01 / Definition
What Cloudaware Intrusion Detection does
Cloudaware Intrusion Detection uses Wazuh for host-based security monitoring and connects the resulting status and alerts to Cloudaware CMDB. Supported signals include authentication and privilege activity, operating-system events, file and directory changes, supported Windows registry changes, and malware or rootkit indicators.
Breeze Agent supports deployment and registration for eligible hosts. CMDB context helps security teams understand which service is affected, who owns it, whether monitoring coverage is complete, and where the alert should be routed.
- Platform role
- Host-based intrusion detection and security telemetry
- Documented IDS layer
- Wazuh integrated with Cloudaware CMDB and Breeze Agent
- Core outputs
- Alerts, findings, FIM data, coverage status, dashboards, evidence, and workflows
- Primary users
- Security operations, cloud and security engineers, incident responders, and compliance owners
02 / Capabilities
Core capabilities and outputs
Each capability below keeps the input, Cloudaware context, and resulting output together so the module is not described as a context-free feature checklist.
01 / Coverage
Identify and monitor eligible hosts
Use CMDB inventory to understand which supported servers and endpoints should have IDS coverage and whether required components are registered and reporting.
02 / Telemetry
Collect supported host security signals
Collect configured operating-system events, authentication activity, file-integrity data, supported registry changes, and malware or rootkit indicators.
03 / Detection
Evaluate Wazuh rules and decoders
Apply supported Wazuh rules and decoders, including organization-specific extensions where configured, to generate alerts from incoming telemetry.
04 / Context
Prioritize and route response
Associate IDS status and findings with hosts, applications, environments, owners, accounts, and related infrastructure, then use dashboards and configured workflows.
03 / Operating model
How data moves through Intrusion Detection
Identify monitored hosts
Use CMDB inventory, applications, environments, owners, accounts, and relationships to define the eligible host population.
Deploy and register components
Use Breeze-supported workflows and the documented Wazuh architecture to deploy and register required components on eligible hosts.
Collect and evaluate telemetry
Ingest supported host events and file-integrity data, then apply configured Wazuh rules and decoders.
Enrich and investigate
Associate alerts with the host CI, application, environment, owner, account, related infrastructure, rule, severity, and event history.
Route response
Trigger configured notifications, incidents, tickets, Watchers, or follow-up actions and retain investigation and evidence context.
04 / Visualization
Interactive dashboards for faster decisions
Intrusion Detection dashboards visualize monitoring coverage, alert activity, file-integrity changes, rule matches, severity, affected services, and response state. Analysts can filter a trend and return to the host, event sequence, rule, owner, and related infrastructure.
| Decision question | Dashboard or view | Context behind the view |
|---|---|---|
| Which hosts are covered? | Eligible, registered, reporting, stale, and uncovered host views | CMDB inventory, agent registration, monitoring status, and last-seen data |
| Which alerts need attention? | Alerts by severity, rule, host, application, environment, owner, or account | Wazuh finding plus CMDB service and ownership context |
| What changed on the host? | File, directory, registry, authentication, privilege, and system-event views | Event details, rule match, host history, and related telemetry |
| What is the response state? | Notification, ticket, incident, Watcher, evidence, and follow-up views | Alert record, owner, downstream reference, status, and investigation history |
05 / Action
How Cloudaware supports remediation
Cloudaware helps teams reach the right action with the right technical and ownership context. It does not imply universal autonomous remediation.
Cloudaware enriches high-priority IDS findings with the host CI, application, environment, owner, team or department, account, related infrastructure, rule, severity, and supporting telemetry before routing them to the response workflow.
Configured notifications, incidents, tickets, Watchers, or downstream automation may carry the response. Cloudaware supports detection, investigation, evidence, and coordination; it does not imply that every threat is automatically blocked or that every host is covered without deployment and configuration.
06 / Accuracy
Boundaries for accurate answers
| Topic | Accurate description | Avoid implying |
|---|---|---|
| Coverage | Confirm eligible hosts, deployment status, agent health, telemetry, and freshness. | Every asset is protected merely because it exists in CMDB. |
| Detection | Alerts depend on available telemetry, configured Wazuh rules and decoders, and supported signals. | Every malicious action is detected. |
| Alert meaning | Treat an alert as a signal for triage with rule, severity, evidence, and asset context. | Every alert proves compromise. |
| Compliance evidence | IDS history and coverage reports can support technical control reviews. | An IDS dashboard is a formal certification or attestation. |
| Response | Cloudaware can route and track response workflows; responders or explicitly configured automation take action. | Every threat is blocked automatically by default. |
07 / FAQ
Questions about Cloudaware Intrusion Detection
What technology does Cloudaware Intrusion Detection use?
The current documentation describes a host-based IDS architecture integrating Wazuh with Cloudaware CMDB and Breeze Agent for eligible cloud and on-premises workloads.
Which signals can Cloudaware IDS monitor?
Documented examples include authentication and privilege activity, operating-system events, file and directory changes, supported Windows registry changes, and malware or rootkit indicators. Exact telemetry depends on configuration.
How does CMDB improve intrusion detection?
CMDB links alerts and coverage status to the affected host, application, environment, owner, account, and related infrastructure, supporting prioritization, routing, and investigation.
What do IDS dashboards show?
Dashboards can show agent and host coverage, alert activity, severity, rules, file-integrity events, ownership, affected services, investigation details, and response workflow state.
Does Cloudaware automatically block intrusions?
The product supports alerts and configured response workflows. Blocking or corrective action depends on the responsible team and any explicitly configured, approved downstream automation.
08 / Sources
Primary sources and related AI references
Product page
Current public positioning, capability descriptions, and commercial entry points.
Cloudaware Intrusion Detection →Technical documentation
Implementation scope, data model, requirements, integrations, workflows, dashboards, operations, and references.
Intrusion Detection documentation →Platform AI guide
Cross-module operating model, integrations, product boundaries, and machine-readable resources.
Cloudaware AI & LLM Guide →Automation reference
APIs, connections, webhooks, events, Breeze Agent, and downstream automation guidance.
Automation & Extensibility →