Features

Everything you need to monitor, qualify, act

Every block is configurable per tenant. Default rules are provided and tunable; the AI agent runs on demand or automatically, based on severity.

Ingestion

Direct collection, least privilege

Collection runs directly from each domain controller using a ready-to-use installation kit. The kit uses a least-privilege service account: never an administrator account.

  • Ready-to-use kit, guided installation
  • Direct collection from each domain controller
  • Least-privilege service account
  • No administrator account required, at any step

Sophos Central

Detections and blocks, correlated with the directory

Each tenant is linked to its own Sophos Central account. VigilanceX pulls XDR/MDR detections (endpoints, servers, firewalls, e-mail depending on licenses) and blocks: malware cleaned, exploit stopped, website blocked, firewall threats, e-mail alerts.

  • Each tenant linked to its own Sophos Central account
  • XDR/MDR detections according to the tenant's licenses
  • Blocks reported: malware cleaned, exploit stopped, website blocked, firewall threats, e-mail alerts
  • Correlation with Active Directory activity of the same accounts, machines and IP addresses

AI analysis agent

A structured verdict, with evidence

On demand or automatically based on severity, the agent reads the alert or detection, queries tenant data read-only and enriches it with file, URL and IP reputation. It returns a structured verdict that the team can accept or challenge.

  • Qualification: likely incident, likely false positive, etc.
  • Confidence level and reassessed severity
  • Findings with evidence and MITRE ATT&CK techniques
  • Actionable recommendations; model provider chosen by the operator

Notifications

The right recipient, in the right language

Notifications are sent by e-mail and Telegram, configured per tenant and sent in the tenant's language. System events are notified as well, to avoid operational blind spots.

  • E-mail and Telegram, per tenant
  • Notification language specific to each tenant
  • System events: failed import, new source, failed Sophos connector, analysis completed

Storage and archives

Controlled retention, monthly archiving

Event retention is configured per tenant. Every month, data is archived into compressed files to local storage or S3-compatible storage. Restore and download are available directly from the interface.

  • Per-tenant configurable retention
  • Monthly archiving into compressed files
  • Local or S3-compatible storage
  • Restore and download from the interface

Operations

Built for the teams who run it

VigilanceX installs as containers and updates from an image registry, with built-in version checking. Authentication is centralized, the interface is fully bilingual FR/EN and offers a light or dark theme.

  • Container-based installation
  • Updates from an image registry, built-in version checking
  • Centralized authentication, per-user permissions
  • Bilingual FR/EN interface, light or dark theme

Want to see these features in real conditions?

The demonstration covers collection, rules, Sophos correlation and the AI agent verdict.

No public pricing: every deployment is scoped with you. Request a demonstration.

Request a demonstration
HostCitadel