Name | Description |
---|---|
Global configuration | Global and remote settings |
Cluster | Master node configuration |
Registration service | Automatic agent registration service |
Name | Description |
---|---|
Global configuration | Logging settings that apply to the agent |
Communication | Settings related to the connection with the manager |
Anti-flooding settings | Agent bucket parameters to avoid event flooding |
Labels | User-defined information about the agent included in alerts |
Name | Description |
---|---|
Alerts | Settings related to the alerts and their format |
Integrations | Slack, VirusTotal and PagerDuty integrations with external APIs |
Name | Description |
---|---|
Policy monitoring | Configuration to ensure compliance with security policies, standards and hardening guides |
OpenSCAP | Configuration assessment and automation of compliance monitoring using SCAP checks |
CIS-CAT | Configuration assessment using CIS scanner and SCAP checks |
Name | Description |
---|---|
Vulnerabilities | Discover what applications are affected by well-known vulnerabilities |
Osquery | Expose an operating system as a high-performance relational database |
Inventory data | Gather relevant information about system OS, hardware, networking and packages |
Active response | Active threat addressing by inmmediate response |
Active response | Active threat addressing by inmmediate response |
Commands | Configuration options of the Command wodle |
Docker listener | Monitor and collect the activity from Docker containers such as creation, running, starting, stopping or pausing events |
Name | Description |
---|---|
Log collection | Log analysis from text files, Windows events or syslog outputs |
Integrity monitoring | Identify changes in content, permissions, ownership, and attributes of files |
Agentless | Run integrity checks on devices such as routers, firewalls and switches |
Name | Description |
---|---|
Amazon S3 | Security events related to Amazon AWS services, collected directly via AWS API |