Offline-first · Wazuh-style · v2.2.1

Security for
network, servers & web.

A lightweight agent · manager · CLI · dashboard you can pip install — now with a full SecOps brain: SIEM, XDR, EDR, UEBA, SOAR, Threat Intel, NDR, Cloud & a local AI triage. MITRE-mapped alerts and one-click response — your data never leaves your network.

Nexus Manager
Live
.env modified on prod-web-01
NEXUS-FIM-001
CRITICAL
L14
Log4Shell — log4j 2.14.0
NEXUS-VULN-001
HIGH
L12
Laravel APP_DEBUG in production
NEXUS-WEB-001
HIGH
L11
Host firewall disabled
NEXUS-FW-001
MEDIUM
L10
Security posture
Network100%
Server62%
Website42%
FILE INTEGRITYLOG MONITORINGVULN DETECTIONMITRE ATT&CKACTIVE RESPONSEPOSTURE SCOREmTLSRBACOFFLINE-FIRSTFILE INTEGRITYLOG MONITORINGVULN DETECTIONMITRE ATT&CKACTIVE RESPONSEPOSTURE SCOREmTLSRBACOFFLINE-FIRST

01 — The platform

Most security tools watch logs. Nexus understands your stack  Laravel, Next.js, Nginx  and keeps every finding inside your own network.

Offline-first

Telemetry is signed with HMAC and stored locally. Nothing is sent to a third-party cloud.

Developer-aware

Catches exposed .env, APP_DEBUG in production and leaked NEXT_PUBLIC secrets — not just raw logs.

Lightweight

A stdlib-only agent. Install with pip or npm, run as a service, scale to many endpoints.

02 — Capabilities

Everything you'd expect from a SIEM  plus what developers actually need.

FIM

File Integrity Monitoring

Baseline checksums detect when sensitive files like .env change — instantly, with the exact before/after hash.

Logs

Log Monitoring

App-aware decoders for Laravel, Nginx and auth logs catch SQLi, scanners, exceptions and brute-force in real time.

CVE

Vulnerability Detection

Correlates your software inventory against a CVE database — Log4Shell, PuTTY, 7-Zip and more, with version ranges.

Web

Web & App Audit

Detects what SIEMs miss: APP_DEBUG in production, exposed .env, weak DB creds, leaked NEXT_PUBLIC secrets.

Detect

Rule & Alert Engine

Level 0–15 alerts mapped to MITRE ATT&CK, deduplicated, grouped into incidents to kill alert fatigue.

Respond

Active Response

One-click “Secure” — block IP, enable firewall, kill process, harden. Dry-run by default with protected-IP allowlists.

9/10
Wazuh core parity
4
Components: agent · manager · cli · dashboard
0
Heavy deps — agent is stdlib-only
1
Command to install

03 — SecOps

A full SOC brain, inside one install.

Nexus consolidates the de-duplicated capabilities of 20 enterprise tools into 9 modules inside nexus-fleet — one platform, one agent, no external API. They read the same real data and feed each other from detection to automated response.

SIEM

Search & aggregate the event store with the NQL query language.

Splunk · Elastic · QRadar
XDR

Fuse many alerts across time into one kill-chain incident.

Defender · Cortex XDR
EDR

Real process tree (pid/ppid) + suspicious-lineage detection.

CrowdStrike · SentinelOne
UEBA

Per-entity behavioral baselines + anomaly scoring + peer analysis.

Securonix · Exabeam
SOAR

Playbooks → real active response, dry-run-safe and triple-gated.

Cortex XSOAR · Google SecOps
Threat Intel

IOC store + match on real telemetry + feed import & retro-hunt.

MISP · OTX · abuse.ch
NDR

Beaconing/C2, port-scan & IOC-destination detection from flows.

Security Onion · QRadar QFlow
Cloud (CSPM)

Evaluate cloud config vs CIS + import Prowler; posture score.

Cortex · Defender for Cloud
AI Triage

Prioritize, summarize the kill-chain & recommend — no API cost.

Local · zero token

04 — Architecture

One platform, four components.

nexus-agent
Endpoint daemon
  • FIM · logs · SCA
  • Syscollector · inventory
  • Offline store-and-forward
01
nexus-manager
Central API server
  • Rule & alert engine
  • Vuln detection · policy
  • License · RBAC · audit
02
dashboard + cli
Monitoring & control
  • Web dashboard
  • Interactive SOC console
  • REST API
03
agentHMAC · TLS · mTLSmanager

05 — Editions

Start free. Unlock more as you grow.

Free
Rp 0

For evaluation and small setups.

  • 2 agents
  • Core detection rules
  • Dashboard & CLI
  • Community support
Get started
Popular
Pro
Rp 50/mo

For teams securing real infrastructure.

  • Seat-based agents
  • All rules · FIM · Web audit · SCA · Vuln
  • Sigma import & Active Response
  • Reports · posture score · email support
Contact sales
Enterprise
Custom

Unlimited scale with priority care.

  • Unlimited agents
  • mTLS · at-rest encryption · RBAC
  • Priority support & onboarding
  • Custom licensing
Talk to us

06 — Get started

Up and running in one command.

No cluster, no indexer, no heavy runtime. Install the package, run the manager, enroll an agent — and watch real findings appear.

nexus — terminal
$ pip install nexus-fleet
Then
> nexus-manager run --host 0.0.0.0 --port 8765> nexus-agent enroll --host <manager> --key <KEY> --watch ./app> nexus-agent start> nexus-cli alerts

07 — Founders

The people behind Nexus.

Candra Kirana
ck271138@gmail.com
Azhar Muttaqien
azharsss457@gmail.com