Wazuh SIEM · plugin for QuoxCORE
Security monitoring, without the headaches.
A governed connector to the Wazuh security platform. Every response is scoped, approved where it matters, and witnessed on WARD.
In plain words
What it is, where it lives, when to reach for it
- What is it
- A plugin for the QuoxCORE dashboard that connects to the Wazuh SIEM you already run: agents, alerts, posture.
- Where do I use it
- On the Wazuh view in your dashboard, reading your own Wazuh manager and indexer.
- When would I use it
- When you want security alerts and agent status in the same dashboard your fleet already reports to.
- How do I use it
- Buy it once in the store for $25, then an org admin installs it and points it at your Wazuh manager.
QuoxCORE is the free, self-hosted platform underneath this. What is QuoxCORE
What it does
One plugin, the whole security desk
Agents triage the alert feed, deploy Wazuh agents across your fleet through the bastion, scan for vulnerabilities and check compliance.
How it installs: pay once, get a licence key, enter it in your QuoxCORE dashboard. The Wazuh panel appears. Nothing to download, nothing to redeploy.
Ten AEE intents cover the full SIEM surface: alerts, agents, vulnerabilities, file integrity, compliance and response. Destructive actions go through the safety system.
Fleet agent setup
Deploy Wazuh agents to any host via bastion SSH. No manual installation. Bulk deploy to the whole fleet.
Alert feed
Security alerts with severity classification and MITRE ATT&CK mapping, in a dedicated panel tab.
Vulnerability scanner
CVE detection per host with severity, affected packages and remediation guidance.
File integrity
Track file changes across your fleet on a timeline. Detect tampering and unauthorised modifications.
Compliance
CIS benchmarks, PCI-DSS, HIPAA and GDPR checks with pass and fail scoring per host.
AI triage
CommanderQ analyses alert patterns, filters noise from your environment and prioritises what needs attention.
Active response
Block IPs, kill processes, isolate hosts. Every response goes through the approval flow first.
MITRE ATT&CK
Every alert mapped to tactics and techniques, so you see attack patterns rather than isolated events.
Fleet coverage
See which hosts have agents and which do not. Spot the gaps in your security perimeter.
Audit trail
Every action logged with AEE envelopes. A full record of who did what, when and where.
Seven tabs
Full visibility, one panel
The plugin adds a dedicated Wazuh panel to QuoxCORE with seven tabs, from manager health to compliance posture. Manager health tracks five critical daemons:wazuh-db, wazuh-modulesd, wazuh-analysisd,wazuh-remoted and wazuh-syscheckd.
Destructive actions, which means agent deploy, agent removal and active response, require approval through the safety system before anything runs.
MANAGER HEALTH wazuh-modulesd running wazuh-analysisd running wazuh-remoted running wazuh-syscheckd running FLEET 9 agents 7 active 1 disconnected 1 pending ALERTS (24h) Critical: 2 High: 8 Medium: 31 Last: SSH brute force on nw-edge-gw-01
You: "Any security issues this week?" CommanderQ: "3 items worth attention: 1. nw-worker-01 has 2 critical CVEs (libssl3, curl) Fix: apt update && apt upgrade libssl3 curl 2. 47 failed SSH attempts on nw-edge-gw-01 from 185.220.101.x (Tor exit node) - blocked by active response 3. /etc/crontab modified on nw-hv-02 at 03:14 - matches scheduled maintenance window, benign"
AI triage
CommanderQ reads the feed so you do not have to
Ask questions in plain English. CommanderQ queries the Wazuh API, cross-references with fleet data from QuoxAgent and Uptime Kuma, and returns actionable answers.
It filters noise based on your environment, identifies false positives from maintenance windows, and provides fix commands you can run immediately. Triage happens via prompt delegation to CommanderQ, not a separate ML model.
- Contextual triage with fleet awareness
- Noise filtering based on your environment
- Fix commands for detected vulnerabilities
- Cross-references with QuoxAgent and Uptime Kuma data
Agent deployment
Deploy agents from the dashboard
Traditional Wazuh agent deployment means SSH-ing into every host, adding the repository, installing the package, editing the config and starting the service. This plugin reduces that to a single click.
Select hosts from your fleet, click deploy. QuoxCORE connects through your bastion, installs the Wazuh agent, configures the manager address and starts the service.
- One-click deployment via bastion SSH
- Automatic agent configuration and startup
- Bulk deploy to the entire fleet
- Deployment history tracked server-side
- Agent status verification after install
HOST IP STATUS nw-web-01 10.20.0.101 Deploying... nw-db-01 10.20.0.102 Installed nw-worker-01 10.20.0.103 Ready nw-backup-01 10.20.0.104 Ready nw-hv-01 10.20.0.10 Installed nw-hv-02 10.20.0.11 Ready nw-monitor-01 10.20.0.50 Installed Already enrolled: nw-edge-gw-01, wazuh01
How it installs
Four steps to a working SOC
No download and no redeploy. The plugin unlocks with a licence key on your instance.
Prerequisites: a QuoxCORE instance and a Wazuh v4.x server reachable from your bastion.
Pricing
Pay once, keep it
One payment unlocks the full plugin: all seven tabs, all ten AEE intents, AI triage and fleet agent deployment. No monthly fee, no seats, no metering.
Requires QuoxCORE and a Wazuh v4.x server you run yourself.
Wazuh is open source and not included in this price.
Governed
A security desk with a trail
Security tooling that acts on your fleet should be the most accountable thing you run. Every response this plugin makes is scoped, gated and witnessed.
Scoped
Every action ships as one of ten declared AEE intents. The plugin can do what it declares and nothing else.
Approved
Agent deploy, agent removal and active response are gated. A human approves before anything touches a host.
Witnessed
Every response is recorded on WARD, the append-only receipt chain. The trail cannot be quietly edited after the fact.
Kill switch
One control stops the plugin acting on your fleet immediately. Monitoring keeps reading, actions stop.
Every verdict, every deployment, every response: witnessed on the WARD receipt chain. Read the WARD protocol →