For the complete documentation index, see llms.txt. This page is also available as Markdown.

SIEM + EDR/XDR

Sec1 SIEM + EDR/XDR is unified detection and response. A lightweight agent collects logs and endpoint telemetry from your fleet; the platform detects threats, correlates them into incidents and lets your SOC respond — from one console.

Overview

Understand what the platform does and how the pieces fit together:

Architecture

A simple end-to-end picture — agents, ingest, pipeline, detection, correlation, AI and response:

Data collection

Two ways to get data in — the Sec1 agent or an existing log collector — and how one agent serves SIEM, EDR and XDR:

Setup & access

Reach the live console, sign in with your platform credentials and understand the gateway:

Install the agent

Prerequisites, the network allowlist and single vs bulk install on Windows, Linux or macOS:

Endpoints & telemetry

Read the per-host detail view — the telemetry collected from each endpoint:

Vulnerability management

Find and triage vulnerable software across the fleet and per host:

Device control

Inventory connected peripherals and approve or block them:

Application control

Allow or deny software execution and installation by rule:

Detections, alerts & incidents

Follow the detection-to-incident flow and investigate cases:

Response actions

The live-response toolkit for acting on a host:

Last updated