Skip to main content

What is Pharos?

Pharos is Cyber Threat Intelligence for Wazuh, operated as a Wazuh Labs service. It keeps a live mirror of the corpus, the CVE catalog published by Wazuh CTI, and builds the product around it: search that reaches vendors, products and packages, a CVE page that shows every source's own verdict, a revision timeline, and a read-only sidecar that reports what a Wazuh fleet actually runs. The corpus itself stays free and public at cti.wazuh.com. Pharos is the product layer on top.

The corpus, searchable

The mirror holds over 366,000 CVE records and follows upstream's change stream every hour. Vendors, products and packages are first-class objects with their own pages, so a search for libssl3 lands on the package rather than on prose mentions of it. Each record carries the verdict of every source that has ruled on it, with EPSS, CISA KEV membership and exploit availability alongside, and a revision timeline of what changed and when. Details in The corpus.

A fleet, observed

The sidecar is a read-only connector installed on the Wazuh node with one command. Over an outbound connection it reports the packages the fleet runs, the vulnerability findings Wazuh has already made, and the alert values worth checking against the corpus. Nothing is installed on a manager and nothing writes to the customer's cluster.

What the fleet reports lands in the Signals inbox in the console, where each entry can be triaged, assigned and tagged. Install steps in Install the sidecar.

Priced by the signal

A signal is a message from a sensor that Pharos checked. Connecting a manager is free. There is no per-manager fee and no licence, and the bill follows what the connected fleet actually sends. A monthly limit, expressed in signals, caps the spend, and stopping at the limit is the default. The unit and the limit are defined in Signals.

Part of the Wazuh Labs ecosystem

Sign-in is Wazuh ID, the identity shared by every Wazuh Labs service: one account, one login, valid across the ecosystem. An organisation is the group of members a company shares in Wazuh ID, and each organisation gets one Pharos tenant, created at first sign-in. The Hub at hub.wazuh.com is the front door of the ecosystem, where an organisation activates services and manages its account. How sign-in works is in Sign in.

What Pharos is not

  • Not a scanner. Pharos never touches a customer host. Inventory arrives from the Wazuh deployment the customer already runs, read by a sidecar that only reads.
  • Not a replacement for Wazuh CTI. The corpus stays free and public. Pharos is the product layer: the search, the fleet awareness and the workflow around them.
  • Not a threat intelligence platform. No STIX or TAXII broker and no adversary graph. Alert triage and adversary attribution are Mobius. Dark web monitoring and credential exposure are Umbra. Cloud posture is Argus. AI usage governance is Lumen.