Three components:
Capabilities: log analytics, intrusion detection, FIM, configuration assessment, vulnerability detection, compliance.
Collects via agents (logs, system activity, file changes) and agentless (Syslog/SSH/APIs).
V3 replaced V2. Supports Windows, Linux, macOS memory dumps. Detects fileless malware, kernel rootkits, process injection, in-memory C2.
Workflow: process triage (pstree, psscan) -> network triage (netscan) -> suspicious process analysis (dlllist, malfind) -> command history (cmdline, linux.bash)
Comprehensive: vulnerabilities, misconfigs, secrets, SBOM generation. Broader scope, slightly slower.
Focused vuln scanner, 30-40% faster than Trivy. Pairs with Syft for SBOM.
Both produce false positives/negatives. Do not treat as authoritative alone.