> For the complete documentation index, see [llms.txt](https://docs.cybaops.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cybaops.com/modules/dashboard.md).

# Dashboard

The CybaOps Dashboard provides a high-level view of your organisation's security posture, active risks, vulnerabilities, and Managed Detection & Response (MDR) activity. It is designed to give security teams, IT administrators, and business stakeholders immediate visibility into their current security status and the areas that require attention.

The dashboard combines information from Vulnerability Manager, Detect & Respond (MDR), Security Assessments, Domain Scanning, and Security Posture Rating into a single view.

<figure><picture><source srcset="/files/Uz57n9MKHx9GOQrxRLgh" media="(prefers-color-scheme: dark)"><img src="/files/9z5ucE6cO3bQODy52xFF" alt=""></picture><figcaption></figcaption></figure>

{% hint style="info" %}
You will only see widgets for modules that are included in your licence.&#x20;
{% endhint %}

***

### <mark style="color:$primary;">Security Posture Rating</mark>

**What it shows**

The Security Posture Rating provides an overall indication of your organisation's security maturity and risk level.

**Where the data comes from**

The score is calculated using information gathered throughout your CybaOps environment, including:

* Vulnerability scans
* Domain scans
* Security assessments

**Timeframe**

The score reflects your current security posture based on the latest available security data.

**Additional Information**

The Security Posture Rating is covered in a dedicated guide. You can select the score or view the linked documentation for a detailed explanation of how the score is calculated and maintained.

***

### <mark style="color:$primary;">Domain Scanner</mark>

**What it shows**

The Domain Scanner provides a quick overview of the health and security configuration of your selected internet-facing domain.

The dashboard widget highlights the status of your key email security controls:

* MX Records
* SPF
* DMARC

Selecting **View Results** opens the full Domain Scan results within Vulnerability Manager.

#### **Where the data comes from**

CybaOps performs automated external scans against your selected domain and related public services.

The scan includes:

**DNS & Email Security**

* MX Record configuration
* SPF Record validity
* DKIM Record presence and correctness
* DMARC policy configuration
* MTA-STS configuration
* TLS-RPT configuration
* WHOIS registration information

**TLS & Web Security**

* HTTPS support and redirects
* TLS version validation
* SSL certificate validity
* HSTS configuration
* Security headers including:
  * Content Security Policy
  * X-Frame-Options
  * X-Content-Type-Options
  * Referrer-Policy
  * Permissions-Policy

**Passive Website Security**

* Lightweight web application assessment
* Detection of common misconfigurations
* Basic vulnerability identification

**Public Exposure & Vulnerability Intelligence**

* Shodan exposure analysis
* Internet-facing service discovery
* Known vulnerability identification

**Additional Checks**

* Subdomain enumeration
* Third-party script analysis
* Domain reputation validation
* Threat intelligence checks

**Timeframe**

* Automatically scanned every **24 hours**
* Users can initiate scans sooner through the **Schedules** page
* Results displayed represent the latest completed scan

***

### <mark style="color:$primary;">Immediate Actions Open</mark>

**What it shows**

Immediate Actions identifies the most important issues requiring attention within your tenancy.

These actions are automatically prioritised to help focus effort on the items presenting the greatest risk.

The widget can be viewed as:

* A total count of actions
* A detailed action list

Selecting the expansion arrow opens the full Immediate Actions module.

**Where the data comes from**

Information is aggregated across multiple CybaOps modules, including:

* Vulnerabilities
* Assets
* MDR incidents
* Security assessments
* Domain scanning results

**Timeframe**

The widget reflects the current list of active Immediate Actions based on the latest available security data.

**Recommended Action**

Review and remediate Immediate Actions as soon as possible to reduce risk exposure.

***

### <mark style="color:$primary;">Vulnerabilities Over Time</mark>

**What it shows**

This chart displays vulnerability trends over time across all severity levels.

The graph enables you to identify:

* Emerging security issues
* Improvements in remediation performance
* Long-term vulnerability trends
* Changes in overall risk exposure

Vulnerabilities are grouped by severity:

* Critical
* High
* Medium
* Low
* Informational
* Unknown (where applicable)

**Where the data comes from**

Data is collected from:

* Vulnerability Manager scans
* Asset scanning activity
* External security assessments
* Integrated vulnerability sources

**Timeframe**

The chart displays data across the entire period your organisation has been using CybaOps.

***

### <mark style="color:$primary;">Vulnerabilities by Severity</mark>

**What it shows**

This chart provides a snapshot of currently open vulnerabilities grouped by severity.

This allows users to understand the current risk profile of their environment.

Severity categories include:

* Critical
* High
* Medium
* Low
* Informational

**Where the data comes from**

Data is sourced from Vulnerability Manager. Only currently open vulnerabilities are displayed.

**Timeframe**

Represents the latest vulnerability status based on the most recent completed scans.

***

### <mark style="color:$primary;">MDR Open Incidents</mark>

**What it shows**

This widget displays the total number of currently open MDR incidents being managed within Detect & Respond.

Open incidents represent security investigations that have not yet been fully closed.

**Where the data comes from**

Data is sourced directly from Detect & Respond (MDR).

This includes:

* Open security incidents
* Active investigations
* Ongoing analyst activity

**Timeframe**

Shows the current count of incidents that remain open.

***

### <mark style="color:$primary;">MDR Incidents by Hour of Day</mark>

**What it shows**

This heatmap visualises when incidents occur throughout the week.

The chart helps identify:

* Periods of increased attack activity
* Common threat timings
* Behavioural trends within your environment

**Where the data comes from**

Data is collected from MDR incidents generated within Detect & Respond.

**Timeframe**

The chart represents incident activity across all historical MDR data held within the platform.

***

### <mark style="color:$primary;">MDR Incidents by Tactic</mark>

**What it shows**

This chart maps incidents against the MITRE ATT\&CK framework tactics.

It allows users to understand the types of attacker behaviour most frequently observed within their environment.

Examples include:

* Initial Access
* Persistence
* Execution
* Lateral Movement
* Command and Control
* Exfiltration

**Where the data comes from**

Data is sourced from MDR incidents and their associated MITRE ATT\&CK classifications.

**Timeframe**

Represents all MDR incidents recorded within the platform.

***

### <mark style="color:$primary;">MDR Detections Over Time</mark>

**What it shows**

This chart displays trends for:

* Incidents
* Alerts

The graph helps security teams identify:

* Changes in threat activity
* Increased alert volumes
* Long-term security trends

**Where the data comes from**

Data is collected from Detect & Respond monitoring and alerting activity.

**Timeframe**

The chart reflects all available historical MDR detection data.

***

### <mark style="color:$primary;">Cyber Security Assessment</mark>

**What it shows**

The Cyber Security Assessment provides an overview of your organisation's security maturity across key security domains.

Each category receives an individual rating to help identify strengths and areas for improvement.

Typical domains include:

* Logging and Monitoring
* Identity and Access Management
* Supply Chain Security
* Engagement and Training
* Data Security
* Incident Management
* Risk Management
* Architecture and Configuration
* Asset Management
* Vulnerability Management

**Where the data comes from**

The assessment is completed by your organisation during onboarding and periodic review exercises.

**Timeframe**

Displays the most recent completed Cyber Security Assessment.

**Additional Information**

Selecting the assessment will provide detailed recommendations and improvement opportunities for each category.

***

### <mark style="color:$primary;">Keeping Your Dashboard Up to Date</mark>

Most dashboard information updates automatically as new security data becomes available.&#x20;

To ensure the most accurate view of your security posture:

* Complete your Cyber Security Assessment regularly
* Ensure assets remain actively monitored
* Review and close Immediate Actions promptly
* Schedule vulnerability scans consistently
* Monitor MDR incidents and investigations
* Verify domain scanning coverage for all managed domains

The dashboard should be reviewed regularly by both operational teams and management stakeholders to maintain visibility of your organisation's overall security health.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cybaops.com/modules/dashboard.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
