| Name | Description |
|---|---|
| Global configuration | Global and remote settings |
| Cluster | Master node configuration |
| Registration service | Automatic agent registration service |
| Name | Description |
|---|---|
| Global configuration | Logging settings that apply to the agent |
| Communication | Settings related to the connection with the manager |
| Anti-flooding settings | Agent bucket parameters to avoid event flooding |
| Labels | User-defined information about the agent included in alerts |
| Name | Description |
|---|---|
| Alerts | Settings related to the alerts and their format |
| Integrations | Slack, VirusTotal and PagerDuty integrations with external APIs |
| Name | Description |
|---|---|
| Policy monitoring | Configuration to ensure compliance with security policies, standards and hardening guides |
| OpenSCAP | Configuration assessment and automation of compliance monitoring using SCAP checks |
| CIS-CAT | Configuration assessment using CIS scanner and SCAP checks |
| Name | Description |
|---|---|
| Vulnerabilities | Discover what applications are affected by well-known vulnerabilities |
| Osquery | Expose an operating system as a high-performance relational database |
| Inventory data | Gather relevant information about system OS, hardware, networking and packages |
| Active response | Active threat addressing by inmmediate response |
| Active response | Active threat addressing by inmmediate response |
| Commands | Configuration options of the Command wodle |
| Docker listener | Monitor and collect the activity from Docker containers such as creation, running, starting, stopping or pausing events |
| Name | Description |
|---|---|
| Log collection | Log analysis from text files, Windows events or syslog outputs |
| Integrity monitoring | Identify changes in content, permissions, ownership, and attributes of files |
| Agentless | Run integrity checks on devices such as routers, firewalls and switches |
| Name | Description |
|---|---|
| Amazon S3 | Security events related to Amazon AWS services, collected directly via AWS API |