Intrusion Detection
Cloudaware Intrusion Detection integrates a host-based IDS (Wazuh) with Cloudaware CMDB and Breeze Agent to provide endpoint-level threat detection, audit logging, and security telemetry for cloud and on‑prem workloads.
- Audience: Security operations, cloud and security engineers, compliance owners
- Outcome: Endpoint monitoring with IDS status visible in CMDB, prioritized alerts and dashboards for incident response, and audit-ready evidence for compliance requirements such as PCI DSS, HIPAA, and SOC 2
Use Cloudaware Intrusion Detection when you want to:
- Detect suspicious activity and signs of compromise on servers and endpoints.
- Monitor privileged access and security-relevant operating system events.
- Identify changes to sensitive files, directories, configurations, and Windows registry entries.
- Correlate events with applications, environments, owners, and infrastructure context.
- Route high-priority findings to incident, ticketing, notification, or response workflows.
- Demonstrate host-monitoring coverage and retain evidence for compliance reviews.
- Standardize investigation and response procedures across cloud and on-premises workloads.
Core Capabilities
Cloudaware Intrusion Detection provides:
- File integrity monitoring (FIM) – changes to monitored files, directories, and supported Windows registry locations detected and recorded.
- Security event monitoring – authentication events, privilege activity, system events, and other supported host telemetry evaluated for suspicious behavior.
- Rootkit and malware detection – supported indicators and host checks used to identify potential compromise.
- Custom detection rules – Wazuh rules and decoders configured or extended to address organization-specific detection requirements.
- CMDB-based enrichment – findings associated with hosts, applications, environments, owners, accounts, and related infrastructure context.
- Risk-based prioritization – severity, detection logic, asset context, and operational importance used to support triage.
- Agent and coverage visibility – IDS registration and monitoring status available for supported hosts in CMDB and reporting views.
- Incident routing – alerts connected to Watchers, notifications, tickets, incidents, and other supported response workflows.
- Dashboards and investigation – searches, filters, dashboards, timelines, and reports used for triage and analysis.
- Compliance evidence – event history, file integrity data, agent coverage, findings, and reports retained for control reviews and audits.
How Intrusion Detection Works
Cloudaware Intrusion Detection follows a telemetry-to-response workflow:
- Identifies monitored hosts. Cloudaware CMDB provides server inventory, ownership, application, environment, and relationship context.
- Deploys and registers agents. Breeze Agent supports deployment and registration of the required Wazuh components on eligible hosts.
- Collects security telemetry. Wazuh agents collect supported operating system events, file integrity data, authentication activity, malware and rootkit indicators, and other host security signals.
- Evaluates rules. Wazuh rules analyze incoming telemetry and generate alerts when events match configured detection logic.
- Adds CMDB context. Cloudaware associates IDS status and findings with the affected host, owner, application, environment, account, and related infrastructure where available.
- Surfaces findings. Security teams review findings through Wazuh dashboards, searches, filters, CMDB records, and Cloudaware reporting views.
- Routes response workflows. Alerts and findings can trigger notifications, incidents, tickets, Watchers, and configured follow-up actions.
- Supports investigation and evidence. Event history, findings, agent status, dashboards, and reports provide context for incident response, control validation, and audits.
Intrusion Detection Data and Visibility
Intrusion Detection data is available through both Wazuh and Cloudaware views.
Wazuh
The Wazuh application is available in Cloudaware Control Hub (Launcher). Use Wazuh to:
- Search detailed security events.
- Review rule matches and alert details.
- Filter events by agent, host, rule, severity, or time range.
- Configure Watchers and alert conditions.
- Investigate event sequences and supporting telemetry.
See Navigation in Wazuh and Dashboards & Reporting.
Cloudaware CMDB
Use Cloudaware CMDB to:
- Review IDS status for supported hosts.
- Relate monitored endpoints to applications, environments, owners, and accounts.
- Build list views and reports to identify hosts without expected IDS coverage.
- Correlate findings with other CMDB and Cloudaware module data.
Advanced Analytics
Use Cloudaware Advanced Analytics to build IDS coverage dashboards.
Relationship to Other Modules and Services
Intrusion Detection works with other Cloudaware capabilities throughout the monitoring and response lifecycle:
- Cloudaware CMDB provides host inventory, ownership, application, environment, and relationship context.
- Breeze Agent supports agent deployment, registration, telemetry collection, and host-level execution.
- Change Management can provide approval and audit context for remediation actions.
- ITSM and notification integrations can route findings to tickets, incidents, collaboration channels, and response teams.
Explore the Intrusion Detection Documentation
Use these guides together as the Cloudaware Intrusion Detection documentation set.
Prepare Intrusion Detection
-
Review requirements. Confirm prerequisites for agents, network access, permissions, integrations, and operational readiness.
-
Review the architecture. Understand the Cloudaware-managed Wazuh deployment model, components, CMDB relationships, and data flow.
-
Review sources and agents. Learn how Breeze Agent, Wazuh agents, hosts, and CMDB assets provide IDS telemetry.
Configure Detection and Alerting
- Findings & Rules: Understand rule evaluation, finding normalization, severity, and tuning.
- Navigation in Wazuh: Find dashboards, searches, filters, and Watcher controls.
- Wazuh Alerts & Watchers: Configure incidents, tickets, notifications, and alert workflows.
Investigate and Report
- Dashboards & Reporting: Use Wazuh dashboards, CMDB views, KPIs, investigations, and compliance reports.
- Playbooks: Follow workflows for incident response, privileged activity review, drift investigation, and coverage validation.
Operate Intrusion Detection
- Operations: Manage agent health, triage, maintenance, access control, and recurring IDS operations.
- Reference: Review Wazuh version details, ports, protocols, and supported signals.