DHRUVADHRUVA · AI SOC on Wazuh · Live

An AI SOC that proves
its calls.

DHRUVA runs on top of Wazuh and does the analyst's first pass for you. It triages every alert in context, auto-closes the noise, and responds in minutes. Self-hosted, so nothing leaves your network.

92% liveTriage confidence
76% liveFalse positives auto-closed
4 min liveMedian response
DHRUVA · triage stream live ●
source wazuh-alerts-* 8,412 / 24h
enrich asset · identity · TI · baseline +9 ctx
5503 vuln scanner, known noise FP · auto-closed
Escalation · analyst review
Impossible travel on m.chen. Confidence 88 percent. Waiting for an analyst.
ConfirmInvestigateClose
5712 SSH brute · 77.91.x.x TP · escalated
verdict reasoning attached grounded ✓
auto-triage92% confidence · MITRE mapped
WazuhRuns as a layer on the SIEM you own
3Editions, Community free forever
28Shipped components, on the box
100%Self-hosted, your data stays yours
01 · Why a new layer on Wazuh

Compound intelligence. Open stack. Your infrastructure.

Wazuh gives you the SIEM. DHRUVA gives you the SOC running on top of it. AI triage, rule tuning that actually ships, hypothesis-driven hunting, and natural language investigation. All closed-loop, all on infrastructure you own.

01

Closed loop

It gets smarter every cycle.

Every override becomes a learning signal. Every approved proposal reduces the false-positive rate. Every cycle ships a smarter SOC than the last one.

02

Self-hosted

Your data never leaves.

Runs on your Linux box next to Wazuh. Your alerts, your data, your LLM keys. No SaaS lock-in and no telemetry phoning home.

03

Org-level scale

One platform, many tenants.

Fernet-encrypted isolation for subsidiaries, business units, or dev, staging and prod. Per-environment LLM configs. Cost tracking and audit per tenant.

02 · Architecture

Three layers. One closed loop.

Context feeds action. Action writes decisions. Decisions feed the feedback loop. The feedback loop rewrites the rules. Guidance bounds all of it.

01Context layer. Wazuh alerts, enriched with asset, identity, threat intel and behavioral baselines.
02Action layer. Triage agent writes a verdict. Detection agent proposes rule changes. Feedback loop rewrites them.
03Guidance layer. Risk criteria, escalation logic, playbooks and the knowledge base bound every call.
Closed loop · every cycle compounds running ●
01 ALERTS8,412/min Wazuh SIEM
02 ENRICH+9 context asset · identity · TI · baseline
03 TRIAGEClaude verdict · confidence · reasoning
04 DECIDEauto Postgres ledger
05 REVIEWanalyst overrides become signal
06 FEEDBACK4h cycle FP patterns · missed threats
07 PROPOSErule diff XML plus MITRE mapping
08 DEPLOYapproved Wazuh API · effectiveness tracked
deploy to Wazuhself-improving detection
03 · What ships

Every feature. On the box.

28 components across 6 domains. No phase 2 marketing, no roadmap coupons. If it is in the datasheet, it is in the tarball.

Context layer
Alert enrichment pipeline
Asset, identity, TI, historical, behavioral baselines, time context
Live threat intelligence
10 feeds: AbuseIPDB, OTX, VirusTotal, CISA KEV, EPSS, ThreatFox
Behavioral baselines
30-day per agent, IP and user. Z-score anomaly flags at 2.5 sigma
Risk scoring
Composite 0 to 100 with multiplicative boosters
Action layer
AI triage agent
Claude. Structured verdict, confidence, reasoning, MITRE mapping
Detection engineering agent
Proposes Wazuh rule changes with FP-reduction math. Human approves
Threat hunt agent
Hypothesis-driven hunts against MITRE coverage gaps, 6h cycle
Natural language SIEM
Ask in English. Two-pass Claude plans then synthesizes
SOAR, playbooks
Auto-containment with approval workflow and rollback
Active response, 9 actions
Block IP, isolate host, kill process, quarantine file, verify
Guidance layer
Playbook engine
YAML playbooks auto-selected by rule group, injected into triage
Risk criteria
Asset tiers, user risk profiles, MITRE priorities, your policy
Escalation logic
Auto-close conditions, always-escalate triggers, SLA targets
Knowledge base, FTS5
Analyst notes and learnings, injected into agent prompts
Feedback loop
FP pattern detection
Rules with recurring false positives surfaced every 4 hours
Rule tuning auto-actions
threshold_raised, baselined, monitoring, auto_tuned
Override analysis
Human vs AI disagreements classified into learning signals
Effectiveness tracking
Pre and post FP-rate comparison, marks proposals effective
Case management
Incident grouping
4-rule deterministic engine, 30-min window, MITRE tactic aware
L1 / L2 / L3 workflow
Assignment, timeline, merge, SLA enforcement
MTTD / MTTR / MTTA
Shift-based, SLA trends, analyst utilization, workload alerts
Ticketing, bidirectional
Jira, ServiceNow, PagerDuty, webhook ingest and sync
Platform
Multi-tenancy
Fernet-encrypted per-tenant config, client-scoped queries, MSSP admin
Multi-LLM providers
Anthropic, OpenAI, Groq, Ollama, failover chains, cost tracking
Real-time webhook ingest
1 to 3s latency, HMAC-SHA256, IP allowlist, idempotency
Alert anonymization
Strip client identifiers before the LLM, deterministic tokens
RBAC, 4 roles plus tab ACL
admin, senior_analyst, analyst, read_only, rate limits
Audit trail
Actor, action, target, IP. Compliance-ready explainability
04 · Proof, not adjectives

Anyone can claim. We cite.

These are production numbers from a live DHRUVA deployment, measured over a 7-day window. Not a lab benchmark. If we cannot show the work, we do not print the number.

Footnotes · sources of record
1Metrics measured on one live DHRUVA deployment over a 7-day window, not a synthetic benchmark. Your numbers will vary with alert mix and tuning.
2Self-hosted design. Alerts, data and LLM keys stay on your infrastructure. No telemetry home.
MetricLive
Triage confidence
92%Measured on one live DHRUVA deployment, 7-day window. Not a lab benchmark.
False positives auto-closed
76%Noise your analysts never had to touch, counted from real alert volume.
Median response
4 minFrom alert to a triaged, actioned verdict on one live deployment, 7-day window.
05 · What others do not have

Six things most AI SOC platforms do not actually ship.

Graded by capability, not brand. The industry uses these words in datasheets. We ship them in the tarball.

01

AI-native triage

Core architecture, not a bolted-on copilot. Every alert gets reasoned context with behavioral anomaly signals.

02

Closed-loop detection

AI proposes rule changes from triage outcomes. Auto-tunes per-rule confidence thresholds. Self-improving.

03

Natural language SIEM

Full English to OpenSearch to synthesis pipeline with source routing. Beyond KQL copilots.

04

CVE remediation with verify

From CVE to fix command to remote execution to 3x syscollector verification, in one flow.

05

Behavioral baseline anomalies

Z-score flags on every alert, built into enrichment. Not a separate UBA bolt-on.

06

Rule-tuning auto-actions

The feedback loop raises thresholds, baselines noisy rules and tracks effectiveness on its own.

06 · Editions

Three tiers. Plus partners.

Community free forever. Team where mid-market lands. Enterprise for mature orgs. All self-hosted, all with unlimited agents.

Freeforever
Free

Community

AI triage, enrichment, MITRE heatmap

AI triage7 TI feeds5 users
$999/mo
Default

Team

Your Wazuh, but actually working

Detection AgentNL SIEM25 users
$2,999/mo · annual
Annual

Enterprise

Full autonomous SOC

Threat huntSOARMulti-tenant
Start where it makes sense

Download DHRUVA. Or book an expert.

Community is free forever. Self-host and start triaging today. Or have Prathamesh look at your Wazuh first with a Noise Teardown, a written one-pager in 24 hours.