Security Intelligence Platform
All Tenants cybowatch-alerts-*
Live
A
Admin
Active
Agents
-
Online
Disconnected
Agents
-
Offline
Critical
Severity
-
Rule Level 15+
High
Severity
-
Rule Level 12-14
Medium
Severity
-
Rule Level 7-11
Low
Severity
-
Rule Level 0-6
Total File
Added
-
Total File
Deleted
-
Total File
Modified
-

Events Per Sec

Current
0
Average
0
Peak
0
Total
0
Active: 0 Critical: 0 High: 0 Countries: 0
ENDPOINT SECURITY
Configuration Assessment
Scan your assets as part of a configuration assessment audit.
Malware Detection
Check indicators of compromise triggered by malware infections or cyberattacks.
File Integrity Monitoring
Alerts related to file changes, including permissions, content, ownership, and attributes.
THREAT INTELLIGENCE
Threat Hunting
Browse through your security alerts, identifying issues and threats.
Vulnerability Detection
Discover what applications in your environment are affected by well-known vulnerabilities.
MITRE ATT&CK
Explore security alerts mapped to adversary tactics and techniques for better threat understanding.
Fields
Selected fields
T
_source
Available fields
T
@timestamp
T
agent.id
T
agent.ip
T
agent.labels.group
T
agent.name
T
data.action
T
data.cybowatch.ioc
T
data.cybowatch.severity
#
data.cybowatch.score
T
data.dst_country
T
data.dst_ip
T
data.fw_rule_name
T
data.protocol
T
data.severity
T
data.src_ip
T
manager.name
T
rule.description
#
rule.level
T
rule.id
T
rule.groups
T
syslog_relay_host
T
data.win.system.eventID
T
data.win.system.channel
DQL
Showing - hits
Loading...
Time
_source
Loading...
No agent is selected
Dashboard
Events
Time:
Agent:
Level:
Total Events
-
LOW EVENTS
Medium Events
High Events
Critical Events
Agents evolution
Events by rule group
Top 10 agents by rule group
Rule description
rule.descriptionCount

File Integrity Monitoring

Selected Endpoint: All Agents
-
Files Added
-
Files Modified
-
Files Deleted
-
Total Events

Alerts by action over time

modified deleted added

Top 5 agents

Events summary

Rule distribution

Actions

Top 5 users

UserAgent IDAgent nameCount

No agent is selected

Select an endpoint to view file integrity inventory details

FIM Events Detail

0 hits
timestamp agent.name syscheck.path syscheck.event rule.description rule.level rule.id

Select Endpoint

Dashboard
Events
-
- Total -
-
- Level 12 or above alerts -
-
- Authentication failure -
-
- Authentication success -
Top 10 Alert level evolution
Top 10 MITRE ATT&CKS
Top 5 agents
Alerts evolution - Top 5 agents
TIME:
AGENT:
SEVERITY:
Total IOCs Checked
-
Unique IPs (IOC)
-
MEDIUM Threats
-
HIGH Threats
-
Critical Threats
-
IOC Detection Timeline (Last 24 Hours) rule.groups: cybowatch
Top 10 IOCs (IP Addresses)
IOC (IP Address) Score Hits
Severity Distribution data.cybowatch.severity
CRITICAL
0%
HIGH
0%
MEDIUM
0%
LOW
0%
Top Countries data.cybowatch.country
CountryCityEvents
Top ISPs data.cybowatch.isp
ISP NameEventsASN
Usage Types data.cybowatch.usage_type
Time Range:
Agent:
Severity:
Status:
Dashboard
Inventory
Events
-
Critical - Severity
-
High - Severity
-
Medium - Severity
-
Low - Severity
-
Pending - Evaluation
Top 5 Vulnerabilities Count
Top 5 OS Count /span>
Top 5 Agents Count
Top 5 Packages Count
Most common vulnerability score
Vulnerability Base Score
Most vulnerable OS families
Vulnerabilities by year of publication
0
Critical
0
High
0
Medium
0
Low
Dashboard
Intelligence
Framework
Events
Total Alerts
-
Tactics Detected
-
Techniques Used
-
Affected Agents
-
Alerts evolution over time
Top tactics
Attacks by technique
Top tactics by agent
MITRE techniques by agent
Operating system families Count
Package types
Top 5 endpoints by memory
Top 5 installed packages Count
Top 5 running processes Count
Top 5 operating systems Count
Top 5 host CPUs Count
Top 5 destination ports
Top 5 source ports
Process start times
Time:
Agent:
Level:
Total Events
-
Requirements Distribution
Events
TimeAgentDescriptionRequirementsLevel
Time:
Agent:
Level:
Total Events
-
Article Coverage
Events
TimeAgentDescriptionRequirementsLevel
Time:
Agent:
Level:
Total Events
-
Standard Coverage
Events
TimeAgentDescriptionRequirementsLevel
Time:
Agent:
Level:
Total Events
-
Control Families
Events
TimeAgentDescriptionRequirementsLevel
Time:
Agent:
Level:
Total Events
-
Criteria Coverage
Events
TimeAgentDescriptionRequirementsLevel
Time:
Agent:
Level:
Total Events
-
Event Distribution
Events
TimeAgentDescriptionGroupsLevelRule
Time:
Agent:
Level:
Total Events
-
Event Distribution
Events
TimeAgentDescriptionGroupsLevelRule
Time:
Agent:
Level:
Total Events
-
Event Distribution
Events
TimeAgentDescriptionGroupsLevelRule
Time:
Agent:
Level:
Total Events
-
Event Distribution
Events
TimeAgentDescriptionGroupsLevelRule
Time:
Agent:
Level:
Total Events
-
Event Distribution
Events
TimeAgentDescriptionGroupsLevelRule
Time:
Agent:
Level:
Total Events
-
Event Distribution
Events
TimeAgentDescriptionGroupsLevelRule
AGENTS BY STATUS
TOP 5 OS
TOP 5 GROUPS
Agents
IDNameIP AddressGroup(s)Operating System Cluster NodeLast Keep AliveStatus
Agent Groups
GroupAgentsConfiguration
nieRsyslog, sfwSYNCED
defaultLAPTOP-6Q2MMRG2SYNCED
All Users Passwords are never shown - Stored as SHA-256 hashes on server
Username Display Name Role Tenants / Index Access Created Actions
Loading users...
Report Configuration
Daily
Last 24h
Weekly
Last 7 days
Monthly
Last 30 days
Loading customers...
Report Preview
Generate a report to preview it here

No Report Generated

Select a customer and period on the left, then click Generate Report to preview it here.

Fetching live data from CyboWatch...

Connecting to backend
Generated Reports View and manage previously generated reports
Report Title Customer Period Generated By Date Status Actions
No saved reports found.
Send Report to Client
This will email the PDF directly to the client
Customer
Period
Send To
Report File

License Management

CyboWatch
Loading
LICENSE KEY
.... .... .... ....
VALID FROM
--
VALID THRU
--
LICENSED TO
--
Days remaining --

Need to renew or have questions about your license? Contact CyboWatch support.