See what is happening in your Active Directory and your Sophos protections.
VigilanceX collects security logs from your domain controllers, adds Sophos Central detections, and lets an AI agent qualify the alerts. One dashboard, one organization per tenant, per-user permissions.
Likely incidentConfidence 87%Reassessed severity HIGH
The 28 failed sign-ins on account j.moreau originate from a single IP address and target a privileged account. Correlated with a Sophos detection on SRV-FILES-01.
MITRE ATT&CK techniquesT1110T1078
Recommendation Reset the account password, block the source IP address and review sign-ins on DC-LAB-02.
Notification sent: e-mail + Telegram (EN)
Stylized mockup: all displayed data is fictional.
Less noise, more signal
Active Directory visibility
Sign-ins, lockouts, log clearing, sensitive accounts: security events from every domain controller are collected, searchable, and turned into alerts by a rules engine.
Correlated Sophos
Sophos Central detections and blocks (endpoints, servers, firewalls, e-mail) are correlated with the Active Directory activity of the same accounts, machines and IP addresses.
AI verdict
The AI agent reads the alert, queries tenant data read-only, enriches it with file, URL and IP reputation, then returns a structured verdict with evidence and recommendations.
From raw event to decision
Collection
Domain controller logs and Sophos Central detections, per tenant.
Rules
The rules engine, configurable per tenant, turns events into alerts.
Alert
Severity from LOW to CRITICAL, with context, accounts and machines involved.
AI analysis
Structured verdict: qualification, confidence, evidence, MITRE ATT&CK, recommendations.
Notification
E-mail and Telegram, per tenant, in the tenant's language.
Read-only, least privilege, controlled data
VigilanceX never writes to your sources. The installation kit uses a least-privilege service account: never an administrator account. Secrets are encrypted, data is segregated per tenant, retention and archiving are configurable.
See VigilanceX on your own scenarios
A guided demonstration with your use cases: one or more tenants, with or without Sophos Central, depending on your organization.
No public pricing: every deployment is scoped with you. Request a demonstration.
Request a demonstration