Get started

Security Operations Centre · a free marketplace plugin

Free in the marketplaceAnchored on Wazuh SIEM · $25

The security desk inside QuoxCORE. Nothing overstated.

It is the security operations surface inside QuoxCORE: live Wazuh posture, a threat feed with real severities, one-click security actions and the WARDEN agent in the sidebar. The Wazuh plugin that feeds it real alerts is a separate one-time $25 purchase. It is earlier-stage than our NOC, and this page says exactly what ships today and what does not.

Shipping plugins 1Actions live 5 of 8Chat lanes 3 agentsSecOps team 5 agents

In plain words

What it is, where it lives, when to reach for it

What is it
A free plugin for the QuoxCORE dashboard: a security operations view built on the Wazuh SIEM plugin.
Where do I use it
On the SOC view in your dashboard; real alerts appear once a Wazuh manager is configured.
When would I use it
When you want one screen for security posture, the threat feed and the SecOps agent team.
How do I use it
Add it free from the store; real alerts need the separate $25 Wazuh plugin pointed at your Wazuh manager.

QuoxCORE is the free, self-hosted platform underneath this. What is QuoxCORE

QuoxCORE · SOC view recreation · example data
SOC Wazuh live7/9 agents0 alerts
Security posture78%
7Active1Disconnected9Total0Hi/crit alerts
Threat feed
Security actions
T Threat scanF FirewallA Auth logs! IncidentsC CVE searchI IDS SoonV Vuln SoonB Baseline Soon
posture → feed → action → approvala recreation of the SOC view · example data, not a live feed

What ships today

The honest ledger

The SOC view is free in the marketplace: you add it, and an admin installs it from your dashboard. No checkout, no licence key.

One security plugin is buyable today. The rest of the suite is roadmap, and the view itself says so with a lock, not a promise.

Shipping now
SOC viewthe three-column security surface in QuoxCOREin the dashboard
Wazuh SIEM pluginlog analysis, threat detection, agent management$25 · see the plugin
WARDENthe security operations agentcore agent
SecOps teamWARDEN plus four specialists, governed by policyincluded
Roadmap · not for sale yet
IDS / Suricataintrusion detection and network traffic analysiscoming soon
Vulnerability scannerOpenVAS / Nessus vulnerability scanningcoming soon
SOARsecurity orchestration and automated responsecoming soon
This ledger mirrors the SOC view itself: the three roadmap entries render as locked cards in the product, and three of the eight security actions stay disabled until their backends exist. When they ship, they will appear here with a price. Not before.

The SOC is younger than the NOC. Where the NOC can point at a shelf of shipping integrations, this surface points at Wazuh and stops. We would rather show you one honest anchor than a catalogue of placeholders.

The agent

WARDEN watches the feed

WARDEN is the security operations agent in the sidebar of the SOC view. Calm, measured, precise. It reads the live posture and the priority threats as context, so when you ask about auth failures it already knows which agents are disconnected and which alerts are high severity.

Its safety configuration is explicit. Scans, log analysis and status checks run without ceremony. Firewall rule changes, security policy modifications and user access changes require human approval. It never exposes credentials in a response, and it escalates critical findings to the orchestrator.

  • Page context injected: posture summary plus priority threat evidence
  • Two more lanes in the same sidebar: CIPHER for encryption and PKI, CODEX for code security
  • Actions log to the audit trail, per its own standing rules
agent profile · sentinel
IDENTITY
  name        WARDEN
  role        security operations · manager
  reports to  QUOX (orchestrator)
  tone        calm, measured, precise

AUTO-APPROVED
  security scans · log analysis · status checks

REQUIRES APPROVAL
  
  
  

NEVER
  expose credentials in responses
  disable security features without approval

ESCALATES ON  critical breach · compliance violation

The team

Five agents, one approval gate

The SecOps team ships with the platform: WARDEN orchestrates four specialists. Team runs do not start without approval, and every task checkpoint leaves evidence.

WARDENorchestrator · threat assessment · incident triageCIPHERnetwork security · firewall audit · TLS/SSL · DNSNETWATCHnetwork monitoring · traffic analysis · intrusion detectionHYPERIONinfrastructure audit · host hardening · Proxmox securityQUOXCODEcode review · dependency audit · CVE scanning
approval before startcheckpoint after each taskVOLT evidence required200k token budget80 tool-call cap

Security actions

Eight actions, five live

Each action is a one-click security task: it goes through a confirmation modal, then WARDEN runs it and the result lands in the panel. The three that need backends we have not shipped stay disabled, and say so in the interface.

T Threat scan across monitored systems F Firewall status and anomalies A Auth log analysis ! Open incidents and active alerts C CVE search for your stack I IDS alerts needs Suricata/SnortV Vulnerability scan needs scanner backendB Baseline check needs baseline config

Disabled means disabled: the interface shows the same three greyed-out actions until the backends exist. No button on this surface pretends.

The anchor

Wazuh is the part you can buy

Everything live on the SOC view flows from one place: the Wazuh SIEM plugin. It supplies the manager health, the agent counts behind the posture score, and the alert stream behind the threat feed, with severities mapped straight from Wazuh rule levels.

The plugin is a governed connector to a Wazuh v4.x server you run yourself: alert triage, fleet agent deployment over bastion SSH, vulnerability and compliance checks, with destructive actions gated behind approval.

  • Refreshes every 60 seconds while the view is open
  • No Wazuh connected: the view says so, rather than showing fake numbers
  • Alert severity mapped from rule level, critical at 12 and above

Wazuh SIEM · plugin

One payment, licence key unlock

The single shipping plugin behind this surface. Pay once in the store, enter the key in your dashboard, connect your Wazuh server.

How you get it

Free in the marketplace, and it stays free

SOC is a free plugin you add from the store. What it watches over is the part you scale.

store

On its own

The security operations centre for your own QuoxCORE instance: alert triage, incident timelines and the evidence trail behind every action an agent takes on your estate. Add it from the marketplace and an admin installs it from the dashboard: no checkout, no licence key, no seat count.

free · in the store
wazuh

Feed it real detections

SOC is the console. Wazuh SIEM is the detection engine that fills it: agent-based intrusion detection, log analysis and file integrity monitoring across your hosts.

sold separately