Skip to main content

What is Mobius?

Mobius is an agentic SOC for Wazuh. It sits on top of the Wazuh deployment you already run and does the work of a level-1 analyst, on every alert, around the clock:

  1. Ingest. Mobius polls your Wazuh indexer for new alerts through the connector, which is outbound-only, opens no inbound ports, and never lets credentials leave your network.
  2. Triage. An AI L1 analyst classifies each alert: a verdict, a risk score, MITRE ATT&CK enrichment, and a written rationale. A corpus of security playbooks grounds the analysis.
  3. Correlate. Escalated alerts are grouped into incidents and passed through a deeper L2 review, so a burst of related alerts reaches you as one coherent story.
  4. Respond. When a triaged incident warrants it, Incident Response can block the attacker IP on the affected agent, automatically or after your approval.
  5. Notify. Routing rules deliver what matters to the right channel. The rest stays queryable in the console.

What you get in the console​

  • Every alert with its AI verdict, score, and rationale, filterable and auditable.
  • Incidents with their member alerts, timeline, and status.
  • Environment health: connector status, ingest rate, and processing lag.
  • Notification routing, team management, and billing.

Deployment shape​

Nothing about your Wazuh deployment changes. Mobius runs as a hosted service, and the only thing installed on your side is the connector, a single self-contained binary on one Wazuh node. Which node depends on the shape of the deployment, and the install page says which. Mobius pulls alerts on demand through the connector's outbound session and never stores your indexer credentials.