Everything you need to monitor, qualify, act
Every block is configurable per tenant. Default rules are provided and tunable; the AI agent runs on demand or automatically, based on severity.
Active Directory
Security logs, finally usable
VigilanceX collects security logs from your domain controllers: successful and failed sign-ins, account lockouts, log clearing, changes affecting sensitive accounts. The Events page provides full-text search across all collected data.
- Events page with search across all collected logs
- Alerts page powered by a per-tenant configurable rules engine
- Default rules provided, tunable without development
- Silent server monitoring: a source that stops reporting is flagged
Ingestion
Direct collection, least privilege
Collection runs directly from each domain controller using a ready-to-use installation kit. The kit uses a least-privilege service account: never an administrator account.
- Ready-to-use kit, guided installation
- Direct collection from each domain controller
- Least-privilege service account
- No administrator account required, at any step
Sophos Central
Detections and blocks, correlated with the directory
Each tenant is linked to its own Sophos Central account. VigilanceX pulls XDR/MDR detections (endpoints, servers, firewalls, e-mail depending on licenses) and blocks: malware cleaned, exploit stopped, website blocked, firewall threats, e-mail alerts.
- Each tenant linked to its own Sophos Central account
- XDR/MDR detections according to the tenant's licenses
- Blocks reported: malware cleaned, exploit stopped, website blocked, firewall threats, e-mail alerts
- Correlation with Active Directory activity of the same accounts, machines and IP addresses
AI analysis agent
A structured verdict, with evidence
On demand or automatically based on severity, the agent reads the alert or detection, queries tenant data read-only and enriches it with file, URL and IP reputation. It returns a structured verdict that the team can accept or challenge.
- Qualification: likely incident, likely false positive, etc.
- Confidence level and reassessed severity
- Findings with evidence and MITRE ATT&CK techniques
- Actionable recommendations; model provider chosen by the operator
Notifications
The right recipient, in the right language
Notifications are sent by e-mail and Telegram, configured per tenant and sent in the tenant's language. System events are notified as well, to avoid operational blind spots.
- E-mail and Telegram, per tenant
- Notification language specific to each tenant
- System events: failed import, new source, failed Sophos connector, analysis completed
Storage and archives
Controlled retention, monthly archiving
Event retention is configured per tenant. Every month, data is archived into compressed files to local storage or S3-compatible storage. Restore and download are available directly from the interface.
- Per-tenant configurable retention
- Monthly archiving into compressed files
- Local or S3-compatible storage
- Restore and download from the interface
Operations
Built for the teams who run it
VigilanceX installs as containers and updates from an image registry, with built-in version checking. Authentication is centralized, the interface is fully bilingual FR/EN and offers a light or dark theme.
- Container-based installation
- Updates from an image registry, built-in version checking
- Centralized authentication, per-user permissions
- Bilingual FR/EN interface, light or dark theme
Want to see these features in real conditions?
The demonstration covers collection, rules, Sophos correlation and the AI agent verdict.
No public pricing: every deployment is scoped with you. Request a demonstration.
Request a demonstration