SIEM+EDR+SOAR+NGFW
SIEM+EDR+SOAR+NGFW
Xcloak Security Suite is an open-core security platform that integrates multiple security functions into a single system. It combines network firewall capabilities, security information and event management, endpoint detection and response, security orchestration and automated response, identity threat detection and response, and mobile device management. The platform uses one agent to collect data, one backend for processing, and one dashboard for visualization. It is designed to run on the user’s own infrastructure. The platform groups features by the tasks an analyst performs: detection, response, investigation, risk management, identity monitoring, and governance. Detection capabilities include rule based threat detection, behavior based attack detection, malware and traffic scanning, as well as alerts for compromised credentials, impossible travel, and brute force attempts. Response features include automated playbooks, the ability to isolate a host or kill a process remotely, and human approval steps for destructive actions. Investigation tools offer search across all logs, case management with timelines, and AI assisted alert triage. Risk management provides an organization wide risk score, compliance tracking, and vulnerability prioritization. Identity monitoring enriches alerts with Active Directory context. Typical workflow begins when an agent detects a potential issue. The detection engine checks the event against threat intelligence, correlates related events, and opens an incident. Automated response actions then fire based on predefined playbooks. The platform is built with Go and Next.js and is available as open source software. It is intended for security teams that want to reduce the complexity of managing separate tools for network protection, log monitoring, endpoint defense, and automated response.