Skip to content

Security Operations

The Security module (license-gated) centralizes SOC workflows: real-time alerts, investigation tools, MITRE heatmaps, playbooks, and compliance tracking.

Requires module.security on the tenant license.

RoutePurpose
/securityOverview metrics
/security/alertsAlert inbox (live updates)
/security/investigateTooling workspace
/security/scannersScanner configuration
/security/complianceFramework posture
/security/threat-intelIndicators and feeds
/security/playbooksResponse playbooks

Alerts may arrive via edge ingest, webhooks (Defender, Wazuh, CrowdStrike), or manual creation.

security.read plus fine-grained security.tool.* for ping, nmap, ssh, etc.