24/7 monitoring of security events across all infrastructure agents, with automatic correlation and prioritization by risk level and MITRE severity.
Every critical alert is analyzed by the integrated AI engine to identify the MITRE tactic, potential impact and recommended remediation actions with full context.
Native automation layer with specialized endpoints: real-time Telegram alerts, automatic daily reports, spike detection, playbook generation and multi-level escalation chains.
Automatic creation of enriched tickets in osTicket, Jira Service Management or ServiceNow. Every incident is documented, assigned and traceable with full AI analysis.
Instant generation of response playbooks for active incidents. The AI engine produces actionable containment, investigation and documentation guides tailored to the detected threat.
Real-time dashboard with operational metrics, SSE event feed, risk indicators and automatic reports for regulatory compliance audits.
Perimeter traffic aggregated by the minute: allowed and blocked sessions, bandwidth split by upload and download, destination countries and applications in use — without storing the raw logs.
Who connects over VPN, from which country and with which assigned address. Rejected attempts are logged with their origin, and access granted after repeated failures raises an immediate alert and opens a ticket.
Security sources — agents on servers and endpoints, OpenSearch indexers, external SIEMs and cloud logs — send events to the Normalizer. Supports multiple protocols: REST API, syslog, webhooks and direct OpenSearch queries.
The Normalizer converts heterogeneous events to the OBSIDIA standard format (rule · agent · mitre · level · dedup · state · fingerprint). The Poller Engine deduplicates by SHA-256 fingerprint and maintains state per 20-second cycle. Each adapter is independent.
Alerts with level ≥ 7 (configurable per plan) are processed by the integrated AI engine. It identifies the MITRE ATT&CK tactic and technique, the corresponding Kill Chain phase, the potential impact and generates actionable remediation recommendations with full context.
The Dispatcher builds a ticket with a structured subject (severity · rule · agent) and an enriched body including: event data, full AI analysis, MITRE context and remediation steps. Supports osTicket, Jira Service Management and ServiceNow.
The n8n layer consumes API endpoints to trigger real-time Telegram alerts, detect volume spikes, verify SLA, monitor agent availability and generate response playbooks. Multi-level escalation chains (tier1 → tier2 → tier3) progressively notify based on configurable response time.
Every event is recorded in the Event Store (PostgreSQL). The SSE Dashboard transmits it in real time to the SOC team. The analyst can mark alerts as False Positive, Acknowledged or Resolved directly from the monitor — the action is recorded and automatically closes the ticket in the integrated ITSM system.
The AI engine receives full incident context: triggered rule, affected agent, MITRE tactic, severity and related events in the time window. No client data exposed in shared environments.
Containment steps specific to the detected threat: network isolation, session revocation, process or account blocking. Ordered by minimum operational impact.
Forensic investigation guide: artifacts to collect, logs to review, recommended tools and key questions to determine the actual scope of the incident.
Incident documentation structure, closure criteria, post-incident remediation actions and control improvement recommendations to prevent recurrence.
| Type | Starter | Pro | Enterprise |
|---|---|---|---|
| 🛡️ Firewalls / routers | ≤ 3 | 4 – 10 | ∞ |
| 💻 Endpoints + servers | ≤ 99 | 100 – 999 | ∞ |
| 🔒 WAF / databases | ≤ 1 each | Included | ∞ |
| ☁️ O365 tenants | ≤ 1 | Included | ∞ |