Kybit Nexus for Wazuh
Wazuh finds the alerts; Kybit Nexus investigates them. Plain answers on what Kybit Nexus adds on top of a Wazuh deployment, and what it leaves exactly where it is.
Can Kybit Nexus triage Wazuh alerts?
Yes. Wazuh is one of the alert sources Kybit Nexus has a connector for today: Kybit Nexus polls the Wazuh alerts, gathers the context an analyst would look up and writes a reasoned assessment. A full triage takes about 16 seconds on Kybit hardware, and a deterministic policy engine, not the model, decides what may close.
What does Kybit Nexus add on top of Wazuh?
Wazuh detects, and Kybit Nexus investigates what it detected. For each alert Kybit Nexus looks up the asset's tier in the CMDB, the user's roles in the directory, open findings from the vulnerability scanner and the indicator's reputation in threat intelligence, then proposes a verdict and a response for a person to decide on.
The sources and response tools it has connectors for today:
- Alerts
- Wazuh, IBM QRadar, Microsoft Defender, CrowdStrike Falcon, Splunk, Progress Flowmon, GREYCORTEX Mendel, AlienVault OSSIM, Microsoft Entra sign-ins, Ingest API (any source)
- Vulnerabilities
- Findings API (any scanner)
- Identity
- Microsoft Entra ID, Active Directory
- Assets
- NetBox
- Threat intel
- MISP, VirusTotal, AbuseIPDB, GreyNoise, urlscan.io
- Response
- FortiGate, OPNsense, VyOS, SentinelOne, Microsoft Entra ID, Active Directory
Does Kybit Nexus replace Wazuh?
No. Wazuh stays the SIEM and its detection rules stay where they are. Kybit Nexus reads the Wazuh alerts, adds what an analyst would look up and hands back a decision; nothing is migrated.
Can Kybit Nexus act on a Wazuh alert?
Kybit Nexus proposes the response and acts through the tools in your stack, and every destructive action waits for a person to approve it. Its response connectors today are FortiGate, OPNsense, VyOS, SentinelOne, Microsoft Entra ID and Active Directory, for isolating a host, disabling an account or blocking an address.
Where do Wazuh alerts go when Kybit Nexus triages them?
In Kybit Nexus that depends on the mode chosen for the tenant. In local mode the model runs on Kybit hardware and nothing leaves. In hybrid mode, the default, a second model in the EU sees only a pseudonymised summary, and raw events never leave. In hosted mode the full evidence goes to an EU-hosted model after an explicit, recorded opt-in.
Read what leaves your estate, data class by data classDoes Kybit Nexus help a Wazuh deployment with NIS2?
Kybit Nexus adds the record NIS2 asks for around each incident. It records the incident timeline, decisions and approvals on an append-only trace and exports them for reporting, while Wazuh keeps providing the detections.
Who runs Wazuh and Kybit Nexus together?
Kybit s.r.o. builds and runs Wazuh deployments with round-the-clock monitoring, and Kybit's own SOC and MDR service runs on Kybit Nexus. Kybit Nexus also works on top of a Wazuh deployment you run yourself.
Wazuh implementation and monitoring at kybit.czRequest a demo to see Kybit Nexus triage your own Wazuh alerts.