Getting Started
After signing in, select your server and start from the Dashboard. Follow this sequence to efficiently navigate the platform.
Dashboard
Your security command centre — view system health, threat state, latest scans and suggested actions.
System Health
CPU, memory, disk, swap, load, uptime – at a glance.
Threat State
Analyst‑interpreted process behaviour classification.
Latest Scans
Audit, vulnerability and malware scan timestamps & results.
Suggested Actions
High‑priority recommendations to improve security.
Use it when: Starting your daily review or checking overall server health.
Global Attack Map
Live geographic overview of detected attacks against your server.
Attack Locations
Unique mapped source countries / cities.
Total Attempts
Detected attempts in the selected time window.
Blocked / Active
Green = blocked, Red = active threat.
Use it when: You want a quick visual of attack sources before diving into logs.
Security Incidents
Correlated security events with severity, MITRE mapping, and response workflows.
Critical / High
Priority incidents requiring immediate review.
Categories
Network, Web Attack, Malware, etc.
Playbooks
Attach and run SOAR playbooks directly from the incident.
Use it when: An alert requires investigation or a documented response.
Always review evidence before executing any automated response.
Threat Intelligence
Active IOCs (Indicators of Compromise) and matches against your server’s event history.
Active IOCs
Enabled indicators by the security team.
Server Matches
IOC IPs observed in AttackLogs.
Filtering
Search by value, type, severity, source, match status.
Use it when: You need to check if a known malicious indicator has appeared on your server.
Security Logs
Raw security‑related events collected by the agent – the foundation for any investigation.
Use it when: You need the raw event context behind an alert or incident (e.g. SSH auth attempts, web requests).
Network Monitoring
Real‑time interface health, bandwidth, latency, packet loss, and active connections.
Upload / Download
Current speed and total transferred.
Latency & Packet Loss
Response time and delivery stability.
Connections
Established (TCP/UDP) and listening sockets.
Use it when: Investigating network performance, connectivity issues, or unusual traffic patterns.
Forensics & Attack Provenance
Read‑only workspace to investigate processes, network activity, and file paths.
Timeline Events
Unified view of incidents, threats, evidence, and SOAR tasks.
PID Investigator
Collect process identity, parent chain, children, open files, sockets, hashes.
Path Investigator
Bounded metadata + SHA‑256 scan (file contents are never uploaded).
Use it when: You need deep visibility into a suspicious process or file – without destructive actions.
Audit Log
Security‑oriented system audit view – baseline configuration and compliance checks.
Use it when: Performing a baseline review or checking system security posture before onboarding.
Vulnerability Scan
Results from vulnerability scanning – known issues in installed packages.
Use it when: Checking if installed software has known security issues that need patching.
Malware / Virus Scan
Malware detection findings with a false‑positive safety policy.
Detection
Files, processes, or scripts flagged by scanners.
False‑positive handling
Previous FP decisions are reused only if SHA‑256, scanner, rule & version match.
Actions
Quarantine, restore, or mark as false positive (with evidence).
Use it when: You suspect a malicious file or want to review scan findings.
Active Response
Evidence‑backed suspicious or malicious processes and services – with safety checks.
- Only suspicious processes are shown; normal Linux processes are hidden.
- Before termination, agent re‑validates PID, create time, name, executable.
- Protected OS and Miku services cannot be stopped.
Use it when: You have confirmed a malicious process and need to stop it immediately.
SOAR Console
Playbook approval, execution tracking, and agent task queue.
Total Executions
Track all playbook runs.
Status
Awaiting Approval, Success, Failed, etc.
Approval Required
High‑risk actions need explicit approval before execution.
Use it when: An incident has a defined response and you need to approve or track automated actions.
Resource Usage
CPU, memory, disk, swap, load, and uptime with historical trends.
Use it when: Server is slow, a scan is consuming high CPU, or you need capacity planning.