Sentinel is an autonomous cyber-response agent that detects security incidents, investigates what actually happened, safely tests remediation, takes approved action, and learns from every attack.
Our first incident is a leaked AWS CI credential. CloudTrail events stream into ClickHouse, where Sentinel compares activity against a 30-day baseline and detects suspicious behavior such as unusual IAM discovery, new access keys, or unseen networks.
Once an incident opens, agents investigate using real evidence from CloudTrail, threat intelligence, and Semgrep. Every claim must cite an evidence ID. Sentinel builds an IAM attack graph to understand blast radius and proposes remediation as SAFE, REVIEW, or DANGEROUS actions.
Before touching production, Sentinel proves the plan in a sandbox. It replays both the attacker and the legitimate CI workload. If a remediation stops the attacker but breaks CI, ablation identifies the harmful action, the planner repairs the plan, and Sentinel tests again. Approved changes are executed, verified, and recorded with rollback information.
Afterward, a red-team agent mutates the attack to find evasions. A learner proposes new detectors and playbooks, while an evaluator rejects changes that regress on previous scenarios. Humans approve every promotion.
Sentinel doesn't just respond to an incident. It learns how to respond faster and more safely the next time.