> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cyberup24.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Optional Software

Beyond the applications installed by default, the LARK supports additional applications that extend its capabilities. These applications are optional: they are not part of the standard installation and are added only when the capability they provide is required.

<Note>
  The applications on this page are not installed by default. The default set is covered on the applications page. The procedures for installing and removing applications are in the administration section.
</Note>

## Available options

The following applications are commonly added to a LARK. Each layers onto the default stack rather than replacing any part of it.

<AccordionGroup>
  <Accordion title="RunReveal: SIEM and log correlation">
    RunReveal aggregates logs and alerts from across the appliance, correlates them, and applies detection rules. When present, it serves as the central point for searching and correlating collected data. Without it, the underlying data is still captured and stored by the default applications; RunReveal adds the correlation and search layer.
  </Accordion>

  <Accordion title="Grafana: dashboards and visualization">
    Grafana provides dashboards for visualizing data held on the appliance, supporting the identification of patterns and trends and the monitoring of activity over time. It reads from the appliance's stored data and presents it visually.
  </Accordion>

  <Accordion title="Nessus: vulnerability scanning">
    Nessus performs active vulnerability scans against hosts on a network. In contrast to the passive monitoring the appliance performs by default, Nessus actively assesses systems, and is used where active vulnerability assessment is required alongside passive observation.
  </Accordion>

  <Accordion title="Tracecat: security automation and case work">
    Tracecat provides automation workflows and case management for investigations, with an AI assistant that operates from the case record. It can run automated playbooks in response to activity and provides analysts a single timeline to work from. When present, it serves as the system of record for investigation work.
  </Accordion>
</AccordionGroup>

<Warning>
  Because these applications are optional, a given appliance may or may not have any of them installed. The applications present on an appliance should be confirmed before relying on a capability described here. Where this documentation refers to an optional application, it is identified as optional.
</Warning>

## Additional applications

The options above are the applications most commonly added, but they are not the only ones available. Administrators may install other approved applications from the appliance's on-board source. The administration section describes how application installation works and which sources are available.
