tokens&
For enterprises
tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status
  1. Hackathon
  2. Project gallery
  3. SENTINEL
Trí Nguyễnabout 1 hour agoContributorEvent build

SENTINEL

Sentinel is an autonomous cyber-response agent that investigates real security incidents, safely tests remediation, takes approved action, and learns from every attack to respond faster next time.

Review the project

Start with the source code, then open the demo or video if available.

View GitHub repository
Watch demo video
Demo video
Watch demo video
Project description
Sentinel is an autonomous cyber-response agent that detects security incidents, investigates what actually happened, safely tests remediation, takes approved action, and learns from every attack. Our first incident is a leaked AWS CI credential. CloudTrail events stream into ClickHouse, where Sentinel compares activity against a 30-day baseline and detects suspicious behavior such as unusual IAM discovery, new access keys, or unseen networks. Once an incident opens, agents investigate using real evidence from CloudTrail, threat intelligence, and Semgrep. Every claim must cite an evidence ID. Sentinel builds an IAM attack graph to understand blast radius and proposes remediation as SAFE, REVIEW, or DANGEROUS actions. Before touching production, Sentinel proves the plan in a sandbox. It replays both the attacker and the legitimate CI workload. If a remediation stops the attacker but breaks CI, ablation identifies the harmful action, the planner repairs the plan, and Sentinel tests again. Approved changes are executed, verified, and recorded with rollback information. Afterward, a red-team agent mutates the attack to find evasions. A learner proposes new detectors and playbooks, while an evaluator rejects changes that regress on previous scenarios. Humans approve every promotion. Sentinel doesn't just respond to an incident. It learns how to respond faster and more safely the next time.
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • SSemgrep
Project gallery
Project links
  • GitHub repository
  • Demo video
Tools used
  • Guild.ai logoGuild.ai
  • ClickHouse logoClickHouse
  • SSemgrep