Interactive Demo

signal-engine-siem
Signal Sentry · for enterprise

Are you struggling with
storage of SIEM?

You already pay to store every log line. Almost nobody reads them. Signal Sentry reads all of them, puts the events that belong together in one place, and hands your team the few worth acting on - with Maya's read on the threat already attached. It uses logs you already keep. There's nothing to install on your servers.

2.88MFindings in one place
141 msTo search every one
25Attack types, named and mapped
1,080Accounts, 18 regions, one view

Those are figures from a live reference deployment - what the console shows, not a promise about yours. Signal Sentry is sold as an annual enterprise plan. There's no self-serve tier.

We recommend the walkthrough: it's free, takes 30 minutes, and we run it on a week of your own logs so you can see what it finds before you decide. Prefer to ask first? Message the team and we'll reply within 24 hours.

How it works

Inside
Signal Sentry

Three log sources in. One ranked list out. Every event is joined up, checked against 25 known attacks and scored before anyone on your team sees it.

☁️
ReadCloudTrail, VPC Flow and AWS WAF. Read-only.
›
⚙️
TidyThree formats turned into one
›
🔗
Join upEvents about the same thing, put together
›
🧠
Add factsThreat intel, the MITRE match, what it reached
›
🎯
Rank25 named attacks decide what needs a person
Overview

Know what is burning,
know what is noise,
know what to do first.

One screen for every account you run. Critical, High and Medium are counted apart, so 434,360 Medium findings can't bury the ones that are Critical. Traffic your WAF blocked is counted apart from traffic that reached you - only one of those is tonight's problem.

  • ›Critical, High and Medium counted apart
  • ›1,080 accounts and 18 regions on one screen
  • ›Blocked traffic kept separate from traffic that got through
  • ›Daily volume, so a spike shows the same day
See it in the demo above - free, no sign-up ›
🕑 Last 30 days ▾Until: NowAll sourcesCloudTrail (user activity)VPC flow (network)AWS WAF (web attacks)↻ Refresh2,882,407 findings · 2997 ms
695,945Critical
1,651,567High
434,360Medium
2,882,407Total findings
1,080Accounts with findings
18Regions
25Use cases
159,498WAF campaigns
188,489WAF defended
2,175,014Reached origin
Findings over time
21 Jul27 Jul2 Aug8 Aug14 Aug20 Aug
Coverage

25 use cases,
each mapped to MITRE ATT&CK.

You don't get raw events to work out for yourself. Every finding arrives with the attack already named - broken auth probing, SSRF, IAM privilege escalation - and its MITRE ATT&CK ID attached. It drops straight into the coverage map you already report on.

  • ›The attack is named, not left for you to work out
  • ›A MITRE ATT&CK ID on every finding
  • ›Severity scored the moment the match is made
  • ›Open any row to see the events behind it
Book a walkthrough - free, 30 minutes ›
Use-case coverage — 10 of 25, click a row to investigate
Use caseSeverityMITREFindings
Broken auth / JWT probingcriticalT1552 / T1078747,052
Rate-limit evasioncriticalT1498 / T1078126,809
Server-side request forgerycriticalT1190 / CAPEC-66464,186
Path traversal / local file inclusioncriticalT1083 / T100639,382
AI-assisted vulnerability scanningcriticalT1595.00229,465
SQL injection attemptcriticalT1190 / CAPEC-6617,523
IAM privilege escalationcriticalT1098 / T15481,219
Layer-7 DoS / cost exhaustionhighT1499.002831,391
Talking to malicious IP (threat intel)highTA0011 / T1071389,172
Session replay / challenge evasionhighT1550 / T1539192,227
Search

2.88 million findings,
searched in 141 ms.

Type a query and autocomplete finishes it, or click instead - source, severity, threat, port, WAF outcome are all one click. Same answer either way. Drag the chart to narrow the time window without touching the query.

  • ›Type a query, or click a filter - same result
  • ›141 ms to search 2.88 million findings
  • ›Drag the chart to zoom to a time window
  • ›Save the searches you run every morning
See it in the demo above - free, no sign-up ›
🕑 Last 30 days ▾Until: NowPathAllHas path≥ MediumComplete☆ Save↻ Refresh
🔍Type a query (autocomplete). E.g.: severity:critical AND dst_port:[5000 TO 6000]
Source👤 CloudTrail🌐 VPC flow🛡 AWS WAF
SeverityCriticalHighMediumLowInfo
Threats🌐 Malicious IP📡 Port scan📤 Data exfiltration+5 more
PortSSH 22RDP 3389MySQL 3306Redis 6379
Web attacks (WAF)💉 SQL injection📝 XSS📁 Path traversal / LFI☁ SSRF+9 more
WAF outcome🛡 Defended (blocked)⚠ Reached origin🔥 High risk (≥80)+2 more
Message Count2,882,309 results · 141 ms
21 Jul27 Jul2 Aug8 Aug14 Aug20 Aug

Drag across the chart to zoom to a time window

Freshness

You can see
how current the data is.

Most tools tell you they're up to date. This one shows you. Freshness is read from the findings index itself - the newest event in it is the last sync - so a stalled feed is visible the moment it stalls, not a week later when someone asks.

  • ›Document count and share, for each of the 3 sources
  • ›Size and time of the last sync batch
  • ›Cluster health on the same screen as the data
  • ›Measured from the index, not reported by the sender
Talk to our team - we reply within 24 hours ›
Data freshness by sourceaggregated live from the findings index — newest indexed event = last sync; nothing is pushed
Total findings2,940,164across 3 sources
CloudTrailuser activity• 25m ago
13,266 docs · 0.5%
last sync batch: 29 docs (15m window ending 15:47:50)
VPC Flownetwork• 25m ago
563,395 docs · 19%
last sync batch: 66 docs (15m window ending 15:47:57)
AWS WAFweb attacks• 28m ago
2,363,503 docs · 80%
last sync batch: 1,532 docs (15m window ending 15:44:27)
98.1%CPU
58%Memory
66.9%Disk
2,948,840ES docs
YellowCluster
861Log errors
0.01Load (1m)
Who it is for

Built for large teams.
Not for everyone.

Signal Sentry earns its place once you have thousands of machines, several cloud accounts, and more logs a day than any person can read. If that's not you yet, our CSPM and asset scanning cover the same ground for a lot less - and we'll tell you so on the call rather than sell you this.

You have a SOC team

We cut what reaches them.

Events arrive grouped, named and scored, so your analysts spend the day on the 1% that's real instead of sorting the other 99%. Everything they need to decide sits on the finding itself - no jumping between six consoles to piece together what happened.

You do not have a SOC team

Then Signal Sentry is the SOC team.

Maya does the work a level-one analyst would do. It joins related events, works out what's exposed, scores how bad it is and drafts the fix. It only comes to a person when there's a real decision to make - and it brings the context with it.

Sold as an annual enterprise plan. There's no self-serve tier and no free trial of the full product - the demo above is the free way to see it working. Tell us your log volume and we'll tell you honestly whether you need this yet.

Get started

See it on your own logs.

We'll connect one of your log sources and show you what a week of your own data looks like once it's joined up. Engineers on the call. No slides.

Free, 30 minutes. Read-only access to logs you already keep - nothing to install.