CTEMEGA
Sentinel Active Defense

Your attack surface
never stands still — and neither does Sentinel.

A one-time scan is a photograph. Sentinel is continuous: it monitors registered assets, detects real drift and suspicious behavior, and — when your plan and policy allow — helps contain a threat before it becomes an incident.

ACTIVE DEFENSE

Monitor, detect, correlate, analyze, contain, verify

Signals come from Sentinel's own monitoring and from telemetry you forward from your own edge (nginx, and more sources over time). Related signals are correlated into an incident, analyzed — by AI when available, deterministically when it isn't — and, when policy allows, met with a scoped, time-boxed response: rate limiting, a challenge, or temporary containment. Every response is verified against a real observed effect before it's ever reported as active, and every one has an expiration and a rollback path.

SENTINEL ACTIVE DEFENSEEXAMPLE
Monitor
Detect
Correlate
Analyze
Contain
Verify
WHAT ONE INCIDENT LOOKS LIKE
1Threat detected
2Evidence correlated
3Risk scored
4Policy evaluated
5Response authorized
6Threat contained
7Protection verified

Every containment action is scoped, time-boxed, and reversible — what a given plan and policy allow to run automatically (vs. require a human to approve) is configured, never assumed. Sentinel reports its real coverage honestly: monitoring-only isn't shown as protected.

POLICY-CONTROLLED, NOT AUTOMATIC

What runs on its own depends on your plan and your policy

Detection and alerting are available on every plan. Rate limiting and challenge responses are available starting on Pro. Temporary containment and unattended automated response are Enterprise-only, and still require an explicit opt-in — nothing acts on your behalf by default. This isn't a firewall that blocks on its own; it's a policy-gated response layer you configure.

THE PROBLEM

What you scanned last month isn't what's exposed today

A new port opens, a service gets redeployed, a forgotten admin panel comes back online — none of that shows up in a report from six weeks ago. Exposure changes continuously; monitoring has to as well.

EXAMPLE

A drift, caught

Yesterday, three open ports. Today, a fourth — unexpected. This is exactly the kind of change Sentinel is built to catch, shown here as a labeled example.

EXAMPLE
YESTERDAY
:443
:80
:22
TODAY
:443
:80
:22
:8080NEW
Sentinel Drift
Mission
Analysis
Response
HOW IT WORKS

Baseline, change, drift, event, mission

Sentinel keeps a real history per asset and compares each new probe against it. A genuine change is classified as a drift event — and if you've configured a Mission for it, that event can trigger an automated response.

Baseline
Change
DriftClassified by type
Event
MissionIf configured

Sentinel compares each new probe against your asset's stored baseline. A real change — not noise — becomes a classified drift event, which can trigger a Mission.

KEY CAPABILITIES

What Sentinel actually does today

Continuous re-probing
Registered assets are re-checked on an ongoing basis, not just at scan time.
Real drift classification
Changes are classified by type — not just flagged as "different" — so you know what actually changed.
Honest history
When there's no data for a period, Sentinel shows that plainly rather than fabricating a result.
Event-driven, not report-driven
A drift becomes an event your team can react to immediately.
Behavioral detection
Request bursts, enumeration patterns, and other suspicious activity are detected from real traffic, not just configuration drift.
Verified, reversible response
A containment action is only ever reported as active after a real observed effect confirms it — and every one expires or rolls back.

Your exposure is moving. Is your security?

Start free — see your real attack surface in minutes.