Products/SOC Dashboard
SOC Dashboard

Your security operations, without the noise

Centralise your logs and events, detect real threats with an AI analysis engine and a rules engine you control, correlate multi-stage attacks, and run incidents to resolution. All in one dashboard, built into the XHack platform you already use.

Open the dashboard
Works with your stack
Real-time ingestion
Tenant-isolated

app.xhack.io / soc

XHack SOC Dashboard overview

Real time

Events land as they happen

18

Detection rule operators

MITRE

ATT&CK mapped, end to end

SLA

Tracked on every incident

What it does

A full security operations centre, on one screen

Ingest everything, detect what matters, correlate the multi-stage attacks and run every incident to closure. Here is the whole product at a glance.

Multi-source ingestion

Cloudflare, Wazuh, webhooks and a lightweight log wrapper, all feeding one normalised event stream.

Detection rules engine

Eighteen operators, nested AND/OR logic, thresholds and AI-generated rules from plain English.

Alert stacking

Repeat hits from the same source collapse into one alert with a count, instead of hundreds of duplicates.

Attack chain detection

Correlates alerts into multi-stage attacks mapped to the MITRE ATT&CK kill chain.

MITRE ATT&CK

Events and alerts auto-mapped to tactics and techniques for a shared language across the team.

Incident management

A structured workflow from new to closed, with every contributing alert and event attached.

SLA tracking

Per-severity response targets, monitored automatically, with breach alerts in-app and by email.

Tenant-isolated data

Your events never leave your tenant. Configurable retention, hard deletes and a full audit trail.

See it in action

Watch the SOC Dashboard at work

A short walkthrough of ingestion, detection and incident response in the live console.

youtube.com / XHack SOC Dashboard

XHack SOC Dashboard walkthrough

Click to play

AI at the core

An AI analyst on everything you collect

XHack does not just store logs and match patterns. An AI analysis engine reads what comes in and explains it, across every event, every attack chain, every incident, and even the detection rules you create.

AI analysed

Every event

Each event is read in context, classified by severity and mapped to a MITRE technique, with the AI writing out why in plain language rather than just flagging a match.

AI analysed

Every attack chain

The engine explains how correlated events form a chain, which kill-chain stages they cover and what the attacker is most likely trying to achieve.

AI analysed

Every incident

Incidents arrive with an AI summary of what happened across the attached evidence, so a responder opening one sees the whole story, not a pile of raw alerts.

AI analysed

Every rule you write

Describe what you want to catch and the AI drafts a complete detection rule. It routinely adds thresholds and suppression you did not ask for, so the rule is more robust than the sentence you gave it.

Just say what you want to detect, then hit Generate

No rule syntax to learn. Write the threat in your own words and the AI returns a complete rule. It often hardens the logic beyond what you described, so you get a rule that holds up in production, not a literal translation of your sentence.

You describe it

“Alert me when one IP hits more than 20 different URLs and keeps getting 404s in five minutes. That is someone scanning us.”

Rapid 404 scanning from a single source

Severity

High

Match

status_code equals 404

Group by

source_ip

Threshold

20 distinct paths within 5 minutes

Action

Create alert, map to Reconnaissance

The AI added on its own

Distinct-path counting so one URL refreshed 20 times will not trigger it

Suppression for /_next/ and static assets to keep out framework noise

Illustrative example. Every generated rule is yours to edit, test and activate before it goes live.

How logs get in

Feed it from everything, all at once

Four ingestion paths that can all run together. Whatever your infrastructure looks like, its security signal ends up in one normalised stream.

Cloudflare

Pull WAF blocks, firewall matches, bot detections and managed challenges straight from your zones. Add an API token and zone ID, and events flow in normalised automatically.

Wazuh

Connect your Wazuh manager to ingest alerts, file-integrity events, vulnerability detections and agent data. If you already run Wazuh, data flows within minutes.

Webhook forwarding

Build custom pipelines with n8n, Tines or any HTTP-capable tool. POST events to the XHack log API in a supported format and they are ingested immediately.

XHack log wrapper

A lightweight forwarder you deploy in your own environment to ship access logs, application events and authentication events directly to your SOC account.

soc / log sources

SOC Dashboard log sources and ingestion

Detection rules engine

Alert on your threat model, not someone else's

Full control over what fires. Build precise logic by hand, or describe it in plain English and let the AI write the rule for you to review.

soc / detection rules

SOC Dashboard detection rules engine

18 operators

Exact match, contains, starts with, regex, numeric comparisons, exists checks and every negated form.

Nested AND / OR

Group conditions into complex detection logic that matches real-world attack patterns, not single strings.

Threshold rules

Fire only when a condition is met N times in a window. Twenty scanner hits from one IP in five minutes, not one.

Framework-aware suppression

Exclude /_next/, /_nuxt/, /static/ and asset extensions so rules fire on attacks, not on page navigations.

AI-assisted generation

Describe what you want to catch in plain English and the AI writes the full rule, ready for review.

Review before it runs

Every generated rule arrives with conditions, severity and action laid out, so nothing goes live unseen.

Ships with detection out of the box

Pre-built rules cover the attacks you would write first anyway, so you have coverage from day one and tune from there.

SQL injection
XSS
Command injection
Path traversal
SSRF
SSTI
HTTP response splitting
Open redirect
Sensitive file probing
Web scanner detection
Admin panel brute force
Log4Shell
Rapid error scanning

soc / alerts

SOC Dashboard alert stacking

Cut through the noise

One alert, not a thousand

When the same rule fires for the same source inside a six-hour window, XHack stacks the events into one alert with a count badge instead of flooding your queue with duplicates.

  • A count badge shows how many events an alert contains, expandable to every individual event, timestamp and raw payload.

  • If a higher-severity event joins the stack, the alert severity escalates automatically.

  • Link a stack to an incident and every event comes with it, so no evidence is lost.

  • Remove an unrelated event from a stack to keep the investigation clean.

Attack chain detection

See the attack, not just the alerts

Individual alerts tell you what happened. Attack chains tell you what is happening, and where it is headed. XHack correlates related indicators into multi-stage attacks mapped to MITRE ATT&CK.

01

Reconnaissance

02

Initial Access

03

Execution

04

Persistence

05

Privilege Escalation

06

Lateral Movement

07

Exfiltration

soc / attack chains

SOC Dashboard attack chain detail
  • Continuous correlation

    The engine watches alerts and events across your environment for multi-stage patterns, not one-off hits.

  • Severity that reflects reach

    A chain spanning execution and exfiltration is classified differently from one showing only reconnaissance.

  • Configurable time window

    A chain forms when two or more stages appear from related indicators inside the window you set.

  • The higher-level view

    Follow sophisticated attacks that cross multiple events, systems and hours in a single picture.

Backed by a synchronised MITRE ATT&CK framework

Events and alerts are auto-mapped to tactics and techniques, giving your team a shared language and a direct link to MITRE documentation for every classified event. The same tactic mappings drive attack chain detection, deciding which kill chain stage each event belongs to.

Incident management

From detection to resolution, tracked

When events escalate into a confirmed incident, a structured workflow carries it to closure with every piece of evidence attached.

New
Investigating
Contained
Resolved
Closed

soc / incident

SOC Dashboard incident detail

Incidents are created manually or automatically by a rule. Each one carries a severity, an assignee, a status and a complete timeline of every alert, event and action taken. Link alerts and events at any time and the whole picture stays connected.

SLA response targets

Critical

4 hours

High

24 hours

Medium

72 hours

Low

168 hours

Open incidents are monitored against these targets automatically. A breach raises an in-app notification and an email alert. Targets are yours to configure.

Informed, never overwhelmed

  • Email digests are rate-limited to two per hour per tenant, for only the severities you choose.

  • Incident and alert notifications are configured independently, so different people carry different noise levels.

  • In-app notifications appear instantly for new incidents and SLA breaches, each linking straight to the relevant page.

Your data, under your control

  • Events are processed in your isolated tenant and are never visible to another organisation.

  • You set retention periods and manage data by date range or severity, individually or in bulk.

  • Deletions are hard deletes that free your plan quota immediately, and every one is written to the audit trail.

The rest of the console

Everything else the SOC gives you

Agents, reports, suppressions, webhooks, threat intelligence and role-based settings, all in the same workspace.

SOC agents

SOC agents

Deploy and configure the agents that forward and enrich data from across your estate.

Reports

Reports

Generate shareable security reports for leadership, auditors and your own retrospectives.

Suppressions

Suppressions

Tune out the known-good so real signal stays loud, with every suppression logged.

Webhooks

Webhooks

Wire the SOC into the rest of your tooling with inbound and outbound webhooks.

Threat intelligence

Threat intelligence

A synchronised MITRE ATT&CK reference and intel feeds behind every classified event.

Settings & roles

Settings & roles

Role-based access shared with the rest of your XHack platform account.

Questions

The SOC Dashboard, answered

No. The SOC Dashboard is built to sit alongside what you already run. Cloudflare, Wazuh, your own log pipelines and any HTTP-capable automation tool can all feed it at the same time, and it normalises everything into one event stream for analysis.

In real time. Every ingestion method delivers data as it happens, so the dashboard always reflects the current state of your environment rather than a batch from an hour ago.

That is exactly what the platform is designed to prevent. Alert stacking collapses repeat hits from the same source into a single alert with a count. Framework-aware suppression keeps rules from firing on ordinary page loads and static assets. Email digests are rate-limited to two per hour per tenant, and you choose which severities reach which people.

Yes. The rules engine gives you eighteen operators, nested AND/OR groups and threshold rules that fire only after a condition repeats within a time window. If you would rather describe what you want in plain English, the AI generator writes the complete rule for you to review before it goes live.

You promote it to an incident, manually or automatically from a rule. Each incident carries a severity, an assignee, a status that moves from new through investigating, contained and resolved to closed, and a timeline of every alert and event attached to it. SLA targets per severity are tracked automatically, and breaches raise in-app and email alerts.

Events are processed inside your own tenant and are never visible to any other organisation. You set retention periods, and when you delete events, alerts or incidents they are hard deleted. Deletion frees your plan quota immediately, and every deletion is written to the audit trail.

It is part of the XHack company platform and runs inside the same multi-tenant architecture as everything else. Your team reaches it through the same account with the same role-based permissions, so security operations are a natural part of how you already use XHack.

Stand up your SOC today

Connect a source, watch events land in real time, and let the engine surface what actually matters. Start in the dashboard or book a walkthrough with our team.