Use case · 06

Incident response, with context in hand.

When something actually goes wrong - a breach, a breakage - incident response is the scramble to understand it and shut it down. The old way: detect, page someone, dig through raw logs at 2am, write the timeline by hand. Suriq detects fast on a managed Wazuh core, packs the noise into one clear incident, routes it to on-call, and hands your responder the evidence - with a plain-English read from Guardian a question away.

The incidents view: a deduplicated queue of security incidents with severity, MITRE tactic, source IP, rule, hit count, status, and last seen.
Click to expand

Attackers hide for months. Then the cleanup takes days you don't have.

Intruders routinely go unnoticed for months. And once you finally declare an incident, piecing it together and shutting it down can take days - days in which they already have everything they came for.

01

It arrives already understood

Wazuh detections are bundled into one incident, deduplicated, and tagged to the MITRE ATT&CK playbook - then routed to on-call so the right person sees it first, not fortieth.

02

A plain-English read, instantly

The AI interpreter turns the raw detections into a clear story: what happened, why it fired, what to check next. It advises; your team decides and acts.

03

Back online, on the record

A clean CloudSnap snapshot is always waiting as the point to recover from, and every action lands on one timeline the instant it happens - so your post-mortem writes itself instead of being pieced together by hand at dawn.

Legacy stack vs. Suriq

DimensionLegacySuriq
Time to contextHours of triageCorrelated incident on arrival
Alert routingManual triage queueDeduplicated, routed to on-call
RecoveryManual runbookA clean restore point already waiting
Post-mortemReconstruct by handTimeline + evidence retained for your post-mortem

Frequently asked questions

How does Suriq turn alerts into an incident?

Wazuh detections are correlated and deduplicated into a single incident with a status you can work - open, acknowledged, resolved, or false positive - tagged to MITRE ATT&CK and carrying the evidence. Responders open one worked incident, not a scroll of raw alerts.

Where do incident alerts get routed?

To the channels your team already uses. Suriq ships a broad set of notification integrations - on-call tools like PagerDuty and iLert, chat like Slack, Microsoft Teams, Discord, and Telegram, plus email - and the lineup keeps growing. Route the incidents that matter to the right people.

Does Suriq automatically fix or contain incidents?

No. The AI interpreter is advisory: it explains what happened, why a detection fired, and what to check next, and it can propose response actions - but every change waits for a human to approve it. Suriq does not silently remediate.

How does Suriq help me recover?

A clean CloudSnap snapshot can sit ready as a known-good point to restore from, and every action lands on one timeline as it happens - so recovery works from a real restore point and the post-mortem assembles itself instead of being pieced together by hand.

Is there an audit trail of the response?

Yes. Status changes and response actions are recorded automatically - who did what, and when - on one timeline retained on a backend you own. It is the evidence your post-mortem and any report need, without reconstructing it later.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.