The Signals inbox
The Signals inbox is what the fleet's sensors sent and Pharos checked, and it is what the bill is made of: every row is a billed signal, as defined in Signals. What a watchlist reported is an advisory, and it has its own page, Advisories, described in Watchlists and advisories. The two are never listed or counted together, because one is what happened in the fleet and the other is what changed in the catalog.
Two kinds of signal
| Kind | One row is | Where it comes from |
|---|---|---|
| Indicator match | One value from a manager's alert stream that matched the indicator corpus, with how often it was seen | The sidecar reads the alert values described in How the sidecar works and Pharos checks them |
| Vulnerable package | One package on one agent that the agent's own Wazuh reported as vulnerable, with all of its CVEs inside it | The findings Wazuh's vulnerability detector already made, reported hourly |
A finding is grouped by agent and package rather than by CVE on purpose. One kernel image flagged for forty CVEs is one row, because one upgrade clears the group. The row says how many CVEs it holds and opens onto them, worst first.
Reading a row
| Column | What it shows |
|---|---|
| Severity | For a finding, the worst of its CVEs. For an indicator match, a score built from the indicator's class, its confidence and how many of the fleet's agents touched it |
| What | The package, or the indicator value |
| What we checked | For a finding, how many CVEs and the installed version, with the chip coloured when at least one CVE is in the CISA KEV catalog. For an indicator, its type and why it matched |
| Where | The kind, the manager and the agent. Both names are buttons that filter the inbox down to them |
| Status | One of the five statuses below |
| First seen | When the finding was first reported, or the indicator first observed |
The search box above the table takes free text and scoped terms: manager:
or agent: narrows to one deployment or one host, and a package name, a CVE
identifier or an indicator value narrows to that. Suggestions appear as
terms are typed, each with a count, and every chosen term becomes a chip. Chips combine.
Beside it sit a status select, a kind select and, for indicator
matches, an indicator type select, plus a column picker.
Statuses and triage
Every signal carries one of five statuses: New, Triaged, Risk accepted, Resolved and False positive. Any status can be set from any other. There is no forced order, because triage is a judgement and the inbox records it rather than enforcing it. Selecting rows brings up a bar with three bulk actions, Triaged, Risk accepted and Resolved, and each open row offers every status it is not already in. Setting a status on a finding moves the whole group, every CVE under that agent and package. Advisories carry the same five statuses and the same bulk bar.
What a row opens into
A row opens under itself rather than beside the table, because a finding is a group and its CVEs belong inside it.
A vulnerable package opens onto the installed package and version, the agent and its operating system, when it was first reported and when it was last confirmed, then its CVEs worst first, each with its severity, a KEV or exploit chip where either applies, and a link to the record on the Vulnerabilities page.
An indicator match opens onto five cards:
- Where it fired: the value, the manager, the agent, the alert field it was observed in, the Wazuh rule that produced the alert, when it was first and last observed, and how many times.
- Elsewhere in the fleet: how many of the fleet's agents have touched the same value, and the arithmetic behind the severity: points for the indicator's class, its confidence and its spread across the fleet, with the thresholds stated.
- Across the Pharos network: how many sensors in how many organisations have seen this indicator, anonymously. When too few organisations have reported it for a count to stay anonymous, the card says so and shows no figure.
- About the indicator: its class, malware family and target brand where known, its confidence and how many independent sources corroborate it.
- Is this wrong?: report a false positive with a reason, our own infrastructure, a shared hosting provider, a legitimate service, stale data or something else, and optionally add the value to the workspace's allowlist so that no sensor in the fleet fires on it again. That is local and immediate.
An Investigate this indicator link sends the value to Investigate for a fresh lookup.
An indicator match is not a vulnerability. It is evidence that something in the fleet talked to a known bad domain, address, URL or file, and the severity is about how bad the indicator is and how far it has spread across the estate, not about a CVE.
Where the counts are
The Overview shows Open signals and Open advisories as two figures that are never added together, each with how many are new. Here, "open" means new or triaged. The Billing page traces the month's signals back to the manager that produced them, by kind and by day. The inbox is where each one is read and dispositioned.