Skip to main content

Pharos documentation

See the hazard before the ship does

Pharos is Cyber Threat Intelligence for Wazuh. It mirrors the Wazuh CTI corpus and keeps it searchable down to the package, and a read-only sidecar reports what a Wazuh fleet actually runs, so exposure is measured rather than guessed.

Install the sidecar    What is Pharos?

Search down to the package

Over 366,000 CVE records, with vendors, products and packages as first-class objects. Filters reach severity, EPSS, the CISA KEV catalog and exploit availability.

Sources that disagree, side by side

Eight sources each carry their own verdict on a CVE, and they disagree. Pharos shows every score instead of picking a winner, because the one that matters depends on what the fleet runs.

A revision timeline

Upstream publishes every change to a record as a versioned revision. Pharos rebuilds the sequence as a timeline: what changed, when, and which source changed it.

A fleet, observed

One command enrols a Wazuh node as a sensor. The sidecar is read-only and outbound-only, and what it reports lands in a triageable inbox, billed by the signal.

WazuhPart of the Wazuh Labs ecosystem.