Skip to main content

Workflows & reports

Mobius runs a focused catalogue of workflows structured around how a modern SOC actually operates: a six-step pipeline runs continuously and watches your Wazuh stack 24/7, and on top of it sit an on-demand threat hunt you trigger yourself and a library of scheduled reports you can switch on per tenant.

Each step that uses AI costs what that step actually consumed, so a deeper pass over one incident costs more than a routine triage, and a step that never ran is never charged for. See Billing & pricing.

How Mobius layers its analysis: L1, L2 and L3​

  • L1 triage. Every Wazuh alert is classified. The goal is to cull false positives, set priority, and decide whether a deeper look is worth it. Runs on every alert, always.
  • L2 investigation. Only the alerts L1 flags for investigation reach this tier. A specialist pass branches by threat category and pulls extra context, going further on high and urgent alerts than on standard ones.
  • L3 incident expert. When correlated alerts form a significant incident, a deeper pass reconstructs the attack chain, writes an executive summary, and recommends actions. Rare by design, and it chains straight into a report.

The continuous flow​

Mobius polls each connected environment about once a minute, drops low-value noise and the same rule firing repeatedly on an agent, then runs L1 triage. Any alert L1 marks for investigation flows straight into L2 for a closer look.

Right after each triage pass, incident correlation groups the fresh alerts per agent and opens or updates incidents, with no button to press. For correlated, higher-severity incidents, the incident expert reads every alert tied to the incident, reconstructs the attack chain, and chains into Generate Incident Report. Report generation is idempotent: it skips if a report already exists for that incident.

What you launch yourself​

The pipeline steps run on their own and show up as locked cards on the workflows page. They are ingest, triage, investigation, correlation and the incident expert. What you drive directly:

  • Threat hunt. Give it an indicator and a lookback window, and Mobius searches your environment and surfaces every match as an alert flagged for investigation. An indicator is an IP, a file hash, a username, a CVE or a rule id.
  • Generate Incident Report. Launched from an incident on the reports page, described below.
  • Incident Response, the Block IP action, is not launched from the catalogue either. It fires automatically or on approval. See Incident response.

Scheduled reports​

Beyond the live pipeline, Mobius ships a library of 17 scheduled reports you can switch on per tenant from the workflows page. Each runs one pass per selected environment and is written in plain language by the AI:

CadenceReports
DailySOC Health, Shift Handoff, Authentication & Access Abuse, Vulnerability Triage, Alert Aging, FIM Drift
WeeklyThreat Landscape, Agent Health & Audit, False-Positive Tuning, Top Talkers, SCA Drift
MonthlyExecutive Summary, Compliance Posture, SLA Performance
QuarterlyBoard Report, Risk Assessment, Compliance Audit Trail

A few carry a beta badge, and the catalogue also lists roadmap cards marked Coming soon that are not built yet. Open any finished run from the Scheduled tab of Reports to read the full report, then use Download as PDF to export a branded copy that carries every section the console shows.

Generating an incident report​

Reports are AI-written narratives describing what happened in an incident: what was detected, when, on which assets, and the recommended next steps.

  1. On the reports page, click New report. A picker lists every incident that does not yet have a report, each showing its threat category and number of alerts.
  2. The button shows Starting... then Generating... while the workflow runs, so you can navigate away. Generation takes a couple of minutes.
  3. When it finishes, the report appears in the list. Click the title to read the full write-up, or the linked INC-… id to jump back to the source incident.

What to expect day to day​

Most alerts are triaged within a few minutes of arriving. Take a typical mid-size deployment at roughly 10k Wazuh alerts a day after de-duplication. Expect roughly 10 to 50 alerts a day escalated to L2 for investigation, roughly 1 to 5 incidents a day opened by correlation, and a handful of generated reports when incidents form. Almost all of that is automated: your job is to review incidents, bundle related ones into cases, run hunts, and act with Incident Response when something needs containment.

Workflow catalogue at a glance​

WorkflowWhen it runs
L1 TriageContinuous and automatic. Pulls and filters alerts from each environment
L2 InvestigationWhen L1 flags an alert, automatic
Scan for incidentsAfter each triage pass, automatic
Incident expertOn significant incidents, automatic
Generate Incident ReportWith each incident, or on demand
Threat huntYou launch it
Incident ResponseAutomatic or on approval
Scheduled reports, 17 of themDaily, weekly, monthly or quarterly