SYNOTI / Detection Config
Detection Config
Wazuh rules, decoders and manager config · 5,120 rules.
Overview
Rules
Decoders
Manager Config
Logtest
Rules
5,120
loaded
Custom Rules
86
user-defined
Decoders
1,204
parsers
Logtest
Ready
interactive
Rule Engine Status
| Component | Status | Version | Notes |
|---|---|---|---|
| Ruleset | Loaded | 4.11.2 | 5,120 rules · 1,204 decoders |
| CDB lists | Loaded | 1.4M entries | updated 2h ago |
| Custom rules | Active | 86 rules | group synoti |
| Logtest | Ready | interactive | port 1515 |
Rule Activity / 24h
Rules by Level
Recent Activity
View allRansomware behavior blocked on mail-01 CRITICAL
Playbook PB-041 auto-contained host · Ryuk TTPs matched
SSH brute force from 203.0.113.42 HIGH
42 failed logins in 60s · source IP blocked
Threat hunt matched T1059.001 on www-02
PowerShell obfuscation · confidence 0.91
SCA scan completed on 128 hosts
98.2% compliance · 11 benchmarks passed
Firewall rule 'BLK-3321' propagated to 14 nodes
0.4s propagation · geo-blocked 12 CIDRs
Sandbox verdict — 'invoice_9921.exe' malicious
Heuristic score 96 · family 'Emotet'
