One platform. Every layer covered.
A Rust-built SIEM and compliance platform: detection, vulnerability management, cloud and container security, and continuous EU compliance in a single engine.
- SIEM
- Vulnerability scanning
- Compliance
- Cloud & containers
Security monitoring
Endpoint security monitoring with real-time file integrity monitoring, log collection, rootkit detection, and security configuration assessment across Linux, Windows, and macOS.
- File Integrity Monitoring (FIM) with inotify, ReadDirectoryChangesW, and FSEvents
- Centralized log collection with 32 built-in decoders
- Rootkit and malware detection via rootcheck
- Security Configuration Assessment (SCA) with CIS benchmark policies
- Active response and automated remediation playbooks
- Syscollector inventory: packages, ports, processes, hardware
Compliance automation
A native compliance engine built for European regulatory requirements, not a plugin or afterthought. Every alert and vulnerability is mapped to the controls it affects.
- NIS2 Article 21 security measures and Article 23 incident reporting
- GDPR Article 32 scoring for encryption, access control, and breach risk
- ISO 27001:2022 Annex A control assessment with gap scoring
- Per-gap remediation guidance and PDF evidence export
- Executive compliance dashboards with trend tracking
- Danish-language reporting (da-DK)
Threat detection & correlation
A rule engine with multi-event correlation identifies complex attack chains as they unfold. 125+ detection rules across 22 YAML files ship out of the box.
- 125+ detection rules: brute force, lateral movement, privilege escalation, and more
- Multi-event correlation links related events across hosts and time windows
- Every alert tagged to MITRE ATT&CK tactics and techniques
- Kill chain analysis from Reconnaissance to Exfiltration
- Custom rule creation and confidence-weighted tuning
- Forensic timelines for incident reconstruction
Vulnerability management
A built-in 5-phase scanner goes from network discovery to continuous risk management. No external Nessus or Qualys license required.
- Phase 1 — active network recon: ARP/ICMP/TCP discovery, OS fingerprinting, 6 timing profiles
- Phase 2 — service intelligence: 206 signatures across 20+ protocols, NVD API 2.0 sync, TLS analysis (Heartbleed, POODLE, ROBOT)
- Phase 3 — authenticated scanning over SSH, WinRM, SNMP, Docker API, K8s API with backport-aware comparison
- Phase 4 — web/API DAST: OWASP Top 10 coverage, intelligent crawler, GraphQL/REST fuzzing
- Phase 5 — continuous assessment: scan orchestration, EPSS scoring, CISA KEV correlation, risk prioritization
- CVE lookup under 1ms via RocksDB prefix scan across 250K+ CVEs with CVSS scoring
Cloud & container security
Native monitoring for modern infrastructure: Docker, Kubernetes, and all three major cloud providers. Built into the same agent — no separate sensors.
- Docker container image layer scanning for CVEs and misconfigurations
- Kubernetes pod, namespace, and cluster-level monitoring
- AWS, Azure, and GCP cloud security posture management (CSPM)
- Container runtime protection and anomaly detection
- K8s manifest security analysis and admission policy checks
- Cloud asset inventory with continuous drift detection
Threat intelligence
An enrichment pipeline integrates MISP, the NVD API, CISA KEV, and ExploitDB so alerts arrive with IOC matches and exploit context already attached.
- MISP, NVD, CISA KEV, and ExploitDB feeds with IOC enrichment
- Alerts arrive pre-matched against known indicators of compromise
- Exploit availability context surfaced alongside each finding
- AlienVault OTX integration for community threat sharing
- IOC matches linked directly to the detections they affect
- Continuous feed sync keeps intelligence current
Integration ecosystem
Connect Sentrios to your existing stack through SIEM forwarding, ticketing, and notification channels. 110+ REST API endpoints with full OpenAPI documentation.
- SIEM forwarding to Splunk and Elasticsearch
- Ticketing integration with Jira and ServiceNow
- Notifications via Slack, Microsoft Teams, email, and webhooks
- 110+ REST API endpoints for custom integrations
- Threat intel via MISP, NVD, and AlienVault OTX with IOC enrichment
- Log forwarding and enrichment with structured JSON output
Code security scanner
Scan repositories and codepaths for vulnerabilities before they reach production. Secret detection, dependency analysis, and pattern matching across 8 languages.
- Git repository and local path scanning
- Secret detection: API keys, passwords, and tokens hardcoded in source
- SCA dependency analysis: package.json, requirements.txt, Cargo.toml, pom.xml
- Code pattern matching: SQL injection, eval(), unsafe deserialization, command injection sinks
- IaC scanning: Terraform misconfigs, Dockerfile issues, K8s manifests
- Python, JavaScript/TypeScript, Java, C#, Go, Rust, PHP, Ruby
Ready to take command?
See the Rust-built engine, the detection rules, and continuous NIS2 scoring on your own data. We will walk you through the full platform.
- EU data sovereignty
- Self-hosted
- Setup in under 30 minutes