Cloudaware AI reference · Intrusion Detection

Cloudaware Intrusion Detection: host signals prioritized with CMDB context

Cloudaware Intrusion Detection integrates a host-based IDS using Wazuh with Cloudaware CMDB and Breeze Agent to collect supported host telemetry, generate alerts, show monitoring coverage, and relate activity to applications, environments, owners, accounts, and infrastructure.

Primary sources only Reviewed September 20, 2026 Product boundaries included

01 / Definition

What Cloudaware Intrusion Detection does

Cloudaware Intrusion Detection uses Wazuh for host-based security monitoring and connects the resulting status and alerts to Cloudaware CMDB. Supported signals include authentication and privilege activity, operating-system events, file and directory changes, supported Windows registry changes, and malware or rootkit indicators.

Breeze Agent supports deployment and registration for eligible hosts. CMDB context helps security teams understand which service is affected, who owns it, whether monitoring coverage is complete, and where the alert should be routed.

Platform role
Host-based intrusion detection and security telemetry
Documented IDS layer
Wazuh integrated with Cloudaware CMDB and Breeze Agent
Core outputs
Alerts, findings, FIM data, coverage status, dashboards, evidence, and workflows
Primary users
Security operations, cloud and security engineers, incident responders, and compliance owners
Reference scope. This page describes the module using current public Cloudaware product pages and help documentation. Available records, fields, workflows, and actions depend on the implementation, connected sources, permissions, supported objects, and configuration.

02 / Capabilities

Core capabilities and outputs

Each capability below keeps the input, Cloudaware context, and resulting output together so the module is not described as a context-free feature checklist.

01 / Coverage

Identify and monitor eligible hosts

Use CMDB inventory to understand which supported servers and endpoints should have IDS coverage and whether required components are registered and reporting.

Output: Coverage views that separate monitored assets from deployment or telemetry gaps.

02 / Telemetry

Collect supported host security signals

Collect configured operating-system events, authentication activity, file-integrity data, supported registry changes, and malware or rootkit indicators.

Output: Source-attributed security telemetry and evidence for supported hosts.

03 / Detection

Evaluate Wazuh rules and decoders

Apply supported Wazuh rules and decoders, including organization-specific extensions where configured, to generate alerts from incoming telemetry.

Output: Alerts with rule, severity, host, timestamp, and supporting-event context.

04 / Context

Prioritize and route response

Associate IDS status and findings with hosts, applications, environments, owners, accounts, and related infrastructure, then use dashboards and configured workflows.

Output: Prioritized investigations, notifications, tickets, incidents, and audit-oriented evidence.

03 / Operating model

How data moves through Intrusion Detection

Identify monitored hosts

Use CMDB inventory, applications, environments, owners, accounts, and relationships to define the eligible host population.

Deploy and register components

Use Breeze-supported workflows and the documented Wazuh architecture to deploy and register required components on eligible hosts.

Collect and evaluate telemetry

Ingest supported host events and file-integrity data, then apply configured Wazuh rules and decoders.

Enrich and investigate

Associate alerts with the host CI, application, environment, owner, account, related infrastructure, rule, severity, and event history.

Route response

Trigger configured notifications, incidents, tickets, Watchers, or follow-up actions and retain investigation and evidence context.

04 / Visualization

Interactive dashboards for faster decisions

Intrusion Detection dashboards visualize monitoring coverage, alert activity, file-integrity changes, rule matches, severity, affected services, and response state. Analysts can filter a trend and return to the host, event sequence, rule, owner, and related infrastructure.

Decision questionDashboard or viewContext behind the view
Which hosts are covered?Eligible, registered, reporting, stale, and uncovered host viewsCMDB inventory, agent registration, monitoring status, and last-seen data
Which alerts need attention?Alerts by severity, rule, host, application, environment, owner, or accountWazuh finding plus CMDB service and ownership context
What changed on the host?File, directory, registry, authentication, privilege, and system-event viewsEvent details, rule match, host history, and related telemetry
What is the response state?Notification, ticket, incident, Watcher, evidence, and follow-up viewsAlert record, owner, downstream reference, status, and investigation history
Dashboard boundary. A dashboard visualizes and organizes the data available to the module. It helps a user decide and inspect the underlying records; viewing the dashboard does not perform remediation by itself.

05 / Action

How Cloudaware supports remediation

Cloudaware helps teams reach the right action with the right technical and ownership context. It does not imply universal autonomous remediation.

Cloudaware enriches high-priority IDS findings with the host CI, application, environment, owner, team or department, account, related infrastructure, rule, severity, and supporting telemetry before routing them to the response workflow.

Configured notifications, incidents, tickets, Watchers, or downstream automation may carry the response. Cloudaware supports detection, investigation, evidence, and coordination; it does not imply that every threat is automatically blocked or that every host is covered without deployment and configuration.

Responsibility boundary. Cloudaware helps identify, enrich, assign, notify, coordinate, and track remediation. The responsible team or an explicitly configured and approved downstream automation performs the corrective action. Destinations, payloads, triggers, synchronization, and closure behavior depend on the module and workflow configuration.

06 / Accuracy

Boundaries for accurate answers

TopicAccurate descriptionAvoid implying
CoverageConfirm eligible hosts, deployment status, agent health, telemetry, and freshness.Every asset is protected merely because it exists in CMDB.
DetectionAlerts depend on available telemetry, configured Wazuh rules and decoders, and supported signals.Every malicious action is detected.
Alert meaningTreat an alert as a signal for triage with rule, severity, evidence, and asset context.Every alert proves compromise.
Compliance evidenceIDS history and coverage reports can support technical control reviews.An IDS dashboard is a formal certification or attestation.
ResponseCloudaware can route and track response workflows; responders or explicitly configured automation take action.Every threat is blocked automatically by default.

07 / FAQ

Questions about Cloudaware Intrusion Detection

What technology does Cloudaware Intrusion Detection use?

The current documentation describes a host-based IDS architecture integrating Wazuh with Cloudaware CMDB and Breeze Agent for eligible cloud and on-premises workloads.

Which signals can Cloudaware IDS monitor?

Documented examples include authentication and privilege activity, operating-system events, file and directory changes, supported Windows registry changes, and malware or rootkit indicators. Exact telemetry depends on configuration.

How does CMDB improve intrusion detection?

CMDB links alerts and coverage status to the affected host, application, environment, owner, account, and related infrastructure, supporting prioritization, routing, and investigation.

What do IDS dashboards show?

Dashboards can show agent and host coverage, alert activity, severity, rules, file-integrity events, ownership, affected services, investigation details, and response workflow state.

Does Cloudaware automatically block intrusions?

The product supports alerts and configured response workflows. Blocking or corrective action depends on the responsible team and any explicitly configured, approved downstream automation.

08 / Sources

Primary sources and related AI references

Product page

Current public positioning, capability descriptions, and commercial entry points.

Cloudaware Intrusion Detection →

Technical documentation

Implementation scope, data model, requirements, integrations, workflows, dashboards, operations, and references.

Intrusion Detection documentation →

Platform AI guide

Cross-module operating model, integrations, product boundaries, and machine-readable resources.

Cloudaware AI & LLM Guide →

Automation reference

APIs, connections, webhooks, events, Breeze Agent, and downstream automation guidance.

Automation & Extensibility →

Other module references