Skip to main content

What is Pharos?

Pharos is Cyber Threat Intelligence for Wazuh, operated as a Wazuh Labs service. It keeps a live mirror of the corpus, the CVE catalog published by Wazuh CTI, and builds the product around it: search that reaches vendors, products and packages, a CVE page that shows every source's own verdict and the advisory activity behind it, watchlists that raise an advisory when a watched record changes, and a read-only sidecar that reports what a Wazuh fleet actually runs. The corpus itself stays free and public at cti.wazuh.com. Pharos is the product layer on top.

The corpus, searchable​

The mirror holds over 366,000 CVE records and checks upstream's change stream every hour. Upstream is Wazuh CTI rather than NVD, and it publishes in batches rather than continuously, so a record reaches Pharos once Wazuh CTI carries it (see How fresh the mirror is). Vendors, products and packages are browsable in their own right and each of them filters the CVE list, so libssl3 is a package to open rather than a word to hope for in prose. Each record carries the verdict of every source that has scored it, side by side, and an advisory activity timeline of when each of those sources last spoke. Details in The corpus.

Any search is also a subscription in waiting. Save it as a watchlist, or press Watch on a vendor or a package, and Pharos raises an advisory when a matching record changes: a new CVE that fits, a revised score, a published exploit, a CISA KEV listing. Advisories come from the catalog rather than from the fleet, and they are never billed.

Indicators, and Investigate​

Beside the CVE catalog, Pharos carries a corpus of indicators: file hashes, addresses and domains that sources have tied to malicious activity. The values a connected fleet reports are checked against it, and a person can check one by hand on the Investigate page, by pasting a domain, a URL, an IP address or a file hash and reading the verdict. Defanged input is understood, so a value copied out of a ticket needs no cleaning up first. Investigate is free, and it keeps answering even when a fleet has stopped at its monthly limit.

A fleet, observed​

The sidecar is a read-only connector that reaches the Wazuh indexer over HTTPS. Over an outbound connection it reports the packages the fleet runs, the vulnerability findings Wazuh has already made, an agent count and roster, the alert values worth checking against the corpus, and the file hashes to check against the indicators. It is not a Wazuh agent: nothing is installed into Wazuh and nothing writes to the customer's cluster. Credentials stay in a root-only file on the customer's host and are never sent to Pharos.

The sidecar is installed from Wazuh Fleet. On the Managers page, connecting a Fleet environment has Fleet install and bind the sidecar on every host in it, with nobody typing anything on a host and no Wazuh credential leaving the network. Managers appear in Pharos over the next few minutes as their hosts check in. The flow is in Install the sidecar from Wazuh Fleet.

What the fleet reports lands in the Signals inbox in the console, where each entry can be triaged. Advisories from watchlists land on their own page, Advisories, next to it: one page for what the sensors sent, one for what the watchlists raised.

Priced by the signal​

A signal is a message from a sensor that Pharos checked, and it comes in three kinds: an alert whose values were looked up, a vulnerable package on one agent, and a file hash that matched a known indicator. Connecting a manager is free. There is no per-manager fee and no licence, and the bill follows what the connected fleet actually sends. A monthly limit, expressed in signals, caps the spend, and stopping at the limit is the default. The unit and the limit are defined in Signals.

Part of the Wazuh Labs ecosystem​

Sign-in is Wazuh ID, the identity shared by every Wazuh Labs service: one account, one login, valid across the ecosystem. An organisation is the group of members a company shares in Wazuh ID, and each organisation gets one Pharos workspace, created at first sign-in. The Hub at hub.wazuh.com is the front door of the ecosystem, where an organisation activates services and manages its account. How sign-in works, and who can get in, is in Sign in.

What Pharos is not​

  • Not a scanner. Pharos never touches a customer host. Inventory arrives from the Wazuh deployment the customer already runs, read by a sidecar that only reads.
  • Not a replacement for Wazuh CTI. The corpus stays free and public. Pharos is the product layer: the search, the fleet awareness and the workflow around them.
  • Not a threat intelligence platform. No STIX or TAXII broker and no adversary graph. Triage of security alerts and adversary attribution are Mobius. Dark web monitoring and credential exposure are Umbra. Cloud posture is Argus. AI usage governance is Lumen.