Skip to main content

Workflows & reports

Mobius runs a focused catalogue of workflows structured around how a modern SOC actually operates: a six-step pipeline runs continuously and watches your Wazuh stack 24/7, and on top of it sit an on-demand threat hunt you trigger yourself and a library of scheduled reports you can switch on per tenant.

Every step that uses AI is priced to match the model it runs — a fast, low-cost model for triage, a more thorough model for deeper investigation and incident analysis — and you only pay for what actually runs against your alerts. See Billing & pricing.

How a real SOC layers AI: L1 → L2 → L3

  • L1 (triage). Every Wazuh alert is classified by a fast, low-cost model. Goal: cull false positives, set priority, and decide whether a deeper look is worth it. Runs on every alert, always.
  • L2 (investigation). Only the alerts L1 flags for investigation reach this tier. A specialist prompt branches by threat category and pulls extra context, using a fast model for standard priority and a more thorough model for high and urgent.
  • L3 (incident expert). When correlated alerts form a significant incident, a more capable model reconstructs the attack chain, writes an executive summary, and recommends actions. Rare by design — and it chains straight into a report.

The continuous flow

Mobius polls each connected environment about once a minute, drops low-value noise and the same rule firing repeatedly on an agent, then runs L1 triage. Any alert L1 marks for investigation flows straight into L2 for a closer look.

Right after each triage pass, incident correlation groups the fresh alerts per agent and opens or updates incidents — no button to press. For correlated, higher-severity incidents, the incident expert reads every alert tied to the incident, reconstructs the attack chain, and chains into Generate Incident Report. Report generation is idempotent: it skips if a report already exists for that incident.

What you launch yourself

The pipeline steps (ingest, triage, investigation, correlation, incident expert) run on their own and show up as locked cards on the workflows page. What you drive directly:

  • Threat hunt — give it an indicator (an IP, file hash, username, CVE, or rule id) and a lookback window, and Mobius searches your environment and surfaces every match as an alert flagged for investigation.
  • Generate Incident Report — launched from an incident on the reports page (see below).
  • Incident Response (Block IP) is not launched from the catalogue either: it fires automatically or on approval — see Incident response.

Scheduled reports

Beyond the live pipeline, Mobius ships a library of 17 scheduled reports you can switch on per tenant from the workflows page. Each runs one pass per selected environment and is written in plain language by the AI:

CadenceReports
DailySOC Health, Shift Handoff, Authentication & Access Abuse, Vulnerability Triage, Alert Aging, FIM Drift
WeeklyThreat Landscape, Agent Health & Audit, False-Positive Tuning, Top Talkers, SCA Drift
MonthlyExecutive Summary, Compliance Posture, SLA Performance
QuarterlyBoard Report, Risk Assessment, Compliance Audit Trail

A few carry a beta badge, and the catalogue also lists roadmap cards marked Coming soon that are not built yet. Open any finished run from Reports › Scheduled to read the full report, then use Download as PDF to export a branded copy that carries every section the console shows.

Generating an incident report

Reports are AI-written narratives describing what happened in an incident: what was detected, when, on which assets, and the recommended next steps.

  1. On the reports page, click New report. A picker lists every incident that does not yet have a report, each showing the threat category, customer, and number of alerts.
  2. The button shows Starting… then Generating… while the workflow runs — you can navigate away. Generation takes a couple of minutes.
  3. When it finishes, the report appears in the list. Click the title to read the full write-up, or the linked INC-… id to jump back to the source incident.

What to expect day to day

Most alerts are triaged within a few minutes of arriving. For a typical mid-size deployment (~10k Wazuh alerts/day after de-duplication), expect ~10–50 alerts/day escalated to L2 for investigation, ~1–5 incidents/day opened by correlation, and a handful of generated reports when incidents form. Almost all of that is automated: your job is to review incidents, bundle related ones into cases, run hunts, and act with Incident Response when something needs containment.

Workflow catalogue at a glance

WorkflowWhen it runs
L1 TriageContinuous, automatic — pulls and filters alerts from each environment
L2 InvestigationWhen L1 flags an alert, automatic
Scan for incidentsAfter each triage pass, automatic
Incident expertOn significant incidents, automatic
Generate Incident ReportWith each incident, or on demand
Threat huntYou launch it
Incident ResponseAutomatic or on approval
Scheduled reports (17)Daily / weekly / monthly / quarterly