Alerts

Low
Medium
High

MITRE ATT&CK Map

LIVE ATTACK ONGOING
No live attacks to show.
Windows 11 Home
Windows PC Win11
show details>
No attacker detected on this machine yet
Ubuntu 20.04.06
Ubuntu Server Ubuntu
show details>

Generate Incident Report

Incident ID Summary SEVERITY TIME/DATE MITRE ATTACK GENERATE REPORT
No incidents yet.
ClaudeWazuh

ClaudeWazuh

Your automated SOC analyst. Ask me about current alerts, threats, or security posture.

ARIA is thinking...
Use tool: :wazuh :m365
GPT-4o ✦

Microsoft 365 Dashboard

Entra ID
Exchange
OneDrive / SharePoint
⚠ Alert Logs
Searching

Sign-In Logs

TimeUserIP AddressLocationStatusMFA ResultAppDevice OS
Click Load All to fetch data.

MFA / Security Info Changes

TimeEventTarget UserInitiated ByResultIP
Click Load All to fetch data.

Account Actions (Disable / Enable / Password Reset)

TimeActionTarget UserInitiated ByResult
Click Load All to fetch data.

Registered MFA Methods

Method TypeDevice / DetailRegistered
Click Load All to fetch data.
Searching

External & Suspicious Emails (BEC keyword match highlighted)

TimeMailboxFromSubjectReadAttachmentFlag
Click Load All to fetch data.

Inbox Rules

UserRule NameEnabledForward ToDeletes MailMove To Folder
Click Load All to fetch data.

Mailbox Forwarding

UserSMTP ForwardingAuto-Reply
Click Load All to fetch data.
Searching

OneDrive File Activity

TimeActionFile / ResourceIP
Select a user and click Refresh.

OAuth App Grants

App NameScopesConsent Type
Select a user and click Refresh.
Scanning API
Ready

Sign-In Alert Log (auto-classified from sign-in data)

Detected Severity Alert Type User IP Location Status Flags
Loading…