Block the exploit
that actually worked.
Sentinel is not another signature list. It is configured from the findings a real penetration test proved against your systems — it knows the exact request that got in, because it is the one we sent.
One attempt. Blocked everywhere.
Most controls block at the box that saw the traffic, so an attacker simply moves to the next host and tries again. Sentinel runs as agents sharing one control plane, which means a source that burns a single exploit attempt loses your entire infrastructure.
One exploit attempt · every protected host
AlertMonitor infrastructure
BLOCKED ON 18 / 18 HOSTS
The attacker spent one exploit against one host and lost access to the whole infrastructure. A firewall blocks at the box that saw the traffic; Sentinel blocks everywhere an agent is running, because the agents share one control plane.
How it decides
Blocking is only useful if you trust it, and trust comes from knowing what the decision rests on. Several independent signals have to agree before Sentinel acts.
Is this someone we know?
Known-good sources are checked first, before anything else is considered. The fastest way to break trust in a blocking tool is to block a customer, so that question gets asked before the scoring starts.
Does anyone else recognize it?
The source is corroborated against our own indicators and external reputation data including AbuseIPDB and VirusTotal. A hit raises confidence; it is never the sole basis for a decision.
Does the behavior fit?
Geography and the site's normal traffic baseline are weighed in. Traffic from where your users actually are, behaving like your users actually behave, is treated very differently from traffic that is neither.
Your threshold, not ours
The confidence level required to act is set per website, and you set it. Run it in manual mode and Sentinel will recommend rather than act until you are comfortable with what it is seeing.
We publish the architecture, not the weights. The specific signal order and thresholds stay private for the obvious reason — a published scoring model is an evasion guide.
Why this exists
Modern WAFs do not stop a real attacker. We know, because we get past them.
Not occasionally, and not by finding some exotic flaw in the product. On engagement after engagement we walk through web application firewalls that are switched on, licensed and actively blocking — using the kind of bypass work any competent attacker does.
That claim is worth nothing unless the defense was provably working, so we run a control first: an ordinary commodity scan from a separate address. It gets blocked, exactly as designed. Then the real attack goes through the same WAF and is not seen. The control test, published in full.
Three reasons, and none of them are a scandal
01 · The rules
It only knows published attacks
A signature list encodes what somebody already found and wrote up. An attack written during your engagement has no signature to match, and the advanced bypass techniques attackers actually use were never in the ruleset to begin with.
02 · The deployment
Or it is simply wired wrong
The origin still reachable around the edge. Rules evaluated in an order nobody checked. An exception added for a launch three years ago that was never removed. The product works; the installation does not.
03 · The tuning
Or it was turned down to stop blocking customers
Tuned tight, a generic ruleset blocks real revenue. So it gets loosened, or moved to monitor-only, and everyone quietly agrees not to raise it again. The setting that would protect you is the one that costs you money.
Sentinel was built to end this. It learns your site.
Every failure above comes from the same root: the thing making the decision has no idea what your application does, so it falls back on somebody else’s generic list. Sentinel builds a model of your actual traffic instead — which routes exist, what parameters they legitimately take, the shapes and sequences your real users produce. Valid traffic stops being a guess and becomes something it has measured.
Bypasses have nothing to hide behind
An encoding trick only works if the inspector is matching patterns. When the question is “does this belong on this route at all”, obfuscating the payload does not help — it makes the request stranger, not safer.
It retrains when you ship
Add a page, add a form, change a feature, and it learns the new surface rather than treating it as hostile. A deploy does not become a wave of blocked customers on Monday morning.
So blocking can stay on
Reason 03 disappears when the baseline is your own traffic. Active blocking becomes a decision you can afford, which is the only state in which any of this protects anybody.
One thing this is not
A normal session is not a trust pass. Somebody who browses like a customer for ten minutes and then attacks still trips the detection, and if active blocking is configured, still gets blocked. The baseline describes what valid traffic looks like — it does not vouch for the person sending it.
The difference
Two things a web firewall structurally cannot do.
Even a WAF that worked perfectly would still be one product, sitting in one place, with no idea which parts of your environment are actually weak. Sentinel is neither of those things, and that is the part competitors cannot copy by improving their rules.
01 · Response is instant and everywhere
One host proves an address hostile. Every host stops answering it.
A firewall in front of your website can only act on traffic that reaches your website. We are already on the endpoints, the servers and the workstations — so the moment an address is proven hostile anywhere, it is blocked across every protected system at once.
Not a ticket, not a change window, not a rule somebody pushes to one appliance in the morning. The attacker loses the entire environment on the strength of what they did to one machine in it.
02 · It knows where you are weak
We tested you. So the weak paths get watched by name.
A generic product has to guess what matters on your systems. We do not have to guess — we broke in, so we know exactly which paths are exposed, which are reachable and which would actually hurt.
Those specific weaknesses are monitored specifically. You get told what to fix and why it matters, and until your team has closed it, Sentinel holds the line on that exact path. Remediation stops being a race you run unprotected.
Finding the hole and holding it shut are usually sold by two different companies who never speak. Here they are the same system, and the second one is configured by what the first one proved.
It answers the question you actually have
A blocking tool tells you it blocked something. Your team's next question is always the same, and it is never answered: did anything get through before it was stopped?
When Sentinel acts, it opens a forensic investigation across the infrastructure to find out. If the attack succeeded anywhere, you get an alert with the evidence attached. If it did not, the case closes itself.
Why that matters more than the block
Every other tool in your stack generates work. Alerts pile up, nobody has time to work through them, and the genuine ones get buried in the noise of the ones that turned out to be nothing.
Sentinel is the rare thing that removes work instead of adding it. The detections that did not matter never reach a human at all, which is what makes the ones that do reach you worth reading.
You hold the controls
Nothing here is a black box you have to take on faith.
Five minutes to permanent
Block durations are yours to choose per site, from a brief cool-off to an indefinite ban, with one-click unblock whenever you want it lifted.
Per-site policy
Thresholds, durations and alert routing are configured per website and per server, because a marketing site and a payment application do not deserve the same trigger finger.
Monitor-only mode
Nothing has to block on day one. Run Sentinel in observation mode, watch what it would have done, and turn enforcement on when the evidence has convinced you.
Included for 90 days with every engagement
A penetration test report is an uncomfortable object to be holding: a written, evidenced list of ways into your business that will take your engineering team weeks and a release cycle to close. Between delivery and remediation you are not less exposed — you are exposed in writing.
So covering that window is part of the engagement rather than something we sell you afterwards, and it deliberately extends to desktops, firewalls and switches that were never in the test scope. Coverage runs until the finding is retested and closed.
After that you keep it at the normal rate, month to month, or you stop. No long-term contract on anything we sell — 30 days' notice is all we ask.
See engagement pricingQuestions about Sentinel
Find it, then hold the line
We test your systems properly, then protect what we proved was reachable until your team has closed it.