ↗
Security events by verdict · {{ sd.eventTotal }} in window
No security events for this site in the selected window — quiet is good.
{{ v.label }} {{ v.count }}
Raw Security Events click a row to investigate
Time
Source
Event
Verdict
Investigate
{{ e.time }}
{{ e.src }}
{{ e.title }}
{{ e.meta }}
{{ e.verdict }}
Explore ↗
Scope
Open in Explore ↗
IOC Matches · our assets ↔ known-badrule.groups:misp_ioc_match
Indicator
Type
Seen on · our estate
MISP event
Last seen
Action
{{ m.ioc }}
{{ m.type }}
{{ m.seenLabel }}{{ m.seenDir }}
{{ m.seenSub }}
{{ m.event }}
{{ m.lastSeen }}
Explore
No IOC matches in window — no asset touched a known-bad indicator. ✓
IOC lookup
{{ iocResult.verdict }}{{ iocResult.q }}
{{ iocResult.detail }}
Investigate any IP / domain / hash — threat-intel verdict, attack activity on our estate (events · peak severity · auto-block · IRIS alert), and the suggested action. An IP that attacked us reads SEEN, not CLEAN.
Attacker activity · supporting context
Attack origin map · geolocated source IPs Open in Grafana ↗
No geolocated attacker activity in the selected window — bubbles appear as GeoIP resolves.
Top origin: {{ attackMapTop }}{{ attackNoGeoTxt }} bubble size = hits · colour = containment · live from /api/threat/attackers
Attack flow · source IP → service / port → asset ribbon width = event volume · colour = service/port
External attackers (left) → the port/service they hit (middle) → your affected assets (right) · live from /api/threat/flows
Containment blocked released · 30m timeout detected · not contained LIVE
Global Attacker IPs
Source IP
Country
Activity
Hits
Containment
Action
{{ a.ip }}
{{ a.cc }} {{ a.country }}
{{ a.srcBadgeText }}{{ a.activity }}
{{ a.hits }}
{{ a.verdict }}
{{ atkNoMatchMsg }}
Origin by Country
{{ c.country }}{{ c.count }}
Top MITRE Techniques
{{ t.name }}
{{ t.tactic }}
{{ t.count }}
Network IDS · Suricata {{ idsCard.total }}
{{ idsCard.sub }}
{{ s.name }}{{ s.count }}
Top external talkers
{{ t.ip }}{{ t.meta }}
{{ idsCard.emptyMsg }}
Detection queue · Wazuh alerts
Open in Explore ↗ (deep-dive in SIEM)
{{ alertShowing }}
Rule{{ aIndRule }}
Level{{ aIndLevel }}
Tenant · agent{{ aIndTenant }}
When{{ aIndWhen }}
Action
{{ a.rule }}
rule {{ a.ruleId }} · {{ a.groups }}
L{{ a.level }}
{{ a.tenantName }} · {{ a.agent }}
{{ a.when }}
Explore In IRIS ↗
{{ alertShowing }}
{{ alertPageLabel }}
File-integrity changes · last 24hnewest first · sensitive-path changes in amber
When
Action{{ fimIndAction }}
Path
Tenant · agent
Level{{ fimIndLevel }}
No file-integrity changes match the current filters (last 24h).
{{ f.when }}
{{ f.action }}
{{ f.path }}
{{ f.host }}
L{{ f.level }}
{{ fimShowing }}
{{ fimPageLabel }}
{{ k.label }}
{{ k.value }}
{{ k.sub }}
CVE exposure by tenant · click a tenant to drill into endpoints
Tenant
Critical
High
Medium
Low
Total
{{ t.chevron }}{{ t.tenant }}
{{ t.cCrit.v }}
{{ t.cHigh.v }}
{{ t.cMed.v }}
{{ t.cLow.v }}
{{ t.total }}
{{ e.agent }}
{{ e.cCrit.v }}
{{ e.cHigh.v }}
{{ e.cMed.v }}
{{ e.cLow.v }}
{{ e.total }}
Portfolio concentration · tenant → endpoint · tile size = total CVEs, fill = critical density
critical high medium low
CVE exposure · wazuh-states-vulnerabilitiesCVE dashboard ↗
Package
CVE
CVSS
Fix / remediation
Tenant · agent
{{ v.pkg }}
{{ v.cvss }}
{{ v.fix }}
{{ v.tenantName }} · {{ v.agent }}
{{ vulnShowing }}
{{ k.label }}
{{ k.value }}
{{ k.sub }}
Compliance scorecard · framework pass-rate by tenant click a tenant to scope endpoints + findings · red<50 · amber<80 · green≥80
Tenant
{{ c.label }}
Hosts
Finds
{{ r.tenantName }}
{{ cell.txt }}
{{ r.endpoints }}
{{ r.findings }}
GDPR = process/legal control, not config-scannable (N/A). {{ compMultiNote }}
CIS hardening by endpoint · SCA score vs 70% target Showing: {{ compShowing }}show all
{{ e.host }} · {{ e.tenant }} · {{ e.os }}{{ e.failStr }}{{ e.scoreStr }}
Compliance findings · what's broken · where · how to fix live Wazuh SCA failed checks
Check (what's broken)
Endpoint (where)
Remediation (how to fix)
Frameworks
Raw
{{ f.title }}
{{ f.host }}
{{ f.remediation }}
{{ f.frameworks }}
{{ findingsShowing }}
Live from Wazuh SCA (CIS benchmarks, fleet-wide). Framework scores are real pass-rates of checks tagged to each framework; NIST 800-53 uses direct tags where present plus the CIS→NIST crosswalk. GDPR is a process/legal control not covered by config scanning (N/A). Full raw data in the Grafana 365smg-compliance dashboard.
{{ k.label }}
{{ k.value }}
{{ k.sub }}
Per-tenant SLA · MTTA / MTTR vs contractual target
Tenant
MTTA
Target
MTTR
Status
{{ r.tenantName }}
{{ r.mtta }}
{{ r.target }}
{{ r.mttr }}
{{ r.statusLabel }}
Client-facing PDF reports · white-labeled under 365SMG · availability gated by service plan. Open a report to preview, then print to PDF.
Period June 2026
Client
{{ reportSel.plan }} {{ reportSel.availLabel }}
{{ rep.title }} {{ rep.badge }}
{{ rep.cadence }}
Template in build Requires {{ rep.reqPlan }}
Live data: for the 365smg estate, all six reports render live from Wazuh + IRIS — 30-day detections, CVE state, CIS/SCA scores, MITRE breadth, and real IRIS cases. Metrics with no live feed yet (MTTA/MTTR, edge uptime, IdP account/admin-action counts, change-approval records) are shown honestly as “—” rather than estimated — instrumenting those is the remaining roadmap item (see docs/CLIENT_REPORTS.md).
DFIR-IRIS · alerts pushed from the SOC portal → escalate to cases
{{ caseShowing }}
Ref{{ indRef }}
Severity{{ indSev }}
Title / scope{{ indTitle }}
IRIS object
Investigate
{{ c.ref }}
{{ c.sevLabel }}
{{ c.title }}
{{ c.scope }} · {{ c.created }}
{{ c.objLabel }}
{{ c.objSub }}
Report ↗ Open ↗
{{ caseShowing }}
{{ casePageLabel }}
{{ respGateTitle }}
{{ respGateSub }}
/console reference ↗
{{ k.label }}
{{ k.value }}
{{ k.sub }}
Filter
AUTO → PROPOSE = would auto-contain when armed (near-certain + reversible) · PROPOSE = always needs a human (higher FP) · ♻ Reversible = analyst approve is the 2nd eye · ⚠ Irreversible = needs a named 2nd approver
{{ p.actionIcon }} {{ p.actionLabel }} {{ p.confLabel }} {{ p.revLabel }} {{ p.id }} · {{ p.ago }} ago
{{ p.rule }}
{{ p.tenantName }} · agent {{ p.agent }} ({{ p.host }}){{ p.targetLine }}
{{ p.reason }}
{{ p.caseLinkLabel }}
{{ p.resultText }}
{{ p.gateNote }}
No pending proposals — you're clear. ✓
Currently contained — reverse when triage clears. Each reverse runs through respond() and is audited.
{{ c.kindLabel }}{{ c.host }}
{{ c.tenantName }} · {{ c.detail }}
No active containments. Isolated hosts and quarantined files appear here for one-click reversal.
Automated containment + control-plane actions — the record you can show a client with certainty. Auto-blocked attackers (Wazuh firewall-drop) never create a proposal; they land here as proof they were handled, with a link to the IRIS alert.
Time
Action
Tenant · agent
Requested by
Approved by
Result
Enforce
{{ a.at }}
{{ a.actionLabel }}
{{ a.tenantName }} · {{ a.agent }}
{{ a.requester }}
{{ a.approver }}
No containment actions in the window. Automated firewall-drop blocks, isolations, quarantines, and approvals appear here — real and persisted, not just this session.
Scope
live · updated {{ siemUpdatedAgo }} · auto-refresh 30s
{{ siemHost }}
Open Grafana Explore ↗
{{ h.label }}
{{ h.value }}
{{ h.sub }}
Per-client telemetry · {{ telCount }} tenants · click a row for detail
·{{ siemIndStatus }}
Tenant{{ siemIndName }}
Agents{{ siemIndAgents }}
Alerts{{ siemIndAlerts }}
Critical{{ siemIndCrit }}
Freshness{{ siemIndFresh }}
{{ c.name }}
{{ c.agents }}
{{ c.alerts }} {{ c.trendLabel }}
{{ c.critical }}
{{ c.fresh }}
{{ c.chevron }}
Agents
{{ c.agents }}
{{ c.discNote }}
Alerts
{{ c.alerts }}
this window
Critical
{{ c.critical }}
L≥12
Top rule{{ c.topRule }}
Ingest freshness{{ c.fresh }}
Perimeter firewall & IDS · last 24h Open firewall dashboard ↗
{{ fwKpi.blocks }}
Blocks
{{ fwKpi.uniqueSrc }}
Unique blocked src IPs
{{ fwKpi.topPort }}
Top denied port
{{ fwKpi.idsAlerts }}
IDS/IPS alerts
Platform datasources · isolation-enforced shared stack · per-tenant isolation at the datasource
{{ d.name }}
{{ d.healthLabel }}
{{ d.detail }}
{{ d.iso }}
Showing 365 SMG SOC-wide dashboards — pick a tenant in Scope above to see that client's.
Grafana dashboards · {{ launcherCount }} deep-link · Cloudflare Access authenticates you · opens in Grafana ↗
{{ k.label }}
{{ k.value }}
{{ k.sub }}
Plan catalog · entitlements
{{ p.label }}{{ p.price }}/mo
{{ p.limitsLine }}
{{ ft.sym }}{{ ft.label }}
Tenant subscriptions · usage vs. plan · synced from Zoho
Open Zoho Billing ↗
Tenant
Plan
Usage vs. limits
Invoice
MRR
Actions
{{ b.name }}
{{ b.zohoId }}
{{ b.plan }}
{{ b.addonLine }}
{{ m.label }}{{ m.text }}
{{ b.invLabel }}
auto-suspend pending
{{ b.mrr }}
Zoho ↗
Total MRR
{{ totalMrr }}
Zoho is the billing system of record & customer-facing surface (hosted invoices + client portal). This screen is internal control/visibility only — no card data is handled here. Enforcement: UI upsell → orchestrator gate → provisioning limits → auto-suspend on non-payment. See docs/BILLING_ENTITLEMENTS.md.
!{{ respConfirm.title }}
{{ respConfirm.body }}
Auto-response posture
Per tenant · per action class. Contain = quarantine/kill (reversible). Isolate = cut host off the network (disruptive). Master OFF = everything OBSERVE regardless.
Global master switch
Emergency kill-switch — while OFF, no tenant auto-contains.
TenantContainIsolate
{{ t.name }}
On-demand mitigation
POST /ui/respond → respond() gatekeeper (RBAC · tenant scope · four-eyes · audit)
Action
{{ a.icon }}
{{ a.label }}
{{ respActionDesc }} · destructive — four-eyes required
Runs as {{ analystUser }} ({{ analystRole }}) over the reliable manager→agent SSH path. Reversible action; appended to the audit log + IRIS.
Manage subscription · {{ manage.name }}
Pushes to Zoho {{ manage.zohoId }} — PUT /subscriptions (plan) + add-on line items
Plan
{{ p.label }}
{{ p.price }}/mo
Extra services (add-ons)
{{ a.check }}{{ a.label }}
{{ a.price }}
New MRR {{ manage.newMrr }}
Escalate to DFIR-IRIS
Manual escalation for sub-threshold / out-of-band items SOAR didn't auto-forward. High-confidence detections (L≥12 · MISP) are already in IRIS — no manual step needed.
{{ toast }}
{{ n.tierLabel }} ×
{{ n.title }}
{{ n.sub }}
dismiss all
SOC Operations Manual Read-only
Runbooks & references · {{ manualCount }} docs · ▦ opens here · ↗ opens in repo
{{ docViewName }}
{{ docViewPath }}
Read-only
{{ reportTitle }} {{ reportTenantName }}
Send report to client
Deliver {{ sendReportTitle }} for {{ sendTenantName }} to the primary contact:
{{ sendName }}
{{ sendTo }}
A branded PDF is rendered server-side and emailed. The send is logged to the audit trail. (mock — TODO: integrate report delivery)
Edit client profile
Primary contact (intake.contacts · report recipient)
Tenant (intake.tenant)
Also renames the tenant's Grafana org to match. The slug (identity key) never changes.
Authorization
Delete / offboard tenant
This queues offboarding for {{ deleteName }}: revoke its Grafana org, remove the Wazuh agent group + OpenSearch DLS, and archive the client registry. This is destructive and cannot be undone from here.