Skip to main content

Pharos documentation

See the hazard before the ship does

Pharos is Cyber Threat Intelligence for Wazuh. It mirrors the Wazuh CTI corpus and keeps it searchable down to the package, and a read-only sidecar reports what a Wazuh fleet actually runs, so exposure is measured rather than guessed.

Install the sidecar    What is Pharos?

Search down to the package

Over 366,000 CVE records. Browse them by vendor, by product or by distro package name, and filter on severity, the CISA KEV catalog, exploit availability, source, date and, once a sensor reports, on what the fleet itself runs.

Sources that disagree, side by side

Over a dozen advisory sources each carry their own verdict on a CVE, and they disagree. Pharos shows every score instead of picking a winner, because the one that matters depends on what the fleet runs.

Advisory activity, as the sources tell it

Every CVE page carries a timeline of when the record was published, when each source last revised its verdict, and when it entered the KEV catalog. Every timestamp is the one its source published.

Watch it, and be told

Save any search as a watchlist, or watch a vendor or a package, and Pharos raises an advisory when a matching record changes. Advisories come from the catalog, so they are never billed.

A fleet, observed

One click from Wazuh Fleet enrols the deployment as a sensor, with nothing typed on a host. The sidecar is read-only and outbound-only, and what it reports lands in a triageable inbox, billed by the signal.

Investigate, by hand

Paste a domain, a URL, an IP address or a file hash and read the verdict against the indicator corpus. A person is not a sensor, so Investigate is free.

Where to go​

WazuhPart of the Wazuh Labs ecosystem.