ITWISEOn-premises SIEM · ISO 27001 & TISAX evidence
Collect, protect and prove your logs at audit time.
SEC-WISE collects server, network and Microsoft 365 logs on your own server, stores them in an immutable archive, explains suspicious activity in plain language and prepares a signed evidence package for your auditor.
COLLECT · PROTECT · DETECT · RESPOND · PROVE
Örnek Sanayi A.Ş.
Servisler hazır| Uyarı / ilgili cihaz | Önem | Son görülme | |
|---|---|---|---|
| Art arda yanlış parolayla giriş denendiSRV-DC01 · Windows güvenliği | Yüksek | 2 dk önce | İncele › |
| Kötü amaçlı bağlantıya tıklandımehmet.kaya@ornek-sanayi.com.tr · Microsoft 365 | Kritik | 14 dk önce | İncele › |
| Switch portu sürekli açılıp kapanıyorSW-CORE-01 · Gi0/0/14 | Orta | 38 dk önce | İncele › |
| Yönetici grubuna üye eklendiSRV-DC01 · Domain Admins | Yüksek | 1 sa önce | İncele › |
- SRV-DC010.2.0.24 · şimdi
- SRV-FS010.2.0.24 · 12 sn
- SRV-SQL010.2.0.24 · 20 sn
Product screen (Turkish UI) · fictional sample data
- ISO/IEC 27001:2022Annex A evidence mapping
- TISAX / VDA ISAcontrol evidence & auditor package
- Data stays on-premisessupports KVKK-aligned retention
- Tamper-evident logsWORM archive + signed hash chain
- Turkish-firstUI and plain-language rule guidance
Features
From collection to evidence, one platform
Security team, IT and auditors look at the same screens; each role sees only what it is allowed to.
Log collection
Windows and Linux agent, syslog, SNMPv3, SNMP traps, Microsoft 365 and Acronis. Agents connect over mTLS; nothing is silently dropped.
Detection rules
122 built-in rules: match, threshold, sequence, absence and suppression. Maker-checker lifecycle and dry-run before publishing.
Plain-language alerts
Every alert answers: what happened, what should I do, could it be a false positive? Bulk decisions, expiring exceptions, noise policy.
Investigation
Start from an alert or entity: users, IPs, process tree, files; kill-chain stages, timeline and xlsx/HTML export.
Asset inventory & device 360
Automatic identity matching across Intune, Defender, agent, SNMP and DHCP; ports, LLDP topology, wireless and VPN context.
Microsoft 365 intelligence
Entra sign-ins, Defender alerts, inbound/outbound e-mail threats, new and look-alike domains with RDAP enrichment.
Evidence integrity
WORM raw archive, signed hash chain, continuous verification, retention and approved legal hold.
Compliance evidence
24 ISO/IEC 27001:2022 Annex A and 12 TISAX controls mapped; per-control evidence and a signed auditor package.
Operations & backup
Single-server install, encrypted nightly backups, NAS mirror, monthly isolated restore test, health dashboard.
Product tour
Every alert comes with guidance
The alert drawer answers three questions — what happened, what to do, could it be a false positive — and every decision is recorded with its reason.
Uyarılar
| Uyarı / ilgili cihaz | Önem | Durum | Son görülme | |
|---|---|---|---|---|
| Art arda yanlış parolayla giriş denendiSRV-DC01 · Windows güvenliği | Yüksek | Yeni | 2 dk önce | |
| Kötü amaçlı bağlantıya tıklandımehmet.kaya · Microsoft 365 | Kritik | Yeni | 14 dk önce | |
| Yönetici grubuna üye eklendiSRV-DC01 · Domain Admins | Yüksek | Bakıldı | 1 sa önce | |
| Switch portu sürekli açılıp kapanıyorSW-CORE-01 · Gi0/0/14 | Orta | Yeni | 38 dk önce | |
| UPS aküden besliyorUPS-SERVER-A · SNMP | Orta | Kapatıldı | 3 sa önce | |
| Windows grup ilkesi (GPO) değiştirildiSRV-DC01 · Default Domain Policy | Orta | İncelemede | 5 sa önce | |
| Taklit alan adından e-posta geldiornek-sanayl.com · e-posta | Orta | Yeni | 6 sa önce | |
| Kaynaktan beklenen veri gelmediPRN-3KAT-02 · SNMP | Düşük | Gürültü | dün 18:40 | |
| SQL Server sa hesabıyla oturum açıldıSRV-SQL01 · MSSQLSERVER | Yüksek | Yeni | dün 16:05 |
Ne oldu?
Kısa sürede aynı hesap için çok sayıda başarısız oturum açma.
Ne yapmalıyım?
Hesap kilitlendi mi kontrol edin. Kullanıcı kendisi mi deniyor sorun; değilse deneme yapan adresi engelleyin ve inceleme açın.
Yanlış alarm olabilir mi?
Parolası değişen bir hesabın eski parolayla çalışan servisi, zamanlanmış görevi ya da eşlenmiş sürücüsü.
See the relationships, not just the rows
The investigation graph links users, addresses, devices, processes and files, groups similar entities and orders events by kill-chain stage.
"Başarısız denemelerden sonra başarılı giriş" uyarısı
- Rol
- Etki alanı DC
- IP
- 10.20.1.10
- Konum
- Merkez
- Olay (1 sa)
- 4.812
Architecture
Single server, lossless bus, immutable archive
A record is acknowledged only after it is durably written. The raw copy goes to the immutable archive, the normalized copy to the event store. Everything runs inside your network.
- SourcesWindows/Linux agent, syslog, SNMPv3, Microsoft 365, Acronis
- Ingestion GatewaymTLS · ACK after durable write · back-pressure
- NATS JetStreamdurable bus · no silent loss
- Pipelineraw-writer (signed segments) · normalizer (240 event types)
- StoresMinIO WORM archive · ClickHouse event store · PostgreSQL
- DetectorYAML rules · correlation · exceptions
- Web UI + APIMFA · RBAC · four-eyes · auditor package
Compliance
Evidence, not a “compliant” badge
Daily work — alert decisions, closed cases, backups, restore tests, integrity checks — turns into control evidence automatically. Missing evidence is explained with the period's numbers. The auditor package is ed25519-signed and independently verifiable.
Uyum kontrolleri
| Kontrol | Başlık | Kanıt tamlığı | Kanıt | Eksik | Gözden geçirme | Eşdeğer |
|---|---|---|---|---|---|---|
| A.5.25 | Bilgi güvenliği olaylarının değerlendirilmesi ve karar | Kanıt tam | 214 örnek | — | Yeterli | TISAX 1.6.1 |
| A.5.28 | Kanıt toplama | Kanıt tam | 38 örnek | — | Yeterli | — |
| A.5.33 | Kayıtların korunması | Kanıt tam | 52 örnek | — | Yeterli | — |
| A.8.5 | Güvenli kimlik doğrulama | Kanıt tam | 96 örnek | — | Yeterli | — |
| A.8.13 | Bilgi yedekleme | Kanıt kısmi | 31 örnek | Geri yükleme testi kaydı yok | — | — |
| A.8.15 | Günlük kaydı (logging) | Kanıt tam | 1204 örnek | — | Yeterli | TISAX 5.2.4 |
| A.8.16 | İzleme faaliyetleri | Kanıt tam | 388 örnek | — | Kısmen yeterli | TISAX 5.2.4 |
| A.8.17 | Saat eşitleme | Kanıt eksik | 0 örnek | Dönem saat raporu yok | — | — |
| A.8.20 | Ağ güvenliği | Kanıt tam | 142 örnek | — | Yeterli | TISAX 5.2.7 |
Dönemde 31 başarılı yedek var; ancak bu dönemde tamamlanmış bir geri yükleme testi kaydı yok. Aylık geri yükleme testini etkinleştirin ya da son testin raporunu elle kanıt olarak ekleyin.
- Son paket
- ISO 27001 · 12 ay · 30.09.2026
- bundle_sha256
- 9e4c…b71a
- İmza
- ed25519 · anahtar sw-ev-2026
- Doğrulama
- ✓ Kanıt paketi bütünlüğü doğrulandı
Platform security
A security product protects itself first
Identity
argon2id passwords, mandatory TOTP MFA, step-up for sensitive actions, login throttling, CSRF origin checks.
Isolation
Server-side RBAC, PostgreSQL row-level security and ClickHouse row policies per tenant; read-only auditor role.
Agents & secrets
mTLS agents with your own CA, CA key isolated from the gateway, OpenBao secrets, AES-256 encrypted backups.
Audit trail
Every admin action is recorded immutably; high-impact changes need four-eyes approval.
Supply chain
Distroless, cosign-signed images with SBOM attestations, pinned by digest.
Small surface
Only 443 (UI) and 8443 (agents, mTLS) are exposed; data services live on an internal network.
Supported sources
Talks to the devices you already have
Windows (SEC-WISE agent)
- Security loglogons, accounts, groups, policy
- System & Application
- Process creation4688 · command line
- Sysmonprocess events
- File access auditing4663 and related
- Performance metricsCPU, memory, disk, services
- Hyper-VVM state
- SQL Serveraudit, backup, errors
- IISW3C logs, sites/pools
- DHCP serverscopes, leases, failover
- Active DirectoryDC health, replication, dcdiag
- WEFforwarded events
Linux (SEC-WISE agent)
- journaldsystemd journal
- sysloglocal files
- FIMfile integrity monitoring
- SSH / sudoidentity and privilege
Network & security (syslog · SNMP)
- Sophos Firewallsyslog
- Fortinet FortiGatesyslog
- RuijieRGOS syslog · switch SNMP
- HuaweiVRP switches · wireless AC
- VMware ESXisyslog
- Synology DSMLog Center
- Generic switchSNMPv3 · LLDP
- UPSAPC · RFC 1628
- Printers · NAS · LinuxSNMPv3
- CEF / KVfirewall and VPN
- SNMP trapsv2c/v3 · rate-limited
- SNMP v2cper device, opt-in, read-only
Cloud & backup (API)
- Microsoft 365unified audit
- Entra IDsign-ins, audit, devices
- Intunemanaged devices
- Defender XDRalerts and incidents
- E-mail threatsinbound and outbound
- Acronis Cyber Protect Cloudbackups, jobs, alerts
Vendor and product names are trademarks of their respective owners and are mentioned only to indicate compatibility.
By the numbers
Content that ships on day one
Measured from the current product release (October 2026).
FAQ
Frequently asked questions
Is SEC-WISE a cloud service?
No. SEC-WISE is installed on your own server or VM; logs, the archive and evidence stay there. Microsoft 365 and Acronis connectors only pull data from those services.
Will SEC-WISE tell us we are “ISO 27001 compliant”?
No, by design. It shows which evidence exists for each control and what is missing (complete / partial / missing / not expected). The auditor decides; the signed auditor package can be verified independently.
How do you prove logs were not altered?
Raw records are written first to a MinIO bucket in Object Lock COMPLIANCE mode and chained with ed25519-signed manifests. The chain is verified daily and the full content weekly; a mismatch opens a critical case.
Does it respond automatically?
No. SEC-WISE does not lock accounts or shut down devices. Any high-impact action requires a second person's approval (four-eyes) and is written to the audit log.
Is the UI available in English?
Turkish is the default. English can be selected per user; translation coverage starts from the main screens and is expanding. The product screens on this page are shown in Turkish.
Keep your logs on-premises and your evidence audit-ready.
See SEC-WISE with a scenario close to your environment: installation, first alerts, device view and the auditor package. A demo takes about 45 minutes.