Sentinel Suite โ€“ Cybersecurity Integrated for indispensable SMEs

Sentinel Suite โ€“ Integrated Cybersecurity for SMEs

Overview Suite

Sentinel Suite is a modular cybersecurity platform designed specifically for startups and Italian SMEs that need enterprise-grade protection without the complexity and costs of traditional solutions.

The suite consists of 3 main tools covering the entire life cycle of IT security: from preventive hardening to vulnerability management, from perimeter protection to threat intelligence. Each module works independently but can integrate with others for a coordinated and automated defense.

Compliance: NIS2 (75%), ISO 27001 (80%), PCI-DSS (65%)

Deployment: On-premise, compatible with Debian/Ubuntu, scalable architecture from 5 to 500+ assets.


๐Ÿ”ง MicroSIEM โ€“ Hardening and Continuous Monitoring

What does he do?

MicroSIEM is an advanced web console for automated hardening and continuous monitoring of Linux servers. It implements best practice (CIS Benchmarks, NIST) security configurations and detects suspicious or non-compliant activities in real time.

Key Features

Automated Hardening:

  • Operating system configuration via sysctl, AppArmor/SELinux
  • Local firewall management (iptables) with default policies
  • Disable unnecessary services and reduce attack surface
  • Default models for server roles (web, database, gateway)
  • Template compliance (NIS2, ISO 27001, PCI-DSS)

Real Time Monitoring:

  • Advanced audit logging (auded, ulogd) with correlation rules
  • Remote Connection Monitoring (SSH, RDP, VNC)
  • Tracking privileged user activities and sudo commands
  • Detection privilege escalation attributes
  • Check critical file integrity (Shaf-512)

Multi-channel Alerting:

  • Email Notifications, Slack, Telegram, WhatsApp
  • Alert on unauthorised configuration changes
  • Unexpected service start report
  • Real-time Dashboard with metric compliance

Centralised Management:

  • Auto host discovery via ARP scan
  • Deployment configurations via SSH with elliptical keys
  • Role-based access control (Sysadmin/Reporter)
  • Executive reporting for management

๐Ÿ“ฆ Intellidog Module (Premium Add-on)

Intellidog is the advanced threat intelligence module for MicroSIEM that transforms responsive to proactive monitoring. Available as a premium upgrade, it adds vulnerability-exploit correlation capabilities and automated virtual patching.

Intellidog Features

Vulnerability-Exploit correlation:

  • Integration with Sentinel Core for import vulnerabilities
  • Automatic Enrichment with IoC (Indicators of Compromise) from external sources:
    • MISP (Malware Information Sharing Platform)
    • Shodan (Internet-wide scanning data)
    • AlienVault OTX (Open Threat Exchange)
    • VirusTotal, AbuseIPDB, Talos Intelligence
  • Mapping CVE โ†’ Known exploits โ†’ Active campaigns

Behavioral Analysis System:

  • syscall monitoring via auditd/e BPF
  • Parsing log applications (Apache, Nginx, SSH, database)
  • Network traffic analysis from PCAP (Firedog integration)
  • Detection behavioural abnormalities (UEBA-like)
  • Identification pattern exploit (buffer overflow, command injection, transverse directory)

Exploit Detection:

  • Correlation: "CVE present on asset" + "Traffic with payload exploit detected"
  • Confidence scoring: probability of exploitation (Low/Medium/High/Confirmed)
  • Timeline reconstruction attack with evidence
  • Post-exploitation activities identification (lateral movement, privilege escalation)

Risk Mitigation & Virtual Patching:

  • Automatic mitigation: If exploit detected but not available patch:
    • Malevolent traffic pattern block via Firedog (WAF-like rules)
    • Insulation of compromised asset network
    • Disable temporary vulnerable functionality
  • Virtual Patching: IDS/IPS-like rules to neutralize exploits without patch
  • Priority recommendations: "Confirmed X Vulnerability exploited โ†’ patches within 24h"

Threat Hunting Proactive:

  • Query library Sigma rules for search for threats
  • Historical IoC search on log retention (30-90 days)
  • Automatic hunting campaign on new zero-day CVEs
  • Dedicated Dashboard with threat timeline

Cases of Intellidog use:

  • Accident validation: Confirm if vulnerability detected is actively exploited
  • Zero-day response: Check immediately whether CVE has just been released already exploited in the past
  • Threat hunting: Proactive research not detected
  • Virtual patching: Protect non patchable legacy systems (Windows Server 2008, old appliances)
  • Compliance: Demonstrate to auditor that vulnerability is mitigated even without patch

Cases of use MicroSIEM

  • Hardening web servers exposed to the Internet
  • PCI-DSS compliance for e-commerce environments
  • Monitoring privileged accesses for audit trail
  • Secure cloud environment configuration (AWS, Azure, GCP)
  • Threat hunting proactive with Intellidog module (premium)

Technologies

  • Backend: Python/Flask or Django
  • Frontend: React/TypeScript
  • Database: PostgreSQL or InfluxDB
  • Intel Threat (Intellidog): MISP integration API, Shodan, AlienVault
  • Advanced analysis (Intellidog): eBPF, audited correlation engine
  • Server: Nginx on Linux

๐Ÿ” Sentinel Core โ€“ Vulnerability Management Intelligent

What does he do?

Sentinel Core is a vulnerability management enterprise system that centralizes, prioritizes and orchestrates remediation by coordinating technical teams. Aggregate results from multiple scanners and apply artificial intelligence to identify real risks in the context of your business.

Key Features

Acquisition Vulnerability:

  • Scanner integration: Nessus, OpenVAS, Qualys, Nexpose, Burp Suite, Acunetix, Nmap
  • Automatic import via REST API
  • Format media: XML, JSON, CSV
  • Custom Tool Plugin System

Cataloging and Enrichment:

  • Common Vulnerability Scoring System
  • Scoring EPSS (Exploit Prediction Score System)
  • CVE/NVD database correlation
  • Mapping CWE (Common Weakness Enumeration)
  • Geolocation asset and service identification

Advanced Prioritization:

  • Composite risk scoring (CVSS + EPSS + Business Impact + Asset Exposure)
  • Patch availability assessment and remediation complexity
  • Suggested SLA-based timelines
  • Effort estimation for interventions

Workflow and Orchestration:

  • Automatic task assignment to competent teams
  • Tracking remediation with deadlines
  • Automatic escalation on delays
  • Approved workflow for critical changes
  • Slack/Telegram/Email Notifications

Multi-Level Reporting:

  • Executive Dashboard with Trend and KPI (MTTR, SLA compliance)
  • Operational reports for technical teams
  • Technical details with PoC and remediation steps
  • Export PDF/JSON/CSV/ XML

SOAR integration:

  • Connector for Splunk SOAR, Cortex XSOAR, IBM Resilient
  • Automatic ticket creation (ServiceNow, Jira)
  • Playbook execution for standard remediation

Cases of use

  • Vulnerability management for MSP/MSSP with multiple customers
  • DevOps/SecOps/NetOps team coordination in medium organisations
  • Compliance scanning NIS2 with automatic reporting
  • Bug bounty program management

Technologies

  • Backend: Rust (Axum framework)
  • Database: PostgreSQL with UUID
  • API: REST with JWT authentication
  • Architecture: Microservices-ready, high availability

๐Ÿ”ฅ Firedog โ€“ Advanced Firewall & Threat Detection

What does he do?

Firedog is an advanced firewall system for Linux with default DROP policy, integrated anti-attack protections and intelligent traffic analysis blocked through machine learning. It combines defense-in-depth with threat intelligence to identify and neutralize zero-day threats.

Key Features

Advanced Firewall:

  • Default DROP policy on INPUT/OUTPUT for maximum security
  • SYN flood protection (rate limiting connections)
  • Detection port scanning (threshold-based)
  • SSH brute force protection (fail2ban integrated)
  • ICMP flood protection
  • Anti-spoofing filters (martian packets)
  • NULL/XMAS packets and fragmented packages

Logging and Forensics:

  • Separate INPUT/OUTPUT Logging in PCAP format (ulogd2)
  • Automatic retention 30 days / 1GB with logrotate
  • Retrospective analysis of blocked traffic
  • Event correlation for incident response

Threat Intelligence:

  • Threat scoring 0-100 for each source IP
  • Classification of threats: Critical/High/Medium/ Low
  • Pattern recognition: Port Scan, SYN Flood, Service Attack
  • Identification of attacks on critical ports (RDP, Telnet, SQL)
  • Automatic IP Block Recommendations

Advanced CLI management:

  • User-friendly Python Rule Management Interface
  • Add/remove rules with syntax validation
  • Whitelisting for trusted IP/subnets
  • Temporary or permanent blacklisting
  • Real-time statistics and traffic analysis

OWASP/NIST protection:

  • Defense in multi-layer depth
  • Fail secure with restrictive policy
  • Least privilege enforcement
  • Full logging audit
  • Rate limiting on critical services

Cases of use

  • Protection of web servers exposed with WordPress/Joomla
  • Network Segmentation for PCI-DSS environments
  • Hardening gateway VPN/SSH jump server
  • Incident response with post-attack PCAP analysis
  • Integration with MicroSIEM Intellidog for threat correlation

Technologies

  • Core: iptables/nftables with bash script
  • Logging: ulogd2 with PCAP stack
  • Analysis: Python with tcpdump/scapy
  • Management: Python CLI with argparse
  • Automation: systemd service for automatic startup

๐Ÿ”— Sentinel Suite โ€“ Modular Integration

Workflow Integrated (with Optional Integration Pack)

Scenario 1: Vulnerability-Driven Hardening

  1. Sentinel Core critical CVE detection on exposed 8080 port
  2. MicroSIEM + Intellidog verify whether active exploit โ†’ Confirmed
  3. Firedog automatically lock 8080 door
  4. MicroSIEM apply additional hardening and monitor access attempts
  5. Unified Dashboard complete timeline of the intervention

Scenario 2: Threat Intelligence Alert

  1. MicroSIEM Intellidog receives IoC from MISP: Known attacker IP
  2. Check Log Firedog: IP attempted SSH access 2 hours ago (locked)
  3. Verification MicroSIEM: no impairment detected
  4. Generate report: "No action required"

Scenario 3: Compliance Audit

  1. MicroSIEM execute NIS2 hardening checklist
  2. Sentinel Core scan post-hardening vulnerabilities
  3. Firedog compliant policy firewall verification
  4. MicroSIEM Intellidog confirm no active exploit
  5. Unified report: "NIS2 Compliance: 78% โ†’ 92% after remediation"


๐Ÿ’ฐ Licensing Models

Standalone Modules

  • MicroSIEM
  • Sentinel Core
  • Firedog
  • MicroSIEM + Intellidog

Bundle Suite

  • Complete Suite (4 modules): (-20% compared to separate purchase)
  • Integration Pack

& Services support

  • Standard Support: Email 48h response (included)
  • Premium Support: 24/7 with ALS 4h
  • Deployment advice: (initial on-site/remote setup)
  • Custom compliance mapping: framework (GDPR, HIPAA, sectoral)

๐ŸŽฏ To Whom He Addresses

โœ… SMEs 50-500 employees NIS2 or ISO 27001
โœ… Startup tech handling sensitive data (HealthTech, FinTech)
โœ… E-commerce with PCI-DSS requirements
โœ… MSP/MSSP looking for white-label solution for customers
โœ… System Integrator with cybersecurity portfolio
โœ… Manufacturing companies with OT/IT convergence (Industry 4.0)


๐Ÿ“ž Contacts and Demos

Request free demo 30 days:
๐Ÿ“ง info@dognet.tech
๐Ÿ“ฑ +39 351 5568240 – 352 0321176

Available:

  • Trial free 30 days (environment sandbox)
  • Custom PoC on Your Infrastructure
  • Technical workshop for IT team (2 days)

โ“ FAQ โ€“ Sentinel Suite

๐Ÿง  MicroSIEM โ€“ Intellidog Module

General questions

Q: Is Intellidog a separate tool?
A: No. Intellidog is a premium module of MicroSIEM, not standalone tool. It is activated by purchasing the MicroSIEM + Intellidog upgrade.

Q: Can I just buy Intellidog?
A: No, Intellidog requires MicroSIEM License Active Base. It is a complementary extension that adds threat intelligence and exploit detection to existing monitoring.

Q: If I already have MicroSIEM, how do I add Intellidog?
A: Upgrade license key (differenza โ‚ฌ2.500/anno) + installazione modulo (plugin). Configurazione <1 ora, zero downtime.

Q: Does Intellidog work without Sentinel Core?
A: Yes and no:

  • It works. Threat intel, log/PCAP analysis, generic exploit detection
  • Limited: Without Sentinel Core cannot correlate specific CVE vulnerabilities with active exploits. Recommended to use together for maximum value.

Threat Intelligence

Q: What sources of threat intelligence do you use?
A: Free (included):

  • MISP (community feeds)
  • AlienVault OTX (Open Threat Exchange)
  • AbuseIPDB
  • Talos Intelligence (Cisco)

Payment (optional):

  • Shodan API ($59/month, recommended for maximum coverage)
  • VirusTotal API
  • Recorded Future (enterprise)

Q: Are my vulnerabilities shared?
A: No.. Intellidog download IoC from external sources but not charge Your data. Optionally you can contribute anonymous IoC to MISP community (opt-in).

Q: How up-to-date are the IoCs?
A: Sync every 4 hours with external sources. For zero-day critical: instant sync on manual request or automatic alert.


Exploit Detection

Q: How are certain if a vulnerability is exploited?
A: Multi-source correlation via Intellidog module:

  1. Vulnerability (from Sentinel Core if integrated, or generic detection)
  2. IoC match match: traffic/syscall corresponding to known exploits
  3. Pattern analysis: typical post-exploitation sequences (shell spawn, download file, lateral movement)
  4. Timeline: Timely suspicious events close to scanning port

Confidence: Low (<30%), Medium (30-70%), High (70-90%), Confirmed (90%+).

Q: How many false positives does Intellidog generate?
A: Dipende da threshold confidence. Configurazione default (Medium confidence): ~5-10% falsi positivi. Con tuning dopo 2 settimane: <2%.

Q: Does Intellidog also analyze encrypted traffic (HTTPS)?
A: Only metadata (IP, port, volume, timing). Payload HTTPS is not inspectable without SSL interception (which we do not implement for privacy). For web apps, you need WAF with SSL decryption.


Virtual Patching

Q: What is virtual patching in Intellidog?
A: Temporary protection when official patch is unavailable or unenforceable (leased system). Example:

  • CVE-2024-1234 on Apache 2.2 (EOL, no patch)
  • Intellidog creates Firedog rule: blocks HTTP requests with exploit pattern
  • Protected system without updating Apache

Q: Virtual patch is safe as a real patch?
A: No, it's a mitigation not a definitive fix. Virtual patch reduces attack surface but does not eliminate vulnerabilities. Use only as a temporary solution or for non patchable systems.

Q: How long does it take to create virtual patches?
A: โ€“ Automatico per CVE con exploit pubblico: <1 ora

  • Custom vulnerability manual: 1-3 days (require analysis)

Q: Can Virtual patch block legitimate traffic?
A: Yes, if too aggressive. Intellidog includes testing mode: virtual patch in "alert only" for 24-48h, then if zero false positives โ†’ activation block.


Integration and Workflow

Q: Does Intellidog work automatically or requires manual intervention?
A: Configurable mode:

  • Automatic (default): Automatic detection + alert, suggested virtual patching (requires human approval)
  • Semi-automatic: Detection + virtual patching automatic for Critical, alert for High/Medium
  • Manual: Only detection, all actions require approval

Q: I can integrate threat intel custom (e.g. Internal IoC?
A: Yes, manual upload CSV/JSON or REST API for custom feeds. Compatible format STIX 2.0/2.1.

Q: Intellidog generates dedicated reports?
A: Yes, integrated into the MicroSIEM dashboard with dedicated section:

  • Timeline attacks with forensic evidence
  • IoC match report
  • Virtual patch status
  • Threat hunting results Export PDF/JSON for audit documentation.

Q: Does Intellidog work with Firedog?
A: Yes, native integration:

  • PCAP law from Firedog for exploit analysis
  • Firedog Command for Virtual Patching (Autolock)
  • Correla threat intelligence with firewall events

Performance and Requirements

Q: Intellidog impact MicroSIEM performance?
A: Minimum impact:

  • CPU: +10-15% for correlateon engine
  • RAM: +200-300MB for IoC cache
  • Disk: +50MB for local threat intel database
  • Network: Sync IoC consumes ~100MB/day

Q: Do you need Shodan for a fee?
A: No, but recommended. Basic functionality with free feeds OK. Shodan API ($59/month) adds:

  • Internet-wide scanning for exposed assets
  • Historical date for verification
  • Enrichment vulnerability with real-world exposure date

๐Ÿ”— Integration Pack

Q: What does Integration Pack include?
A: โ€“ Auto API communication between MicroSIEM (with/without Intellidog), Sentinel Core and Firedog

  • Unified Dashboard (single bread of glass)
  • Automated workflow (6 defaults + custom)
  • Setup wizard for configuration
  • Document integration playbook

Q: Integration Pack works with MicroSIEM Base or Need Intellidog?
A: It works with both, but with Intellidog get advanced workflow:

  • Without Intellidog: Alert forwarding, hardening automation, compliance sync
  • With Intellidog: Exploit-driven response, virtual patching orchestrated, threat hunting multi-tool

Q: Can I buy Integration Pack without all the tools?
A: It needs at least 2 tools from the suite. Workflow available depend on active tools.


Any more questions?
๐Ÿ“ง Contact us: info@dognet.tech
๐Ÿ“š Knowledge Base: docs.dognet.tech (under construction)


CONTACT US

Contact Sales Team

EnglishenEnglishEnglish