MCMMCMBy Revdau
Enterprise User Guide

Security (SecOps)

9.1 Overview

MCM centralizes findings from cloud, containers, source code, and hosts. The SecOps dashboard provides an aggregated overview and workflows across all connected accounts, with separate tabs, dashboards, and overviews for:

  • Findings

  • Audit Log Security Scanning

  • Agents

  • Execution History

  • Settings

All have their separate tab, dashboards, and overview

9.2 Supported Security Sources

Cloud Security
AWS GuardDuty
Azure Defender
CloudTrail
Container Security
Docker Hub
ECR
GitHub Container Registry
Source Code Security
GitHub Repositories
Trivy SAST
Host Security
Ubuntu Hosts
Wazuh Agents

9.3 Security Dashboard

Unified visibility into security findings by severity:

  • Total Findings

  • Critical Findings

  • High Findings

  • Medium Findings

  • Low Findings

Finding statuses: Open, In Progress, Resolved.

9.4 Findings

The findings we get are All accounts level, Search and filter: findings by Account, Provider, Severity, and Status. Table attributes include: Finding Name, Severity, Status, Type, Resource, and Detected Date.

9.5 Audit Log Security Scanning

CloudTrail and audit log analysis for connected accounts.

9.5.1 Overview Tab

  • Total Events — All audit events

  • Total Errors — Error events in period

  • Accounts — AWS accounts

  • Regions — AWS regions

Additional dashboards: Top Sources, Top Accounts, Top S3 Buckets, Top Regions, Events by Source over Time, Events by S3 Bucket over Time, Geolocation Map.

9.5.2 Events Tab

AttributeDescription
TimestampEvent date and time
AWS SourceSource service
Rule DescriptionTriggered rule description
LevelSeverity level
Rule IDPolicy rule identifier
S3 BucketAssociated S3 bucket

Search and filter functionality is available:

  • AWS Source

  • Level

  • AWS Account ID

  • Date range filter

9.6 Agents

Security agent monitoring and threat detection. Agent dashboards include Overview and Events, with a dropdown to switch between monitoring modes:

  • Agent

  • Runtime Security

  • Network Security

9.6.1 Overview Tab

The cards and charts are the same across monitoring modes — only the values differ depending on the selected mode (Agent, Runtime Security, Network Security).

  • Total Alerts — All security events

  • Critical Alerts — Level 12 or above

  • Auth Failures — Authentication failures

  • Auth Successes — Authentication successes

Three charts are available for data analysis:

  • Top 10 Alert Level Evolution

  • Top 10 MITRE ATT&CKs

  • Top 5 Agents

  • Alerts Evolution — Top 5 Agents

9.6.2 Events Tab

  • Timestamp

  • Agent

  • Rule Description

  • Level

  • Rule ID

  • MITRE Technique

9.7 Trigger SecOps Job

SecOps jobs can be triggered on a schedule or manually. Click the Trigger SecOps Job button to run a manual scan. At the first time once the user adds the account with secops module, then after the account onboard successfully it will trigger secops job automatically.

9.7.1 Trigger SecOps Job by Schedular

First go to settings of Secops account specific to Secops job auto trigger you must enable both Audit Log Security Scanning and Secops Module. Here we can see the last secops job trigger date and time on screen left side of trigger discovery job button, for all Schedular and Manual discovery.

9.7.2 Trigger SecOps Job by Manual

SecOps jobs can be triggered on a schedule or manually. Click the Trigger SecOps Job button to run a manual scan. To trigger Secops job just click on Trigger Secops Job Button.

9.8 Execution History

Past SecOps scan runs and their results:

  • Execution Time, Status, Duration, Triggered By

  • Resources, Score, Findings, Critical count,Error.

9.9 Settings

SecOps module configuration includes:

  • Provider-specific SecOps scanning controls

  • Audit Log Security Scanning — Enable or disable

  • SecOps Module Status — Enable or disable per account

On this page