Security log analysis, plain-English

A security analyst
in a box for
your logs.

Upload a Linux auth log, an Apache/Nginx access log, a firewall log, or a Windows Event Log export. Sentinel finds brute-force attacks, scanning activity, privilege escalation, and web attacks — and tells you what happened without the SIEM jargon.

No agent to install. Upload a file, get findings back in seconds.

auth.log — 14 lines analyzed
7Failed logins
1Attacking IP
7Findings
Critical

Successful login after repeated failures

203.0.113.9 succeeded logging in as 'root' after 7 failed attempts within 30 minutes.

Medium

Brute-force SSH attempts

7 failed password attempts from 203.0.113.9 against 7 usernames.


What it catches

Threshold-tuned detection across every log format it supports — not a keyword search.

Brute-force & compromise

Repeated failed logins, username enumeration, and the successful login that follows one.

Scanning & recon

Port scans, directory/endpoint enumeration, and sensitive-path probing — with noisy background scans surfaced in aggregate, not spammed as alerts.

Privilege escalation

Direct root logins, su/sudo misuse, and accounts added to privileged groups.

Plain-English reports

Every finding names the who, what, and how many — no SIEM query language required.

Linux auth.log Apache / Nginx Firewall (iptables/ufw) Windows Event Log