Security operations

FAST Overview

Threat intelligence, detection coverage and platform visibility in one place.

Checking collector
Defensive security workspace

Threat intelligence and SIEM visibility built for the blue team.

FAST collects external intelligence, normalizes and scores indicators, exports validated network IOCs to Wazuh, and presents the operational picture through one focused interface.

Collector status
Checking
Waiting for the FAST health endpoint.
Total IOCs
Normalized records in the FAST database
Active Feeds
Providers currently represented in the database
High Confidence
Indicators scored 75 or 100
Detection Rules
3
SSH · Port Scan · LOLBin
IOC distribution
Indicators by type
Source coverage
Threat intelligence feeds

IOC Intelligence

Search, filter and export the normalized threat intelligence database.

IOC ValueTypeFeed(s)ConfidenceLast Seen
No matching IOCs were found.

Threat Feeds

Provider coverage and the number of normalized records attributed to each intelligence source. Use the single global Sync Intelligence control in the header whenever you want fresh data.

Feed status represents whether the FAST database currently contains records attributed to that provider. Providers remain independent, so one feed can fail without blocking the others.

FAST Detections

Current FAST detection catalogue deployed into Wazuh. Live event investigation remains in Wazuh Threat Hunting.

This screen is intentionally read-only. It describes the detection layer without changing Wazuh rule behavior or exposing privileged administration through the public UI.

System Health

Read-only operational visibility for the FAST web collector and its integration points.

Collector
FAST Web / IOC Database
Web API
Flask health endpoint
Checking...
IOC Database
Current normalized IOC count
Last UI Check
Most recent browser-side health check
Not yet
Integrations
Wazuh & deployment boundary
Wazuh Dashboard
External SIEM / Threat Hunting interface
Not configured
Public UI
Designed for tunnel / HTTPS presentation
Read-only admin boundary
Flask Debug
Disabled by default in deployed environments
Off by default
Wazuh Manager, Indexer and Filebeat health remain authoritative in ./bin/fast status. The public UI does not receive Docker-socket access.

FAST Architecture

How external threat intelligence becomes normalized data and Wazuh detections.

01 · Sources
Threat Feeds
Feodo, URLhaus, MalwareBazaar and Spamhaus provide raw indicators.
02 · Collector
Normalize & Deduplicate
FAST converts provider records into one schema and merges duplicate observations.
03 · Intelligence
Score & Store
Confidence is recalculated from source coverage and stored in SQLite.
04 · SIEM
Wazuh CDB & Rules
Validated network intelligence is exported to Wazuh alongside FAST detection rules.
05 · Detection
Threat Hunting
Wazuh analyzes endpoint activity and surfaces FAST security alerts.