Product Documentation

A practical guide for teams learning NyxGate for the first time.

This documentation explains how to approach NyxGate from first sign-in through daily operations: where to begin, how each menu area is intended to be used, how to onboard hosts, and how to operate the platform with discipline and confidence.

First-Hour Clarity Know what to configure first and what can wait.
Operator Guidance Understand the product by workflow, not by guesswork.
Safe Rollout Adopt the platform in a measured way before broad enforcement.
Operator Guide

Start here if you want to understand how NyxGate should actually be used.

NyxGate is easiest to adopt when you treat it as an operating console rather than a collection of disconnected pages. This guide explains the product in the order a new team should approach it: secure setup, early validation, controlled onboarding, daily workflows, and steady rollout.

Overview: start-of-day orientation

Use the Overview page first. It is the quickest way to see whether the platform is healthy, whether hosts are reporting, and where the current priorities sit.

  • Read the posture summary before drilling into detail
  • Use it to spot drift, exposure, or empty telemetry quickly
  • Return here often to confirm whether changes improved the environment
Network and Agents: trust what is enrolled

The Network and Agents areas tell you what the platform can currently see and control. New users should confirm host names, addresses, status, and reporting consistency here early.

  • Check that enrolled hosts look accurate
  • Confirm topology and service visibility are believable
  • Use Agents to understand which systems are actually managed
Threats: detections, sessions, rules, and blocks

Threats is where NyxGate becomes operational. It brings together detections, attack sessions, prevention rules, and blocked entities so you can move from signal to decision.

  • Use Threat Console for raw detection review
  • Use Attack Dashboard for correlated sessions and timing
  • Use Blocked Entities to confirm, extend, or remove prevention actions
Traffic, Monitoring, and Insights: understand behavior

These areas answer the question “what is this host doing, and should I care?” They are especially useful when a detection needs surrounding context before you act.

  • Use Traffic for connection and service patterns
  • Use Monitoring for host condition and system behavior
  • Use Insights for higher-level interpretation and prioritization
Firewall and Patching: change posture deliberately

These sections are where you move from observation into managed control. They are powerful, so the right habit is to review the current state first, then make narrow changes with intent.

  • Review current exposure before changing policy
  • Roll out firewall decisions carefully instead of broadly at first
  • Use patching to reduce known risk with operational awareness
Terminal and Settings: use access with discipline

Terminal gives you operational reach, and Settings controls the platform baseline. Both should be treated as administrative tools, not casual shortcuts.

  • Use Terminal to verify or remediate when UI context is not enough
  • Keep Settings aligned to your operating model and trust boundaries
  • Document who can change policy, unblock entities, or adjust core behavior
First-Day Sequence

The safest way to move from install to confident daily use.

Most friction for new users comes from doing too much too early. This sequence helps teams validate the product, learn the workflow, and avoid premature enforcement decisions.

01

Complete secure setup before anything else

Finish administrative bootstrap carefully, store recovery material properly, and confirm who is responsible for the first operational account.

02

Verify the controller is stable and reachable

Open the platform, review the Overview page, and make sure the system is not only online but also presenting believable posture and host state.

03

Onboard a small pilot group of hosts

Do not begin with the whole environment. Start with a few representative systems so you can validate naming, telemetry, services, detections, and policy behavior safely.

04

Confirm the product is seeing what you expect

Use Agents, Network, Traffic, and host views to make sure host identity, open services, and recent activity match reality before you rely on the platform operationally.

05

Review rules and prevention posture cautiously

Understand which detections are informational, which rules can block, and how blocked entities are managed before you increase enforcement confidence.

06

Move into a repeatable daily workflow

Once telemetry, detections, and basic controls look trustworthy, use NyxGate as the main working surface for review, investigation, patching, and controlled response.

Practical Tasks

The core jobs new users usually need to complete first.

This section explains how to think about the most common operational tasks in NyxGate so the product feels usable from day one instead of only after trial and error.

01

How to onboard a new host well

Generate the install path from the controller, enroll a small number of systems first, and validate identity, services, and reporting before scaling the rollout.

  • Confirm host name and IP are correct
  • Check the host appears in both Agents and Network
  • Wait for initial telemetry before making policy assumptions
02

How to investigate suspicious activity

Begin in Threats, then pivot into the host, related traffic, services, or timeline until you understand whether you are seeing noise, drift, or a real incident.

  • Start with the detection source and affected host
  • Use Traffic and Monitoring for surrounding evidence
  • Act only after the host context matches the detection story
03

How to manage blocked entities

Use blocked entries as deliberate control records. Confirm why the block exists, whether it should expire, and whether the same source is still active before unblocking.

  • Review the reason and host scope first
  • Prefer duration changes when the block is still useful
  • Unblock only when the cause is understood and accepted
04

How to use firewall controls safely

Treat firewall changes as posture work, not quick experimentation. Review the current rule intent, apply changes narrowly, and observe the result before widening scope.

  • Start with obvious high-value restrictions
  • Avoid broad deny rules without host context
  • Re-check host services and traffic after each meaningful change
05

How to use patching operationally

Use patching as part of risk reduction, not only maintenance. Prioritize systems with real exposure or active concern, then validate the host returns cleanly afterward.

  • Check what is missing and why it matters
  • Apply updates with awareness of business impact
  • Confirm the host comes back healthy and current
06

How to use Terminal responsibly

Terminal is best used when the UI has already narrowed the question and you need direct confirmation or remediation. It should support workflow, not replace it.

  • Use it to verify a finding or complete a targeted fix
  • Keep changes deliberate and minimal
  • Return to the platform view afterward to confirm the result
Working Guidance

Habits that make the platform easier to trust and easier to operate.

Strong product adoption is less about clicking every menu and more about forming a clear operating discipline. These principles help new teams get value without creating confusion or accidental disruption.

Begin with a pilot, not the whole fleet

A small pilot group lets you test host visibility, service identification, detections, and enforcement behavior before the platform becomes part of broader operations.

Trust evidence more than first impressions

When something looks suspicious, use host context, traffic, services, and timing together before deciding whether it is an incident, a misconfiguration, or expected behavior.

Make the product part of a repeatable routine

NyxGate becomes more valuable when teams use it consistently for orientation, review, investigation, and follow-through instead of only opening it when something is already wrong.

Operator Questions

The answers a new team usually needs before the product becomes comfortable.

These are practical operating questions rather than sales questions. They help new users understand how to approach NyxGate with judgment and control.

Where should a new operator begin after the first login?

Begin with Overview, then verify enrolled hosts in Agents and Network. Before acting on detections or changing rules, confirm the platform is presenting host identity, services, and status accurately.

How many hosts should we onboard first?

Start with a controlled pilot group that represents different system types. This gives you enough signal to validate the platform without creating unnecessary risk from immediate broad rollout.

When should we trust prevention actions?

Trust prevention only after detections, service visibility, and host identity have been verified on real systems. Teams should understand what will be blocked, how it appears in Blocked Entities, and who is responsible for reviewing exceptions.

What should we review every day?

A healthy daily rhythm is: review Overview, inspect current detections in Threats, confirm notable blocked entities, check any hosts with unusual activity, and review patch or posture items that need follow-through.

When should we use Terminal instead of staying in the UI?

Use Terminal when the UI has already narrowed the question and you need direct confirmation, evidence collection, or a targeted remediation step. It should support the workflow, not replace structured product usage.

What makes a rollout successful?

A successful rollout is measured by accurate host identity, believable telemetry, disciplined rule use, clear ownership for unblock decisions, and a team that understands which page to use for each operational task.

Keep Going

Move from documentation into deployment, product review, or common operator questions.

Use the installation page for the published deployment commands, continue into the features page for product capability detail, or jump into FAQ for quick operational answers.