Monitor, analyze, and neutralize SSH-based attacks in real-time. CloudSentinel maps adversary behaviors to the MITRE ATT&CK framework with an interactive war room dashboard powered by AI.
Active Defense
CloudSentinel operates as a layered defense system that captures, analyzes, and responds to SSH-based threats autonomously.
An SSH honeypot sensor captures attacker sessions, credentials, commands, and SSH client fingerprints (HASSH) in real-time. Every keystroke is recorded.
Captured data is streamed to ClickHouse for high-speed analytics. Each session is automatically mapped to MITRE ATT&CK techniques and fed to an AI-powered analysis engine.
The SOAR engine automatically triggers iptables firewall blocks, publishes threat intelligence events, and can execute active defense playbooks - all within milliseconds.
Capabilities
Every component is designed for real-world threat hunting and incident response workflows.
Interactive D3.js world map showing attack origins and geographic densities live.
Replay full attacker CLI terminal sessions in a simulated terminal environment.
Security Orchestration triggers iptables blocks within 15ms of malicious detection.
System Architecture
A horizontally scalable architecture designed for production deployment across multiple cloud regions.
Captures attacker sessions, credentials, and TTY data on DigitalOcean
High-speed columnar storage for real-time query and aggregation
War Room UI with live WebSocket telemetry and AI-powered chat
Automated blocking, threat intel publishing, and active playbooks
Access the CloudSentinel War Room to monitor live attacks, replay attacker sessions, and take automated defensive action - all from a single dashboard.
Enter War Room