Public Tutorial

Operate the MikuEbluesys Security Platform

A practical walkthrough for analysts — learn each feature, when to use it, and how to investigate & respond effectively.

01

Getting Started

After signing in, select your server and start from the Dashboard. Follow this sequence to efficiently navigate the platform.

1
Open Dashboard Get a high‑level security overview and server health status.
2
Select a Server Ensure the correct protected server is chosen (e.g. Demolab).
3
Review Critical Incidents Start with high‑priority events — don’t read every log at once.
4
Investigate Use logs, attack maps, audit findings, vulnerabilities or malware scans as needed.
5
Respond Leverage the SOAR playbooks when an incident requires action.
Pro tip: Most pages are server‑specific. If data looks empty, check the selected server first.
02

Dashboard

Your security command centre — view system health, threat state, latest scans and suggested actions.

System Health

CPU, memory, disk, swap, load, uptime – at a glance.

Threat State

Analyst‑interpreted process behaviour classification.

Latest Scans

Audit, vulnerability and malware scan timestamps & results.

Suggested Actions

High‑priority recommendations to improve security.

Use it when: Starting your daily review or checking overall server health.

03

Global Attack Map

Live geographic overview of detected attacks against your server.

Attack Locations

Unique mapped source countries / cities.

Total Attempts

Detected attempts in the selected time window.

Blocked / Active

Green = blocked, Red = active threat.

Use it when: You want a quick visual of attack sources before diving into logs.

04

Security Incidents

Correlated security events with severity, MITRE mapping, and response workflows.

Critical / High

Priority incidents requiring immediate review.

Categories

Network, Web Attack, Malware, etc.

Playbooks

Attach and run SOAR playbooks directly from the incident.

Use it when: An alert requires investigation or a documented response.

Typical workflow
Incident Timeline / Raw Logs Assessment SOAR Response

Always review evidence before executing any automated response.

05

Threat Intelligence

Active IOCs (Indicators of Compromise) and matches against your server’s event history.

Active IOCs

Enabled indicators by the security team.

Server Matches

IOC IPs observed in AttackLogs.

Filtering

Search by value, type, severity, source, match status.

Use it when: You need to check if a known malicious indicator has appeared on your server.

06

Security Logs

Raw security‑related events collected by the agent – the foundation for any investigation.

Use it when: You need the raw event context behind an alert or incident (e.g. SSH auth attempts, web requests).

Filter by time, event type, IP, or severity to zoom in on relevant activity.
07

Network Monitoring

Real‑time interface health, bandwidth, latency, packet loss, and active connections.

Upload / Download

Current speed and total transferred.

Latency & Packet Loss

Response time and delivery stability.

Connections

Established (TCP/UDP) and listening sockets.

Use it when: Investigating network performance, connectivity issues, or unusual traffic patterns.

08

Forensics & Attack Provenance

Read‑only workspace to investigate processes, network activity, and file paths.

Timeline Events

Unified view of incidents, threats, evidence, and SOAR tasks.

PID Investigator

Collect process identity, parent chain, children, open files, sockets, hashes.

Path Investigator

Bounded metadata + SHA‑256 scan (file contents are never uploaded).

Use it when: You need deep visibility into a suspicious process or file – without destructive actions.

Destructive containment (e.g. kill process) is separated into Active Response and SOAR.
09

Audit Log

Security‑oriented system audit view – baseline configuration and compliance checks.

Use it when: Performing a baseline review or checking system security posture before onboarding.

10

Vulnerability Scan

Results from vulnerability scanning – known issues in installed packages.

Use it when: Checking if installed software has known security issues that need patching.

Each finding includes affected component and remediation guidance.
11

Malware / Virus Scan

Malware detection findings with a false‑positive safety policy.

Detection

Files, processes, or scripts flagged by scanners.

False‑positive handling

Previous FP decisions are reused only if SHA‑256, scanner, rule & version match.

Actions

Quarantine, restore, or mark as false positive (with evidence).

Use it when: You suspect a malicious file or want to review scan findings.

12

Active Response

Evidence‑backed suspicious or malicious processes and services – with safety checks.

  • Only suspicious processes are shown; normal Linux processes are hidden.
  • Before termination, agent re‑validates PID, create time, name, executable.
  • Protected OS and Miku services cannot be stopped.

Use it when: You have confirmed a malicious process and need to stop it immediately.

13

SOAR Console

Playbook approval, execution tracking, and agent task queue.

Total Executions

Track all playbook runs.

Status

Awaiting Approval, Success, Failed, etc.

Approval Required

High‑risk actions need explicit approval before execution.

Use it when: An incident has a defined response and you need to approve or track automated actions.

Always review incident evidence before approving a SOAR playbook – especially destructive ones.
14

Resource Usage

CPU, memory, disk, swap, load, and uptime with historical trends.

Use it when: Server is slow, a scan is consuming high CPU, or you need capacity planning.

# Example: CPU, memory, disk averages over the last 7 days CPU: 0.5% | Memory: 26.1% | Disk: 77.5%
15

Frequently Asked Questions

What should I check first every day?
Open the Dashboard, select the relevant server, then review high‑severity incidents and unusual activity. Check system health and latest scan results.
Do I need to open every menu?
No. Use the menu according to the task: logs for evidence, incidents for investigation, scans for posture, SOAR for response, and resource/database pages for performance.
When should I use SOAR?
When a response action is defined and authorized. Investigation should come before destructive or disruptive response actions. Always verify the execution result afterward.
Why can a page be empty?
Most common checks: selected server, agent reporting status, applied filters, and whether the feature has collected data yet. Start by confirming the server selection.

Ready to secure your Linux servers?

Start your free trial today and get full visibility, automated response, and expert guidance.

Create Account