Security (SecOps)
9.1 Overview
MCM centralizes findings from cloud, containers, source code, and hosts. The SecOps dashboard provides an aggregated overview and workflows across all connected accounts, with separate tabs, dashboards, and overviews for:
-
Findings
-
Audit Log Security Scanning
-
Agents
-
Execution History
-
Settings
All have their separate tab, dashboards, and overview
9.2 Supported Security Sources
| Cloud Security |
|---|
| AWS GuardDuty |
| Azure Defender |
| CloudTrail |
| Container Security |
|---|
| Docker Hub |
| ECR |
| GitHub Container Registry |
| Source Code Security |
|---|
| GitHub Repositories |
| Trivy SAST |
| Host Security |
|---|
| Ubuntu Hosts |
| Wazuh Agents |
9.3 Security Dashboard
Unified visibility into security findings by severity:
-
Total Findings
-
Critical Findings
-
High Findings
-
Medium Findings
-
Low Findings
Finding statuses: Open, In Progress, Resolved.
9.4 Findings
The findings we get are All accounts level, Search and filter: findings by Account, Provider, Severity, and Status. Table attributes include: Finding Name, Severity, Status, Type, Resource, and Detected Date.

9.5 Audit Log Security Scanning
CloudTrail and audit log analysis for connected accounts.
9.5.1 Overview Tab
-
Total Events — All audit events
-
Total Errors — Error events in period
-
Accounts — AWS accounts
-
Regions — AWS regions
Additional dashboards: Top Sources, Top Accounts, Top S3 Buckets, Top Regions, Events by Source over Time, Events by S3 Bucket over Time, Geolocation Map.


9.5.2 Events Tab
| Attribute | Description |
|---|---|
| Timestamp | Event date and time |
| AWS Source | Source service |
| Rule Description | Triggered rule description |
| Level | Severity level |
| Rule ID | Policy rule identifier |
| S3 Bucket | Associated S3 bucket |
Search and filter functionality is available:
-
AWS Source
-
Level
-
AWS Account ID
-
Date range filter

9.6 Agents
Security agent monitoring and threat detection. Agent dashboards include Overview and Events, with a dropdown to switch between monitoring modes:
-
Agent
-
Runtime Security
-
Network Security

9.6.1 Overview Tab
The cards and charts are the same across monitoring modes — only the values differ depending on the selected mode (Agent, Runtime Security, Network Security).
-
Total Alerts — All security events
-
Critical Alerts — Level 12 or above
-
Auth Failures — Authentication failures
-
Auth Successes — Authentication successes
Three charts are available for data analysis:
-
Top 10 Alert Level Evolution
-
Top 10 MITRE ATT&CKs
-
Top 5 Agents
-
Alerts Evolution — Top 5 Agents

9.6.2 Events Tab
-
Timestamp
-
Agent
-
Rule Description
-
Level
-
Rule ID
-
MITRE Technique

9.7 Trigger SecOps Job
SecOps jobs can be triggered on a schedule or manually. Click the Trigger SecOps Job button to run a manual scan. At the first time once the user adds the account with secops module, then after the account onboard successfully it will trigger secops job automatically.
9.7.1 Trigger SecOps Job by Schedular
First go to settings of Secops account specific to Secops job auto trigger you must enable both Audit Log Security Scanning and Secops Module. Here we can see the last secops job trigger date and time on screen left side of trigger discovery job button, for all Schedular and Manual discovery.

9.7.2 Trigger SecOps Job by Manual
SecOps jobs can be triggered on a schedule or manually. Click the Trigger SecOps Job button to run a manual scan. To trigger Secops job just click on Trigger Secops Job Button.

9.8 Execution History
Past SecOps scan runs and their results:
-
Execution Time, Status, Duration, Triggered By
-
Resources, Score, Findings, Critical count,Error.

9.9 Settings
SecOps module configuration includes:
-
Provider-specific SecOps scanning controls
-
Audit Log Security Scanning — Enable or disable
-
SecOps Module Status — Enable or disable per account
