Tenant --
Connected
Agents 0 online
Alert Summary
Severity breakdown
AI Insights
24h analysis
Recent High-Severity Alerts
Open Tickets & Incidents

Top Source Countries
Scanning...
Integration Status
Checking...
Live Event Feed
LIVE
--
Live Events
Time Level Description Agent MITRE
Loading live events...
Events/min: -- Last event: -- Top agent: -- ES status: -- Auto-refresh: 30s

Threat Intelligence & Attack Map

Updating...
Threat Activity
Critical
High
Medium
Low
Live Events
Detected Threat Events
0 events
Timestamp Source Source IP Target Target IP Severity Rule Agent

Device Monitoring

LIVE
Sysmon, PowerShell, Defender & Linux Audit Events

Loading device events...

Network Monitoring

LIVE
Suricata, Zeek & Sysmon Network Events

Loading network events...

File Integrity Monitoring

LIVE
File Change Events

Loading FIM events...

Endpoint Status

LIVE
Registered Endpoints
AgentIPOSLast EventStatus

Service Availability

ES Nodes
Indices
Index Health Status Docs Size Shards

Vulnerability Detection

Critical
--
High
--
Medium
--
Low
--
Detected Vulnerabilities
Severity Plugin Name Host CVSS Status First Seen
Loading vulnerability data...
Latest first
TimestampAgentDescriptionLevelMITREDetails
Quick Hunts by MITRE ATT&CK
Hunt Results

Open the Quick Hunts library above to run a preset, enter IoCs or a query, then click Hunt.
Built-in presets: External IPs, PowerShell, Suspicious Processes, Brute Force, Log Clearing, Data Exfil, Lateral Movement, Recon

Threat Intelligence

Sources: Loading...
--Open IncidentsActive cases
--CriticalRequires immediate action
--HighEscalation risk
--SLA BreachedOverdue incidents
--Closed (30d)Resolved this month
All Pending AI Analyzed New Triage Investigation Containment Eradication Recovery
📊 Investigation Overview
🔎 Active Case Investigations
All Windows Linux macOS

Security Reports

Generate professional reports for executive summaries, compliance audits, and technical deep dives. All reports are tenant-aware and pull live data from your connected Elasticsearch backends.

Orel Technology Solutions Inc. — CONFIDENTIAL
📈 Executive Summary
📋 Compliance Reports
🔍 Technical Deep Dive
📅 Weekly Briefing

📈 Executive Summary Report

Select a period and click Generate Report to create an executive summary with live data from the platform.

📋 Compliance Report

Select a compliance framework and period to generate a compliance posture report based on your SOC controls and evidence.

🔍 Technical Deep Dive Report

Select a focus area and time range for a detailed technical analysis with raw data, trends, and forensic-level detail.

📈 Weekly Security Briefing

Generate a comprehensive weekly security briefing with executive summary, key metrics, top threats, and recommendations.

Executive Dashboard

Total Alerts (24h)
--
Critical
--
Open Tickets
--
Active Endpoints
--
Vulnerabilities
--
SLA Met
--
SLA Breached
--
Top Threats (24h)

Loading...

MITRE ATT&CK Coverage (7d)

Loading...

Client Compliance Overview

Loading...

Scheduled Reports

0
Active Schedules
📅
0
Total Schedules

Loading scheduled reports...

Login History

TimestampUserActionIP AddressDetails
Triage SLA Team Workflow Notifications
-
Open Incidents
-
Overdue SLA
-
Avg Resolution
-
Auto-Created
Triage Classification Rules Configure how incoming alerts are classified and routed
Severity Quick Reference Severity levels, P-levels, and target response times
Danger Zone Irreversible actions
Reset Open Incidents

Delete all open incidents and reset the case ID sequence back to SOC-{year}-00001. Closed and resolved incidents are preserved.

Response and Escalation SLAs Define target response times per severity level
Recommended: Critical 15m/1h - High 1h/4h - Medium 4h/8h - Low 8h/24h
Escalation Flow How incidents move through response tiers
Tier 1
Initial Triage
Tier 2
Investigation
Tier 3
Senior Analyst
Auto-escalation: T1 timeout to T2, T2 timeout to T3. Max level: 3
Incident Response Team Organize analysts by escalation tier
Team Members by Tier Escalation rules and round-robin assignment

Escalation Configuration
Tier 1
Response SLA60
Timeoutmin
RR index0
Tier 2
Response SLA120
Timeoutmin
RR index0
Tier 3
Response SLA-
No SLA timeout - Final escalation point
RR index0
Incident Lifecycle Standard workflow from detection to closure
01New

Alert detected, ticket auto-created

02Triage

Initial assessment, severity validation

03Investigating

Deep analysis, IoC extraction

04Containment

Isolate systems, block IoCs

05Eradication

Remove artifacts, patch vulnerabilities

06Recovery

Restore services, monitor

07Closed

Post-incident review, lessons learned

MITRE ATT&CK Coverage Tactics covered by active detection rules
Initial AccessExecutionPersistence Privilege EscalationDefense EvasionCredential Access DiscoveryLateral MovementCollection Command and ControlExfiltrationImpact
Notification Channels Configure how your team gets notified on incident lifecycle events
TRIGGER EVENTS
Email Notifications
Slack / Webhook
Recent Notification Activity In-app notification history

No recent activity

v1.4.4 — Scheduled SOC Reports & WHOIS Enrichment

LATEST

August 2026 — Automated SOC reporting with email delivery, WHOIS/RDAP enrichment for IoCs, and significant enrichment performance improvements.

New Features
  • FEAT Automated SOC weekly reports — Comprehensive PDF reports auto-generated and emailed every Saturday covering the previous week's security activity. Sender no-reply@oreltechnologies.net with CC to the cybersecurity team
  • FEAT Automated SOC monthly reports — Delivered on the 1st of every month covering the previous calendar month, sent to the tenant administrator with cybersecurity team CC'd
  • FEAT Real ES data in reports — Reports now pull live alert telemetry from the tenant's Elasticsearch index (previous reports used sample data). Index existence filtering handles missing daily indices gracefully
  • FEAT WHOIS / RDAP enrichment — New built-in integration (no API key required): domain WHOIS lookup (registrar, creation/expiry dates, registrant org, name servers) and IP RDAP lookup (network CIDR, org, ASN, abuse contact). Registration details appear in the IOC lookup and analyst dashboard enrichment panels
Improvements
  • CHANGE Enrichment timeout fix — Batch enrichment no longer aborts at 15s; enrichment calls now use 90s timeout (batch) and 60s (single lookup)
  • CHANGE Cached enrichment results — Full lookup results cached for 2 hours; repeat enrichment of the same IoC returns instantly without re-querying external APIs
  • CHANGE Private IP fast-path — Internal/private IPs (10.x, 192.168.x, 172.16.x, localhost) skip external lookups entirely — batch enrichment of internal traffic now completes in ~0.1s

v1.4.3 — IoC Enrichment from Analyst Dashboard

LATEST

July 2026 — Analysts can now enrich IP addresses directly from threat events on the Analyst Dashboard with one click. New batch endpoint for efficient multi-IoC enrichment.

New Features
  • FEAT IoC Enrichment buttons on event details — Every source and destination IP in the threat event detail modal now has a TI button. Click it to instantly enrich the IP with VirusTotal, AbuseIPDB, AlienVault OTX, and Shodan data
  • FEAT Enrich All IPs — One-click button to enrich both source and destination IPs of a threat event in parallel
  • FEAT Compact enrichment cards — Results display inline in the event modal showing reputation badge, per-source verdicts, abuse confidence scores, VirusTotal detection ratios, and country info
  • FEAT Batch enrichment API — New /api/threatintel/enrich-batch endpoint enriches up to 20 IoCs in parallel. New /api/threatintel/enrich-events endpoint extracts and enriches all unique IPs from a set of dashboard events
Improvements
  • CHANGE Compact enrichment widget — Lightweight reputation badge + per-source summary with close button, designed to not overwhelm the event detail modal

v1.4.1 — Session & Token Hardening, Security Audit Remediation

LATEST

July 2026 — Comprehensive security hardening: credential removal from source code, bcrypt password migration, XSS fixes, rate limiting, race condition fixes, and environment-variable-only secrets.

Security
  • FIX Hardcoded credentials removed — SMTP password, Elasticsearch passwords, and dashboard user hashes moved to environment variables
  • FIX BCrypt password hashing — All new passwords hashed with bcrypt. Existing SHA-256 hashes auto-upgrade on next login
  • FIX XSS in Threat Map table — All alert fields now properly escaped with escHtml()
  • FIX Rate limiting on login — Brute force protection before password verification
  • FIX Admin-only client detail — Client ES password endpoint now requires site_admin/admin role
  • FIX Error information leakage — Full ES response bodies and Python stack traces no longer leak to HTTP responses
  • FIX Race condition fixgenerate_case_id() and round_robin_next() made atomic with BEGIN IMMEDIATE
  • FIX Silent error logging — Session tracking and password history failures now logged
  • FIX JWT secret enforcement — Startup warning when JWT_SECRET env var not set in production
Improvements
  • CHANGE Consolidated escape helpersescapeHtml() now delegates to escHtml(), eliminating duplicate XSS defense code
  • CHANGE Dashboard users via envDASHBOARD_USERS_HASHES env var replaces hardcoded user dict

v1.3.1 — Worker Stability, AI Refinements & UI Enhancements

July 2026 — Uvicorn worker fix, AI investigation improvements, release notes restoration, and global UI polish.

Fixes
  • FIX Uvicorn worker crash-loop — Resolved "Address already in use" error when using --workers 2; downgraded to single-worker mode for stable operation
  • FIX AI chat data parsing — Fixed forEach is not a function error when ai_chat was stored as JSON string instead of array
  • FIX Exec report undefined variables — Added missing medium/low variable declarations in generateExecReport()
  • FIX Case detail modal IDs — Aligned static modal IDs between HTML and JS to prevent blank case detail panels
  • FIX 7 missing modal overlays — Added ticket, case, correlated-alert, client, edit-user, create-user, and integration-config modal overlays
  • FIX Profile modal restored — Added missing profileModal HTML to fix "cannot load profile" error
Improvements
  • CHANGE AI independent verdict — Threat intelligence now serves as context only, no pre-bias in AI investigation conclusions
  • CHANGE 5 AI investigation enhancements — Correlated alerts feeding, severity cap fix, streaming with ES+RAG, auto-populated descriptions, enriched RAG context
  • CHANGE Release Notes page restored — Version history and changelog now available in-app
  • CHANGE Version alignment — Sidebar, system info, and backend version all aligned to v1.3.1
  • CHANGE Platform status endpoint — New /api/platform/status exposes uptime, version, and auto-ingest health
  • CHANGE Uptime & auto-ingest indicators — Settings page now shows service uptime and background ingest status

v1.2 — Navbar Collapsible, Ticket Board Fixes & Platform Improvements

June 2026 — Collapsible navigation sidebar, Ticket Board data-load fix, UI stability improvements, and tenant operations.

New Features
  • FEAT Collapsible Navbar — Navigation sidebar can now collapse for cleaner workspace and more screen real estate
  • FEAT SSE Auth Overhaul — Server-Sent Events now authenticate via ?token= query param, ensuring secure real-time updates
  • FEAT Tenant Isolation Hardening — Enforced multi-tenant isolation middleware across all routers for safer operations
  • FEAT Integrations Tab-Based UI — Tabbed interface with connection status and improved configuration
  • FEAT Loading Skeleton Animations — Shimmer placeholders streamline perceived page performance
  • FEAT Enhanced PDF Reports — Extended reportlab-generated output with improved layout for executive review
Improvements
  • CHANGE Platform UI updated to v1.2 with focused navigation and ticket flow improvements
  • CHANGE Tenant data handling refined across Dashboard, Servers, and Settings reload flows
  • CHANGE Version, badge, and release notes metadata aligned to v1.2 references
Fixes
  • FIX Ticket Board empty-state fix — data grouping now handles grouped and ungrouped response formats
  • FIX addRipple guard — prevents TypeError when click target is not an Element
  • FIX Navigation handler stability — targeted cleanup for sidebar and collision-menu invocation
  • FIX Nginx CSP coverage update to unblock carto tiles and external SheetJS exports in tenant mode
  • FIX Tenant switcher and reload flow refinements for consistent client-side state

v1.1 — Alert Correlation Engine

Alert correlation, improved threat intelligence, and expanded monitoring coverage.

Key Changes
  • FEAT Alert correlation engine — groups related alerts into incidents
  • FEAT OTX threat intelligence integration with pulse and passive DNS lookups
  • FEAT FIM (File Integrity Monitoring) dashboard with event timeline
  • FEAT Executive dashboard with SLA compliance metrics
  • CHANGE Ticket board with drag-and-drop status workflow
  • FIX Various UI and data loading optimizations across all modules

v1.0 — Initial Release

July 2026 — Foundational release with core SOC monitoring, alerting, and case management capabilities.

Tenant Overview

Create and manage organizations within the platform Loading...

Loading clients...

Each tenant has its own Elasticsearch connection, alert pipeline, and user access scope. Select a tenant from the dropdown on the top bar to switch context.

User Accounts

Manage users, assign roles, and control platform access
All Users — View, create, edit, and deactivate platform user accounts
UsernameEmailRoleStatusLast ActiveActions
Loading users...
Roles are assigned per user. Super Admin has full system access — grant sparingly. Admin can manage tenants and users. HR Manager, Dept Head, and Employee roles have limited scopes.

Security & Access Control

Define roles, permissions, and platform security policies
Role Management & Permissions — Assign users to roles and configure page-level access
Users by Role
— Overview of which users are assigned to each role

Loading...

Section Access Matrix
Apply:

Loading...

Maintenance Mode — Temporarily restrict platform access during updates or incidents
Block non-admin users from accessing the platform

Only super admins and admins can log in while this is enabled — useful during maintenance windows or critical incident response.

System Configuration

Platform information, timezone, and service status
System Information — Platform version, backend health, and connected services overview
Elasticsearch
Connection status
Backend Service
FastAPI
Python · Uvicorn
Active Tenant
Currently selected context
Platform Version
v1.4.4
Latest stable release
Service Uptime
Since last restart
Auto-Ingest
Checking...
Background alert ingestion
Timezone — Set default timezone for all users and timestamps
Current Timezone Loading...
Current Time
Changes apply globally — all platform timestamps will reflect the selected timezone.

Audit Trail

View platform activity logs, user actions, and system changes
Activity Logs — Chronological record of all platform actions and events

Loading...

Integrations

0
Total
0
Connected
0
Not Configured
0
Errors
Loading integrations...