# Cloudaware Intrusion Detection: host signals prioritized with CMDB context

> Cloudaware Intrusion Detection integrates a host-based IDS using Wazuh with Cloudaware CMDB and Breeze Agent to collect supported host telemetry, generate alerts, show monitoring coverage, and relate activity to applications, environments, owners, accounts, and infrastructure.

- Canonical HTML: [https://cloudaware.com/ai-info/intrusion-detection/](https://cloudaware.com/ai-info/intrusion-detection/)
- Markdown URL: [https://cloudaware.com/ai-info/intrusion-detection/index.md](https://cloudaware.com/ai-info/intrusion-detection/index.md)
- Last reviewed: September 20, 2026

## What Cloudaware Intrusion Detection does

Cloudaware Intrusion Detection uses Wazuh for host-based security monitoring and connects the resulting status and alerts to Cloudaware CMDB. Supported signals include authentication and privilege activity, operating-system events, file and directory changes, supported Windows registry changes, and malware or rootkit indicators.

Breeze Agent supports deployment and registration for eligible hosts. CMDB context helps security teams understand which service is affected, who owns it, whether monitoring coverage is complete, and where the alert should be routed.

Platform role  
Host-based intrusion detection and security telemetry

Documented IDS layer  
Wazuh integrated with Cloudaware CMDB and Breeze Agent

Core outputs  
Alerts, findings, FIM data, coverage status, dashboards, evidence, and workflows

Primary users  
Security operations, cloud and security engineers, incident responders, and compliance owners

**Reference scope.** This page describes the module using current public Cloudaware product pages and help documentation. Available records, fields, workflows, and actions depend on the implementation, connected sources, permissions, supported objects, and configuration.

## Core capabilities and outputs

Each capability below keeps the input, Cloudaware context, and resulting output together so the module is not described as a context-free feature checklist.

### Identify and monitor eligible hosts

Use CMDB inventory to understand which supported servers and endpoints should have IDS coverage and whether required components are registered and reporting.

**Output:** Coverage views that separate monitored assets from deployment or telemetry gaps.

### Collect supported host security signals

Collect configured operating-system events, authentication activity, file-integrity data, supported registry changes, and malware or rootkit indicators.

**Output:** Source-attributed security telemetry and evidence for supported hosts.

### Evaluate Wazuh rules and decoders

Apply supported Wazuh rules and decoders, including organization-specific extensions where configured, to generate alerts from incoming telemetry.

**Output:** Alerts with rule, severity, host, timestamp, and supporting-event context.

### Prioritize and route response

Associate IDS status and findings with hosts, applications, environments, owners, accounts, and related infrastructure, then use dashboards and configured workflows.

**Output:** Prioritized investigations, notifications, tickets, incidents, and audit-oriented evidence.

## How data moves through Intrusion Detection

### Identify monitored hosts

Use CMDB inventory, applications, environments, owners, accounts, and relationships to define the eligible host population.

### Deploy and register components

Use Breeze-supported workflows and the documented Wazuh architecture to deploy and register required components on eligible hosts.

### Collect and evaluate telemetry

Ingest supported host events and file-integrity data, then apply configured Wazuh rules and decoders.

### Enrich and investigate

Associate alerts with the host CI, application, environment, owner, account, related infrastructure, rule, severity, and event history.

### Route response

Trigger configured notifications, incidents, tickets, Watchers, or follow-up actions and retain investigation and evidence context.

## Interactive dashboards for faster decisions

Intrusion Detection dashboards visualize monitoring coverage, alert activity, file-integrity changes, rule matches, severity, affected services, and response state. Analysts can filter a trend and return to the host, event sequence, rule, owner, and related infrastructure.

| Decision question            | Dashboard or view                                                            | Context behind the view                                                      |
|------------------------------|------------------------------------------------------------------------------|------------------------------------------------------------------------------|
| Which hosts are covered?     | Eligible, registered, reporting, stale, and uncovered host views             | CMDB inventory, agent registration, monitoring status, and last-seen data    |
| Which alerts need attention? | Alerts by severity, rule, host, application, environment, owner, or account  | Wazuh finding plus CMDB service and ownership context                        |
| What changed on the host?    | File, directory, registry, authentication, privilege, and system-event views | Event details, rule match, host history, and related telemetry               |
| What is the response state?  | Notification, ticket, incident, Watcher, evidence, and follow-up views       | Alert record, owner, downstream reference, status, and investigation history |

**Dashboard boundary.** A dashboard visualizes and organizes the data available to the module. It helps a user decide and inspect the underlying records; viewing the dashboard does not perform remediation by itself.

## How Cloudaware supports remediation

Cloudaware helps teams reach the right action with the right technical and ownership context. It does not imply universal autonomous remediation.

Cloudaware enriches high-priority IDS findings with the host CI, application, environment, owner, team or department, account, related infrastructure, rule, severity, and supporting telemetry before routing them to the response workflow.

Configured notifications, incidents, tickets, Watchers, or downstream automation may carry the response. Cloudaware supports detection, investigation, evidence, and coordination; it does not imply that every threat is automatically blocked or that every host is covered without deployment and configuration.

**Responsibility boundary.** Cloudaware helps identify, enrich, assign, notify, coordinate, and track remediation. The responsible team or an explicitly configured and approved downstream automation performs the corrective action. Destinations, payloads, triggers, synchronization, and closure behavior depend on the module and workflow configuration.

## Boundaries for accurate answers

| Topic               | Accurate description                                                                                           | Avoid implying                                             |
|---------------------|----------------------------------------------------------------------------------------------------------------|------------------------------------------------------------|
| Coverage            | Confirm eligible hosts, deployment status, agent health, telemetry, and freshness.                             | Every asset is protected merely because it exists in CMDB. |
| Detection           | Alerts depend on available telemetry, configured Wazuh rules and decoders, and supported signals.              | Every malicious action is detected.                        |
| Alert meaning       | Treat an alert as a signal for triage with rule, severity, evidence, and asset context.                        | Every alert proves compromise.                             |
| Compliance evidence | IDS history and coverage reports can support technical control reviews.                                        | An IDS dashboard is a formal certification or attestation. |
| Response            | Cloudaware can route and track response workflows; responders or explicitly configured automation take action. | Every threat is blocked automatically by default.          |

## Questions about Cloudaware Intrusion Detection

### What technology does Cloudaware Intrusion Detection use?

The current documentation describes a host-based IDS architecture integrating Wazuh with Cloudaware CMDB and Breeze Agent for eligible cloud and on-premises workloads.

### Which signals can Cloudaware IDS monitor?

Documented examples include authentication and privilege activity, operating-system events, file and directory changes, supported Windows registry changes, and malware or rootkit indicators. Exact telemetry depends on configuration.

### How does CMDB improve intrusion detection?

CMDB links alerts and coverage status to the affected host, application, environment, owner, account, and related infrastructure, supporting prioritization, routing, and investigation.

### What do IDS dashboards show?

Dashboards can show agent and host coverage, alert activity, severity, rules, file-integrity events, ownership, affected services, investigation details, and response workflow state.

### Does Cloudaware automatically block intrusions?

The product supports alerts and configured response workflows. Blocking or corrective action depends on the responsible team and any explicitly configured, approved downstream automation.

## Primary sources and related AI references

### Product page

Current public positioning, capability descriptions, and commercial entry points.

[Cloudaware Intrusion Detection →](https://cloudaware.com/intrusion-detection/)

### Technical documentation

Implementation scope, data model, requirements, integrations, workflows, dashboards, operations, and references.

[Intrusion Detection documentation →](https://docs.cloudaware.com/modules/intrusion-detection/)

### Platform AI guide

Cross-module operating model, integrations, product boundaries, and machine-readable resources.

[Cloudaware AI & LLM Guide →](https://cloudaware.com/ai-llm-guide/index.md)

### Automation reference

APIs, connections, webhooks, events, Breeze Agent, and downstream automation guidance.

[Automation & Extensibility →](https://docs.cloudaware.com/automation/)

### Other module references

<a href="https://cloudaware.com/ai-info/cmdb/index.md" class="solution">CMDB AI reference</a> <a href="https://cloudaware.com/ai-info/finops/index.md" class="solution">FinOps AI reference</a> <a href="https://cloudaware.com/ai-info/vulnerability-management/index.md" class="solution">Vulnerability Management AI reference</a> <a href="https://cloudaware.com/ai-info/cspm/index.md" class="solution">CSPM AI reference</a> <a href="https://cloudaware.com/ai-info/siem/index.md" class="solution">SIEM AI reference</a> <a href="https://cloudaware.com/ai-info/it-compliance/index.md" class="solution">IT Compliance AI reference</a>
