Dashboard Guide
The Tamandua Sentinel Dashboard provides real-time visibility into your security posture across all managed endpoints. This guide covers dashboard widgets, metrics interpretation, and customization options.
Dashboard Overview
The dashboard is your primary interface for monitoring endpoint security health and threat activity.
[Screenshot: Full dashboard view with all widgets visible]
Overview Widgets
Security Posture Widget
Displays your organization's overall security health score based on:
- Agent Coverage: Percentage of endpoints with active agents
- Detection Coverage: Endpoints with current detection rules
- Vulnerability Exposure: Known vulnerabilities across endpoints
- Compliance Score: Adherence to security policies
| Score Range | Status | Description |
|---|---|---|
| 90-100 | Excellent | Optimal security posture |
| 75-89 | Good | Minor improvements recommended |
| 50-74 | Fair | Attention required on key areas |
| Below 50 | Critical | Immediate action required |
[Screenshot: Security Posture widget showing score breakdown]
Active Threats Widget
Real-time display of detected threats:
+------------------------------------------+
| ACTIVE THREATS Last 24h |
+------------------------------------------+
| Critical [===] 3 |
| High [======] 8 |
| Medium [=========] 15 |
| Low [============] 24 |
+------------------------------------------+
| Total Active: 50 | Resolved: 127 |
+------------------------------------------+
Click any severity level to filter the Alerts view.
Agent Status Widget
Overview of agent health across your environment:
| Status | Icon | Description |
|---|---|---|
| Online | Green circle | Agent reporting normally |
| Degraded | Yellow circle | Agent reporting but with issues |
| Offline | Red circle | Agent not reporting |
| Isolated | Blue shield | Agent network-isolated |
| Pending | Gray clock | Agent awaiting deployment |
[Screenshot: Agent Status widget with status breakdown pie chart]
Top Endpoints Widget
Lists endpoints with the most alert activity:
| Endpoint | Alerts (24h) | Status | Risk |
|---|---|---|---|
| WORKSTATION-042 | 23 | Online | High |
| SERVER-PROD-01 | 18 | Online | High |
| LAPTOP-SALES-07 | 12 | Online | Medium |
Click an endpoint to view detailed agent information.
Alert Trends
Alert Volume Chart
Interactive time-series chart showing alert volume over time.
Time Range Options:- Last 1 hour
- Last 24 hours (default)
- Last 7 days
- Last 30 days
- Custom range
- By severity
- By category
- By detection source (YARA, Sigma, ML, Behavioral)
[Screenshot: Alert volume chart with severity breakdown over 7 days]
Alert Breakdown
Pie chart visualization of alerts by:
- Category: Malware, Suspicious Activity, Policy Violation, etc.
- Source: Detection method that triggered the alert
- Status: Open, Investigating, Resolved, Suppressed
Trend Indicators
Each metric displays a trend indicator:
- Upward Arrow (Red): Increase from previous period (concerning)
- Downward Arrow (Green): Decrease from previous period (improving)
- Flat Line: No significant change
Example:
Critical Alerts: 5 [Down Arrow] -40% vs last week
Open Investigations: 12 [Up Arrow] +20% vs last week
Agent Status
Agent Health Summary
The Agent Health widget provides at-a-glance status:
+------------------------------------------+
| AGENT HEALTH |
+------------------------------------------+
| [============================] 94% |
| 1,245 / 1,325 agents healthy |
+------------------------------------------+
| Online: 1,245 | Isolated: 15 |
| Degraded: 45 | Pending: 5 |
| Offline: 15 | |
+------------------------------------------+
Agent Version Distribution
View agent version deployment status:
| Version | Count | Percentage | Status |
|---|---|---|---|
| 2.5.0 | 980 | 74% | Current |
| 2.4.2 | 280 | 21% | Supported |
| 2.3.1 | 65 | 5% | Outdated |
[Screenshot: Agent version distribution chart with update recommendations]
Platform Distribution
Breakdown of agents by operating system:
- Windows: Windows 10/11, Windows Server 2016/2019/2022
- Linux: Ubuntu, RHEL, CentOS, Debian
- macOS Preview: Monterey, Ventura, Sonoma lab endpoints only
Recently Deployed
List of recently deployed or updated agents:
| Agent | Platform | Version | Deployed |
|---|---|---|---|
| LAPTOP-NEW-001 | Windows 11 | 2.5.0 | 2 min ago |
| SERVER-WEB-03 | Ubuntu 22.04 | 2.5.0 | 15 min ago |
| MAC-LAB-012 | macOS 14.2 Preview | 2.5.0-preview | 1 hour ago |
MITRE ATT&CK Coverage
Coverage Matrix
Interactive MITRE ATT&CK framework heatmap showing:
- Green: Techniques with active detection rules
- Yellow: Partial coverage (some subtechniques covered)
- Red: No detection coverage
- Blue: Techniques detected in your environment (last 30 days)
[Screenshot: MITRE ATT&CK matrix heatmap with coverage visualization]
Tactic Overview
| Tactic | Techniques Covered | Total Techniques | Coverage |
|---|---|---|---|
| Initial Access | 8 | 9 | 89% |
| Execution | 11 | 14 | 79% |
| Persistence | 17 | 19 | 89% |
| Privilege Escalation | 12 | 13 | 92% |
| Defense Evasion | 35 | 42 | 83% |
| Credential Access | 14 | 17 | 82% |
| Discovery | 25 | 31 | 81% |
| Lateral Movement | 8 | 9 | 89% |
| Collection | 15 | 17 | 88% |
| Command and Control | 14 | 16 | 88% |
| Exfiltration | 8 | 9 | 89% |
| Impact | 12 | 13 | 92% |
Recent Detections by Technique
Techniques observed in your environment:
| Technique | ID | Detections (7d) | Last Seen |
|---|---|---|---|
| Process Injection | T1055 | 45 | 5 min ago |
| Scheduled Task | T1053 | 32 | 12 min ago |
| Registry Run Keys | T1547.001 | 28 | 1 hour ago |
| PowerShell | T1059.001 | 156 | 2 min ago |
Click any technique to view related alerts.
Coverage Gaps
Identifies techniques without detection coverage that have been observed in threat intelligence:
| Technique | ID | Threat Groups Using | Risk |
|---|---|---|---|
| DLL Side-Loading | T1574.002 | APT29, APT41 | High |
| Timestomping | T1070.006 | Multiple | Medium |
Customization
Widget Management
Adding Widgets
- Click Customize in the dashboard toolbar
- Click Add Widget
- Select widget type from available options
- Configure widget settings
- Click Save
[Screenshot: Widget gallery showing available widget types]
Available Widget Types
| Category | Widgets |
|---|---|
| Overview | Security Posture, Active Threats, Alert Summary |
| Agents | Agent Status, Version Distribution, Platform Breakdown |
| Alerts | Alert Trends, Alert Volume, Top Alerts |
| Detection | MITRE Coverage, Detection Rules, ML Model Performance |
| Performance | Pipeline Latency, Query Performance, System Health |
| Custom | Saved Search, Custom Query, External Data |
Removing Widgets
- Hover over the widget
- Click the More Options (three dots) menu
- Select Remove Widget
Resizing and Repositioning
- Drag: Click and drag the widget header to reposition
- Resize: Drag the widget corner to resize
Widgets snap to a grid system for consistent alignment.
Dashboard Layouts
Creating a Layout
- Arrange widgets as desired
- Click Customize > Save Layout
- Enter a layout name
- Optionally set as default
Layout Templates
Pre-built layouts for common use cases:
| Template | Description |
|---|---|
| SOC Overview | High-level security metrics for SOC managers |
| Threat Hunting | Detection and MITRE-focused view |
| Incident Response | Alert and investigation-centric layout |
| Executive | Summary metrics for leadership reporting |
| Agent Operations | Endpoint health and deployment focus |
[Screenshot: Layout template selection dialog]
Sharing Layouts
Share layouts with team members:
- Click Customize > Share Layout
- Select users or roles
- Choose permission level (View/Edit)
- Click Share
Time Zone Configuration
Set your preferred time zone for all dashboard displays:
- Click your user avatar
- Select Preferences
- Choose your time zone
- Click Save
All timestamps will display in your selected time zone.
Refresh Settings
Configure dashboard auto-refresh:
| Setting | Interval | Use Case |
|---|---|---|
| Real-time | 5 seconds | SOC monitoring |
| Frequent | 30 seconds | Active investigation |
| Standard | 5 minutes | General use |
| Manual | Disabled | Report creation |
Enable/disable auto-refresh using the toggle in the dashboard toolbar.
Color Themes
Customize severity colors for accessibility:
| Severity | Default | Deuteranopia | Custom |
|---|---|---|---|
| Critical | Red | Purple | Configurable |
| High | Orange | Blue | Configurable |
| Medium | Yellow | Cyan | Configurable |
| Low | Green | Gray | Configurable |
Dashboard Filters
Global Filters
Apply filters that affect all dashboard widgets:
- Time Range: Limit data to specific time period
- Agent Group: Filter to specific endpoint groups
- Organization: Filter by organization (MSSP mode)
- Tags: Filter by custom tags
[Screenshot: Global filter bar with multiple filters applied]
Widget-Level Filters
Individual widgets can have additional filters:
- Click the filter icon on the widget
- Configure widget-specific filters
- Click Apply
Widget filters combine with global filters.
Saved Filters
Save frequently used filter combinations:
- Configure desired filters
- Click Save Filter
- Enter a name
- Access saved filters from the filter dropdown
Exporting Data
Widget Export
Export individual widget data:
- Click the More Options menu on the widget
- Select Export
- Choose format (CSV, JSON, PDF)
Dashboard Export
Export the entire dashboard as a report:
- Click Export in the dashboard toolbar
- Select format:
- PDF: Formatted report with visualizations
- PNG: Dashboard screenshot
- Configure options (date range, branding)
- Click Export
Scheduled Reports
Automate dashboard exports:
- Navigate to Reports > Scheduled
- Click New Schedule
- Select dashboard and format
- Configure schedule (daily, weekly, monthly)
- Add recipients
Performance Considerations
Large Deployments
For environments with 10,000+ agents:
- Use widget pagination where available
- Leverage agent groups for filtered views
- Consider time range limitations for heavy queries
- Enable query caching in Settings
Dashboard Load Time
If dashboard load time exceeds expectations:
- Review widget count (recommend max 12)
- Check time range filters (shorter ranges load faster)
- Verify agent group filters are applied
- Contact support if issues persist
Next Steps
- Agent Management - Manage your endpoint agents
- Alert Management - Handle security alerts
- Investigations - Conduct threat investigations
- Live Response - Execute remote commands