Pharos documentation
See the hazard before the ship does
Pharos is Cyber Threat Intelligence for Wazuh. It mirrors the Wazuh CTI corpus and keeps it searchable down to the package, and a read-only sidecar reports what a Wazuh fleet actually runs, so exposure is measured rather than guessed.
Search down to the package
Over 366,000 CVE records. Browse them by vendor, by product or by distro package name, and filter on severity, the CISA KEV catalog, exploit availability, source, date and, once a sensor reports, on what the fleet itself runs.
Sources that disagree, side by side
Over a dozen advisory sources each carry their own verdict on a CVE, and they disagree. Pharos shows every score instead of picking a winner, because the one that matters depends on what the fleet runs.
Advisory activity, as the sources tell it
Every CVE page carries a timeline of when the record was published, when each source last revised its verdict, and when it entered the KEV catalog. Every timestamp is the one its source published.
Watch it, and be told
Save any search as a watchlist, or watch a vendor or a package, and Pharos raises an advisory when a matching record changes. Advisories come from the catalog, so they are never billed.
A fleet, observed
One click from Wazuh Fleet enrols the deployment as a sensor, with nothing typed on a host. The sidecar is read-only and outbound-only, and what it reports lands in a triageable inbox, billed by the signal.
Investigate, by hand
Paste a domain, a URL, an IP address or a file hash and read the verdict against the indicator corpus. A person is not a sensor, so Investigate is free.
Where to go
- What is Pharos?, Sign in, The first search and The playground: the shape of the product, who can get in, the first ten minutes in the console, and the read-only demo.
- The corpus, Watchlists and advisories, Investigate and Sources: what a record carries, how to subscribe to a change, how to check one indicator by hand, and where the indicator corpus comes from.
- Install from Wazuh Fleet, How the sidecar works, The sidecar on the host and Fleet exposure: connecting a Wazuh deployment from Wazuh Fleet, what leaves the network and what never does, the host footprint, the network and the least-privilege login it needs, and what the fleet's own exposure looks like.
- The Signals inbox: where what the fleet sent lands, and how it is triaged.
- Signals, Notifications, Team and managers, Settings and Limits: the billable unit and the monthly limit, where advisories and platform events are delivered, who can do what, the workspace's own settings, and the request limits.
Part of the Wazuh Labs ecosystem.