SIEMLess Admin is the mobile companion app for the SIEMless security platform. It lets security analysts and on-call responders review alerts, approve or reject proposed AI-driven remediation actions, and investigate rogue devices on their network — all from their phone.
The app connects to a SIEMless server you run yourself (on-premises or in your own cloud); it does not use a hosted SIEMless service and does not send your telemetry to any third party.
Key capabilities
• Real-time push alerts for high-severity detections, with biometric-protected approve / reject action buttons from the notification.
• Review AI-generated triage verdicts with full context: MITRE ATT&CK tags, source and destination, and the underlying log evidence.
• One-tap response actions: block IPs, isolate hosts, disable users, quarantine email, run AV scans, revoke IAM keys, and more — each scoped to the connectors your server has configured.
• Rogue device detection with a live network map, including a 3D topology view that clusters devices by the agent that last observed them (helpful when physically tracking a rogue on a LAN).
• Multi-server support: add all your customer deployments once and switch between them from a dropdown.
• Offline queue: actions taken in the field are replayed automatically when connectivity returns.
• Agent health dashboard: see which endpoints are online, their last heartbeat, and drill into a single host for full-fidelity telemetry.
• CyberScore: trigger security-hardening scans and apply CIS-benchmarked baselines to your managed endpoints.
Who it's for
SIEMLess Admin is an administrative tool for people who already run a SIEMless server. It is not useful on its own. If you are evaluating SIEMless, start at https://cyberautomation.com.au — the server install takes about 15 minutes.
Security model
• TLS with trust-on-first-use certificate pinning — your first connect captures the server certificate fingerprint; subsequent connects detect any change as a potential man-in-the-middle.
• OIDC or local password authentication, your choice per server.
• Biometric unlock on supported devices (Face ID / fingerprint).
• No data is ever sent to Cyber Automation or any third party: all traffic goes directly to your SIEMless server.