Features / Overview

One platform. Every layer covered.

A Rust-built SIEM and compliance platform: detection, vulnerability management, cloud and container security, and continuous EU compliance in a single engine.

  • SIEM
  • Vulnerability scanning
  • Compliance
  • Cloud & containers
001 / Endpoint

Security monitoring

Endpoint security monitoring with real-time file integrity monitoring, log collection, rootkit detection, and security configuration assessment across Linux, Windows, and macOS.

  • File Integrity Monitoring (FIM) with inotify, ReadDirectoryChangesW, and FSEvents
  • Centralized log collection with 32 built-in decoders
  • Rootkit and malware detection via rootcheck
  • Security Configuration Assessment (SCA) with CIS benchmark policies
  • Active response and automated remediation playbooks
  • Syscollector inventory: packages, ports, processes, hardware
Sentrios security alerts feed with severity and source detail
Alerts surface in real time as agents and syslog stream in.
002 / Compliance

Compliance automation

A native compliance engine built for European regulatory requirements, not a plugin or afterthought. Every alert and vulnerability is mapped to the controls it affects.

  • NIS2 Article 21 security measures and Article 23 incident reporting
  • GDPR Article 32 scoring for encryption, access control, and breach risk
  • ISO 27001:2022 Annex A control assessment with gap scoring
  • Per-gap remediation guidance and PDF evidence export
  • Executive compliance dashboards with trend tracking
  • Danish-language reporting (da-DK)
Sentrios NIS2 compliance scorecard with Article 21 controls
NIS2 Article 21 posture, scored continuously per control.
003 / Detection

Threat detection & correlation

A rule engine with multi-event correlation identifies complex attack chains as they unfold. 125+ detection rules across 22 YAML files ship out of the box.

  • 125+ detection rules: brute force, lateral movement, privilege escalation, and more
  • Multi-event correlation links related events across hosts and time windows
  • Every alert tagged to MITRE ATT&CK tactics and techniques
  • Kill chain analysis from Reconnaissance to Exfiltration
  • Custom rule creation and confidence-weighted tuning
  • Forensic timelines for incident reconstruction
Sentrios MITRE ATT&CK matrix mapping detections to techniques
Detections placed on the ATT&CK matrix, tactic by technique.
004 / Vulnerabilities

Vulnerability management

A built-in 5-phase scanner goes from network discovery to continuous risk management. No external Nessus or Qualys license required.

  • Phase 1 — active network recon: ARP/ICMP/TCP discovery, OS fingerprinting, 6 timing profiles
  • Phase 2 — service intelligence: 206 signatures across 20+ protocols, NVD API 2.0 sync, TLS analysis (Heartbleed, POODLE, ROBOT)
  • Phase 3 — authenticated scanning over SSH, WinRM, SNMP, Docker API, K8s API with backport-aware comparison
  • Phase 4 — web/API DAST: OWASP Top 10 coverage, intelligent crawler, GraphQL/REST fuzzing
  • Phase 5 — continuous assessment: scan orchestration, EPSS scoring, CISA KEV correlation, risk prioritization
  • CVE lookup under 1ms via RocksDB prefix scan across 250K+ CVEs with CVSS scoring
Sentrios vulnerability management view with CVE severity and EPSS scoring
CVEs ranked by CVSS, EPSS, and KEV status for prioritization.
005 / Cloud

Cloud & container security

Native monitoring for modern infrastructure: Docker, Kubernetes, and all three major cloud providers. Built into the same agent — no separate sensors.

  • Docker container image layer scanning for CVEs and misconfigurations
  • Kubernetes pod, namespace, and cluster-level monitoring
  • AWS, Azure, and GCP cloud security posture management (CSPM)
  • Container runtime protection and anomaly detection
  • K8s manifest security analysis and admission policy checks
  • Cloud asset inventory with continuous drift detection
006 / Threat intel

Threat intelligence

An enrichment pipeline integrates MISP, the NVD API, CISA KEV, and ExploitDB so alerts arrive with IOC matches and exploit context already attached.

  • MISP, NVD, CISA KEV, and ExploitDB feeds with IOC enrichment
  • Alerts arrive pre-matched against known indicators of compromise
  • Exploit availability context surfaced alongside each finding
  • AlienVault OTX integration for community threat sharing
  • IOC matches linked directly to the detections they affect
  • Continuous feed sync keeps intelligence current
Sentrios threat intelligence view with IOC matches and exploit context
IOC matches and exploit context, attached to live detections.
007 / Integrations

Integration ecosystem

Connect Sentrios to your existing stack through SIEM forwarding, ticketing, and notification channels. 110+ REST API endpoints with full OpenAPI documentation.

  • SIEM forwarding to Splunk and Elasticsearch
  • Ticketing integration with Jira and ServiceNow
  • Notifications via Slack, Microsoft Teams, email, and webhooks
  • 110+ REST API endpoints for custom integrations
  • Threat intel via MISP, NVD, and AlienVault OTX with IOC enrichment
  • Log forwarding and enrichment with structured JSON output
008 / Code

Code security scanner

Scan repositories and codepaths for vulnerabilities before they reach production. Secret detection, dependency analysis, and pattern matching across 8 languages.

  • Git repository and local path scanning
  • Secret detection: API keys, passwords, and tokens hardcoded in source
  • SCA dependency analysis: package.json, requirements.txt, Cargo.toml, pom.xml
  • Code pattern matching: SQL injection, eval(), unsafe deserialization, command injection sinks
  • IaC scanning: Terraform misconfigs, Dockerfile issues, K8s manifests
  • Python, JavaScript/TypeScript, Java, C#, Go, Rust, PHP, Ruby
006 / Get started

Ready to take command?

See the Rust-built engine, the detection rules, and continuous NIS2 scoring on your own data. We will walk you through the full platform.

  • EU data sovereignty
  • Self-hosted
  • Setup in under 30 minutes