Security Pillar

// Endpoint Security & SIEM

Threats detected before they become incidents.

Wazuh SIEM deployed across your endpoints, servers, and network — correlated, alerted, and triaged by engineers who know your environment. Not a dashboard you log into. A service that pages you when it matters.

< 5 min

Mean time to alert

90 days

Hot log retention

24 / 7

Monitoring coverage

NPC-ready

Compliance reporting

// Coverage

Every layer of your stack. One correlated view.

Siloed alerts miss the story. We ingest from endpoints, servers, network, and cloud — so a login anomaly on a workstation correlates with the firewall event that preceded it.

Endpoints & workstations

Every Windows, Linux, and macOS device is enrolled in the Wazuh agent. File integrity, process execution, and login events — logged and alerted in real time.

Servers & virtualisation hosts

Proxmox, VMware, and bare-metal servers. Kernel events, privilege escalation attempts, and unexpected service restarts surface immediately, not in the next morning's report.

Network traffic & firewall logs

Log ingestion from pfSense, OPNsense, Cisco, and Mikrotik. Lateral movement and port-scan patterns are correlated across devices, not treated as isolated events.

Cloud workloads

AWS CloudTrail, Azure Activity Logs, and container runtime events fed directly into the SIEM. One dashboard, every environment.

// Process

From zero visibility to full coverage in under a week.

Agent deployment is the shortest part. Tuning your environment so alerts are signal, not noise, is where the work actually happens.

01

Agent deployment

Wazuh agents installed on every managed endpoint and server — typically completed within one business day for up to 50 nodes.

02

Baseline & tuning

We establish your environment's normal behaviour over 5–7 days, then suppress noise and sharpen detection rules to your actual threat surface.

03

Real-time alerting

Critical-severity events page your designated contact immediately. Medium events are batched into a daily digest unless they cluster into a pattern.

04

Incident response

When an alert fires, we triage first — you get a qualified finding, not a raw log dump. Containment steps are executed with your approval, fully documented.

// Technology

Open-source stack. No per-seat licensing. Fully auditable.

Every tool we deploy is open-source and self-hosted in your environment. You own the data, the config, and the stack — not a SaaS subscription that walks out the door if you stop paying.

// Your stack. Your data.

No vendor lock-in. No data leaving your network. Full documentation so your team can operate it independently.

Wazuh

SIEM & XDR

Docs

Open-source, agent-based. No per-endpoint licensing cost. Full source access — you own the stack.

Falco

Container & kernel runtime

Docs

eBPF-based syscall monitoring for containerised workloads and Kubernetes clusters.

Grafana / OpenSearch

Dashboards & log search

Custom dashboards per client. Full-text log search across every ingested source with 90-day hot retention.

pfSense / OPNsense

Perimeter log ingestion

Firewall rule hits, blocked IPs, and geo-anomalies correlated with endpoint events for full kill-chain visibility.

// Security scope

Physical and digital security — monitored from one platform.

Our Security pillar covers the full surface: CCTV and AI surveillance, physical access control, and cybersecurity. Frigate NVR motion events and door-controller logs feed into the same SIEM as your endpoint alerts — so a physical intrusion attempt correlates with the network activity that follows it.

  • Wazuh SIEM across endpoints, servers, and cloud

  • Firewall and network log correlation

  • Falco for container and kernel-level runtime monitoring

  • Frigate NVR + CCTV event correlation

  • NPC-compliant audit trail and retention

// FAQ

Common questions

Do we need to replace our existing antivirus?

No. Wazuh sits alongside your existing endpoint protection — it adds visibility at the OS and network layer that AV alone doesn't cover. We integrate, not replace.

How many endpoints is this suitable for?

We've deployed for environments from 5 to 300+ nodes. Below 20 endpoints the setup cost dominates, so we'll be honest if managed IT support is a better fit first.

Is this compliant with Philippine data privacy requirements?

Yes. Wazuh's log retention and access controls support NPC (National Privacy Commission) audit trail requirements. We provide a compliance report template on request.

What happens when a threat is detected at 2 AM?

Critical alerts page the on-call engineer immediately. We triage, assess, and contact your designated point of contact with a qualified finding — not a raw alert dump.

Can you monitor our CCTV and physical access control systems too?

Yes — this is a deliberate part of our Security pillar scope. Frigate NVR events and access control logs can be correlated with network and endpoint events in the same SIEM.

// Get started

Find out what your current stack is missing.

Free security assessment — we review your current environment, identify the highest-risk gaps, and give you a clear remediation plan. No sales pitch until you ask for one.

Or call +63 926 034 6800