ALWAYS ON WATCH

Your infra, defended at machine speed.

Suriq wraps Wazuh with what it is missing: checks posted outside your perimeter, a plain-English answer for every alert, and DNS that fails over the instant a monitored host drops. You see the CVE that hits you in seconds - and your team stays in control of every response.

Seconds
A new CVE drops, and you already know which servers are exposed.
10,000:1
An alert storm collapses into one clear, ranked incident.
Diagnosed
A 2am incident hits, and you wake to an answer, not a mystery.
One click
Audit season: every action logged, the evidence a click away.
Interpreter

Alerts in. Answers out.

Wazuh fires a detection and hands you a dense, technical rule ID. Suriq reads it and answers in plain English: what fired, why it matters, and how to quiet it down.

Ask what a rule means or why an incident triggered. Suriq walks you through the evidence, points to the exact log lines, and suggests a tuning or a fix.

Suriq advises. Nothing runs on its own - anything it proposes waits for someone on your team to approve it.

Input
Any Wazuh alert or incident
Output
Translate · explain · suggest
Workflow
Human-in-the-loop
Acts
Only on your approval
Jack, the Suriq mascot
rule → plain English
incident explained
tuning suggested
you decide

Wazuh gave us the signal. We built the magic.

A detection engine alone tells you something happened. Suriq watches the edge, explains what it means, and keeps you standing when it hits.

01
Reflexes when infra breaks
Restart agents, suppress noisy rules, snapshot a server before a risky change - and fail DNS over automatically when a monitored host drops, reverting once it recovers. Every action is logged and attributable.
02
A brain on every alert
The Interpreter translates Wazuh's deep, technical detections, explains why an incident fired, and suggests how to tune the noise down. It recommends; your team decides.
03
Knows where you're weak
Wazuh's vulnerability detector and CIS / SCA policy scoring flag risky packages and misconfigurations across your fleet - ranked, tracked, and tied to the host they affect.
04
Eyes outside your walls
Suriq watches your network where it's exposed - DNS, routing with RPKI, port and service reachability, blacklist status, certificate expiry - and surfaces drift and hijacks as they happen.
05
Built for whole fleets
Run many teams or customers from one console, each with isolated data, secrets, and access. Built for MSSPs and platform teams that manage more than one environment.
06
Accountable by default
Every action in Suriq is logged, attributable, and bounded by role. Show your team - and your auditors - exactly what happened, when, and on whose behalf.

A CVE breaks in the wild. You know who's exposed in seconds.

December 2021: Log4Shell (CVE-2021-44228) handed attackers remote code execution on anything running log4j - mass-exploited within hours, before most teams even knew where they were exposed. Here is that scramble replayed the Suriq way: catch the probe, pinpoint every vulnerable host, get the exact fix in plain English, and patch with a safety net - while everyone else is still reading the news.

The origin goes dark.
Traffic keeps flowing.

NGINX falls over - the worker dies, the box runs out of memory, the host stops answering. Detection and correlation fire on their own; the moment the monitored origin stops responding, DNS fails over to a warm standby without a page. Deeper response stays in your hands, with every step explained.

01
Down
Detection

We catch it the instant the origin stops answering health checks - dead worker, OOM-killed process, unreachable host. No scan, no wait.

02
Grouped
Correlation

The failed health checks, the 5xx burst, and the host-down signal collapse into one incident, deduplicated and kept as a single timeline.

03
Routed
Alerting

On-call is paged where they already are - Slack, PagerDuty, email - with the assistant's plain-English read on what went down.

04
Failover
DNS failover

The moment the monitored origin stops responding, DNS fails over to a warm standby on its own - and reverts the second the box is healthy again.

The Operations Suite. The muscle behind the magic.

Three production systems doing the heavy lifting around the engine - snapshots, monitoring, and credential isolation, all run from one console.

Frequently asked questions

What is Suriq?

Suriq is a managed security platform built on Wazuh. It watches your servers for intrusions, file tampering, and CVE exposure, turns the deep technical alerts into plain-English incidents, and runs the Wazuh backend for you in your own cloud account.

Do I need to run or know Wazuh to use Suriq?

No. Suriq provisions and manages a dedicated Wazuh backend in your own cloud account - standing it up, tuning detection per host, and watching its health - so you get Wazuh-grade detection without installing or babysitting it.

Who is Suriq for?

Teams that run their own servers - across Linux distributions, containers, and mixed hosting stacks, with or without a control panel - and want managed detection and response without hiring a SOC or standing up a SIEM. Suriq adapts to whatever each host runs.

Does Suriq automatically patch or remediate my servers?

No. Suriq detects, ranks, and explains what is wrong and proposes guided fixes, but every change waits for a human to approve it. It does not silently patch or remediate your servers.

How much does Suriq cost?

Pricing is being finalized, so we are not publishing numbers yet. Suriq is in early access - get on the list or reach out, and we will scope it to your environment.

Stop running Wazuh alone.
Let Suriq run it.

Suriq deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security, all on a managed Wazuh core. The engine you trust, with external checks, plain-English answers, and failover wrapped around it.