Signal Sentry · for enterprise
You already pay to store every log line. Almost nobody reads them. Signal Sentry reads all of them, puts the events that belong together in one place, and hands your team the few worth acting on - with Maya's read on the threat already attached. It uses logs you already keep. There's nothing to install on your servers.
Those are figures from a live reference deployment - what the console shows, not a promise about yours. Signal Sentry is sold as an annual enterprise plan. There's no self-serve tier.
We recommend the walkthrough: it's free, takes 30 minutes, and we run it on a week of your own logs so you can see what it finds before you decide. Prefer to ask first? Message the team and we'll reply within 24 hours.
How it works
Three log sources in. One ranked list out. Every event is joined up, checked against 25 known attacks and scored before anyone on your team sees it.
CloudTrail, VPC Flow and AWS WAF. Read-only.
Three formats turned into one
Events about the same thing, put together
Threat intel, the MITRE match, what it reached
25 named attacks decide what needs a person
Overview
One screen for every account you run. Critical, High and Medium are counted apart, so 434,360 Medium findings can't bury the ones that are Critical. Traffic your WAF blocked is counted apart from traffic that reached you - only one of those is tonight's problem.
2,882,407 findings · 2997 ms
695,945
Critical
1,651,567
High
434,360
Medium
2,882,407
Total findings
1,080
Accounts with findings
18
Regions
25
Use cases
159,498
WAF campaigns
188,489
WAF defended
2,175,014
Reached origin
Findings over time
Coverage
You don't get raw events to work out for yourself. Every finding arrives with the attack already named - broken auth probing, SSRF, IAM privilege escalation - and its MITRE ATT&CK ID attached. It drops straight into the coverage map you already report on.
| Use case | Severity | MITRE | Findings |
|---|---|---|---|
| Broken auth / JWT probing | critical | T1552 / T1078 | 747,052 |
| Rate-limit evasion | critical | T1498 / T1078 | 126,809 |
| Server-side request forgery | critical | T1190 / CAPEC-664 | 64,186 |
| Path traversal / local file inclusion | critical | T1083 / T1006 | 39,382 |
| AI-assisted vulnerability scanning | critical | T1595.002 | 29,465 |
| SQL injection attempt | critical | T1190 / CAPEC-66 | 17,523 |
| IAM privilege escalation | critical | T1098 / T1548 | 1,219 |
| Layer-7 DoS / cost exhaustion | high | T1499.002 | 831,391 |
| Talking to malicious IP (threat intel) | high | TA0011 / T1071 | 389,172 |
| Session replay / challenge evasion | high | T1550 / T1539 | 192,227 |
Search
Type a query and autocomplete finishes it, or click instead - source, severity, threat, port, WAF outcome are all one click. Same answer either way. Drag the chart to narrow the time window without touching the query.
Source
Severity
Threats
Port
Web attacks (WAF)
WAF outcome
2,882,309 results · 141 ms
Message Count
Drag across the chart to zoom to a time window
Freshness
Most tools tell you they're up to date. This one shows you. Freshness is read from the findings index itself - the newest event in it is the last sync - so a stalled feed is visible the moment it stalls, not a week later when someone asks.
aggregated live from the findings index — newest indexed event = last sync; nothing is pushed
CloudTrail
user activity • 25m ago
docs · 0.5%
VPC flow
network • 25m ago
docs · 19%
AWS WAF
web attacks • 28m ago
docs · 80%
98.1%
CPU
58%
Memory
66.9%
Disk
2,948,840
ES docs
Yellow
Cluster
861
Log errors
0.01
Load (1m)
Who it is for
Signal Sentry earns its place once you have thousands of machines, several cloud accounts, and more logs a day than any person can read. If that's not you yet, our CSPM and asset scanning cover the same ground for a lot less - and we'll tell you so on the call rather than sell you this.
You have a SOC team
Events arrive grouped, named and scored, so your analysts spend the day on the 1% that's real instead of sorting the other 99%. Everything they need to decide sits on the finding itself - no jumping between six consoles to piece together what happened.
You do not have a SOC team
Maya does the work a level-one analyst would do. It joins related events, works out what's exposed, scores how bad it is and drafts the fix. It only comes to a person when there's a real decision to make - and it brings the context with it.
Sold as an annual enterprise plan. There's no self-serve tier and no free trial of the full product - the demo above is the free way to see it working. Tell us your log volume and we'll tell you honestly whether you need this yet.
Get started
We'll connect one of your log sources and show you what a week of your own data looks like once it's joined up. Engineers on the call. No slides.
Free, 30 minutes. Read-only access to logs you already keep - nothing to install.