Sentinel Suite โ Integrated Cybersecurity for SMEs
Overview Suite
Sentinel Suite is a modular cybersecurity platform designed specifically for startups and Italian SMEs that need enterprise-grade protection without the complexity and costs of traditional solutions.
The suite consists of 3 main tools covering the entire life cycle of IT security: from preventive hardening to vulnerability management, from perimeter protection to threat intelligence. Each module works independently but can integrate with others for a coordinated and automated defense.
Compliance: NIS2 (75%), ISO 27001 (80%), PCI-DSS (65%)
Deployment: On-premise, compatible with Debian/Ubuntu, scalable architecture from 5 to 500+ assets.
๐ง MicroSIEM โ Hardening and Continuous Monitoring
What does he do?
MicroSIEM is an advanced web console for automated hardening and continuous monitoring of Linux servers. It implements best practice (CIS Benchmarks, NIST) security configurations and detects suspicious or non-compliant activities in real time.
Key Features
Automated Hardening:
- Operating system configuration via sysctl, AppArmor/SELinux
- Local firewall management (iptables) with default policies
- Disable unnecessary services and reduce attack surface
- Default models for server roles (web, database, gateway)
- Template compliance (NIS2, ISO 27001, PCI-DSS)
Real Time Monitoring:
- Advanced audit logging (auded, ulogd) with correlation rules
- Remote Connection Monitoring (SSH, RDP, VNC)
- Tracking privileged user activities and sudo commands
- Detection privilege escalation attributes
- Check critical file integrity (Shaf-512)
Multi-channel Alerting:
- Email Notifications, Slack, Telegram, WhatsApp
- Alert on unauthorised configuration changes
- Unexpected service start report
- Real-time Dashboard with metric compliance
Centralised Management:
- Auto host discovery via ARP scan
- Deployment configurations via SSH with elliptical keys
- Role-based access control (Sysadmin/Reporter)
- Executive reporting for management
๐ฆ Intellidog Module (Premium Add-on)
Intellidog is the advanced threat intelligence module for MicroSIEM that transforms responsive to proactive monitoring. Available as a premium upgrade, it adds vulnerability-exploit correlation capabilities and automated virtual patching.
Intellidog Features
Vulnerability-Exploit correlation:
- Integration with Sentinel Core for import vulnerabilities
- Automatic Enrichment with IoC (Indicators of Compromise) from external sources:
- MISP (Malware Information Sharing Platform)
- Shodan (Internet-wide scanning data)
- AlienVault OTX (Open Threat Exchange)
- VirusTotal, AbuseIPDB, Talos Intelligence
- Mapping CVE โ Known exploits โ Active campaigns
Behavioral Analysis System:
- syscall monitoring via auditd/e BPF
- Parsing log applications (Apache, Nginx, SSH, database)
- Network traffic analysis from PCAP (Firedog integration)
- Detection behavioural abnormalities (UEBA-like)
- Identification pattern exploit (buffer overflow, command injection, transverse directory)
Exploit Detection:
- Correlation: "CVE present on asset" + "Traffic with payload exploit detected"
- Confidence scoring: probability of exploitation (Low/Medium/High/Confirmed)
- Timeline reconstruction attack with evidence
- Post-exploitation activities identification (lateral movement, privilege escalation)
Risk Mitigation & Virtual Patching:
- Automatic mitigation: If exploit detected but not available patch:
- Malevolent traffic pattern block via Firedog (WAF-like rules)
- Insulation of compromised asset network
- Disable temporary vulnerable functionality
- Virtual Patching: IDS/IPS-like rules to neutralize exploits without patch
- Priority recommendations: "Confirmed X Vulnerability exploited โ patches within 24h"
Threat Hunting Proactive:
- Query library Sigma rules for search for threats
- Historical IoC search on log retention (30-90 days)
- Automatic hunting campaign on new zero-day CVEs
- Dedicated Dashboard with threat timeline
Cases of Intellidog use:
- Accident validation: Confirm if vulnerability detected is actively exploited
- Zero-day response: Check immediately whether CVE has just been released already exploited in the past
- Threat hunting: Proactive research not detected
- Virtual patching: Protect non patchable legacy systems (Windows Server 2008, old appliances)
- Compliance: Demonstrate to auditor that vulnerability is mitigated even without patch
Cases of use MicroSIEM
- Hardening web servers exposed to the Internet
- PCI-DSS compliance for e-commerce environments
- Monitoring privileged accesses for audit trail
- Secure cloud environment configuration (AWS, Azure, GCP)
- Threat hunting proactive with Intellidog module (premium)
Technologies
- Backend: Python/Flask or Django
- Frontend: React/TypeScript
- Database: PostgreSQL or InfluxDB
- Intel Threat (Intellidog): MISP integration API, Shodan, AlienVault
- Advanced analysis (Intellidog): eBPF, audited correlation engine
- Server: Nginx on Linux
๐ Sentinel Core โ Vulnerability Management Intelligent
What does he do?
Sentinel Core is a vulnerability management enterprise system that centralizes, prioritizes and orchestrates remediation by coordinating technical teams. Aggregate results from multiple scanners and apply artificial intelligence to identify real risks in the context of your business.
Key Features
Acquisition Vulnerability:
- Scanner integration: Nessus, OpenVAS, Qualys, Nexpose, Burp Suite, Acunetix, Nmap
- Automatic import via REST API
- Format media: XML, JSON, CSV
- Custom Tool Plugin System
Cataloging and Enrichment:
- Common Vulnerability Scoring System
- Scoring EPSS (Exploit Prediction Score System)
- CVE/NVD database correlation
- Mapping CWE (Common Weakness Enumeration)
- Geolocation asset and service identification
Advanced Prioritization:
- Composite risk scoring (CVSS + EPSS + Business Impact + Asset Exposure)
- Patch availability assessment and remediation complexity
- Suggested SLA-based timelines
- Effort estimation for interventions
Workflow and Orchestration:
- Automatic task assignment to competent teams
- Tracking remediation with deadlines
- Automatic escalation on delays
- Approved workflow for critical changes
- Slack/Telegram/Email Notifications
Multi-Level Reporting:
- Executive Dashboard with Trend and KPI (MTTR, SLA compliance)
- Operational reports for technical teams
- Technical details with PoC and remediation steps
- Export PDF/JSON/CSV/ XML
SOAR integration:
- Connector for Splunk SOAR, Cortex XSOAR, IBM Resilient
- Automatic ticket creation (ServiceNow, Jira)
- Playbook execution for standard remediation
Cases of use
- Vulnerability management for MSP/MSSP with multiple customers
- DevOps/SecOps/NetOps team coordination in medium organisations
- Compliance scanning NIS2 with automatic reporting
- Bug bounty program management
Technologies
- Backend: Rust (Axum framework)
- Database: PostgreSQL with UUID
- API: REST with JWT authentication
- Architecture: Microservices-ready, high availability
๐ฅ Firedog โ Advanced Firewall & Threat Detection
What does he do?
Firedog is an advanced firewall system for Linux with default DROP policy, integrated anti-attack protections and intelligent traffic analysis blocked through machine learning. It combines defense-in-depth with threat intelligence to identify and neutralize zero-day threats.
Key Features
Advanced Firewall:
- Default DROP policy on INPUT/OUTPUT for maximum security
- SYN flood protection (rate limiting connections)
- Detection port scanning (threshold-based)
- SSH brute force protection (fail2ban integrated)
- ICMP flood protection
- Anti-spoofing filters (martian packets)
- NULL/XMAS packets and fragmented packages
Logging and Forensics:
- Separate INPUT/OUTPUT Logging in PCAP format (ulogd2)
- Automatic retention 30 days / 1GB with logrotate
- Retrospective analysis of blocked traffic
- Event correlation for incident response
Threat Intelligence:
- Threat scoring 0-100 for each source IP
- Classification of threats: Critical/High/Medium/ Low
- Pattern recognition: Port Scan, SYN Flood, Service Attack
- Identification of attacks on critical ports (RDP, Telnet, SQL)
- Automatic IP Block Recommendations
Advanced CLI management:
- User-friendly Python Rule Management Interface
- Add/remove rules with syntax validation
- Whitelisting for trusted IP/subnets
- Temporary or permanent blacklisting
- Real-time statistics and traffic analysis
OWASP/NIST protection:
- Defense in multi-layer depth
- Fail secure with restrictive policy
- Least privilege enforcement
- Full logging audit
- Rate limiting on critical services
Cases of use
- Protection of web servers exposed with WordPress/Joomla
- Network Segmentation for PCI-DSS environments
- Hardening gateway VPN/SSH jump server
- Incident response with post-attack PCAP analysis
- Integration with MicroSIEM Intellidog for threat correlation
Technologies
- Core: iptables/nftables with bash script
- Logging: ulogd2 with PCAP stack
- Analysis: Python with tcpdump/scapy
- Management: Python CLI with argparse
- Automation: systemd service for automatic startup
๐ Sentinel Suite โ Modular Integration
Workflow Integrated (with Optional Integration Pack)
Scenario 1: Vulnerability-Driven Hardening
- Sentinel Core critical CVE detection on exposed 8080 port
- MicroSIEM + Intellidog verify whether active exploit โ Confirmed
- Firedog automatically lock 8080 door
- MicroSIEM apply additional hardening and monitor access attempts
- Unified Dashboard complete timeline of the intervention
Scenario 2: Threat Intelligence Alert
- MicroSIEM Intellidog receives IoC from MISP: Known attacker IP
- Check Log Firedog: IP attempted SSH access 2 hours ago (locked)
- Verification MicroSIEM: no impairment detected
- Generate report: "No action required"
Scenario 3: Compliance Audit
- MicroSIEM execute NIS2 hardening checklist
- Sentinel Core scan post-hardening vulnerabilities
- Firedog compliant policy firewall verification
- MicroSIEM Intellidog confirm no active exploit
- Unified report: "NIS2 Compliance: 78% โ 92% after remediation"
๐ฐ Licensing Models
Standalone Modules
- MicroSIEM
- Sentinel Core
- Firedog
- MicroSIEM + Intellidog
Bundle Suite
- Complete Suite (4 modules): (-20% compared to separate purchase)
- Integration Pack
& Services support
- Standard Support: Email 48h response (included)
- Premium Support: 24/7 with ALS 4h
- Deployment advice: (initial on-site/remote setup)
- Custom compliance mapping: framework (GDPR, HIPAA, sectoral)
๐ฏ To Whom He Addresses
โ
SMEs 50-500 employees NIS2 or ISO 27001
โ
Startup tech handling sensitive data (HealthTech, FinTech)
โ
E-commerce with PCI-DSS requirements
โ
MSP/MSSP looking for white-label solution for customers
โ
System Integrator with cybersecurity portfolio
โ
Manufacturing companies with OT/IT convergence (Industry 4.0)
๐ Contacts and Demos
Request free demo 30 days:
๐ง info@dognet.tech
๐ฑ +39 351 5568240 – 352 0321176
Available:
- Trial free 30 days (environment sandbox)
- Custom PoC on Your Infrastructure
- Technical workshop for IT team (2 days)
โ FAQ โ Sentinel Suite
๐ง MicroSIEM โ Intellidog Module
General questions
Q: Is Intellidog a separate tool?
A: No. Intellidog is a premium module of MicroSIEM, not standalone tool. It is activated by purchasing the MicroSIEM + Intellidog upgrade.
Q: Can I just buy Intellidog?
A: No, Intellidog requires MicroSIEM License Active Base. It is a complementary extension that adds threat intelligence and exploit detection to existing monitoring.
Q: If I already have MicroSIEM, how do I add Intellidog?
A: Upgrade license key (differenza โฌ2.500/anno) + installazione modulo (plugin). Configurazione <1 ora, zero downtime.
Q: Does Intellidog work without Sentinel Core?
A: Yes and no:
- It works. Threat intel, log/PCAP analysis, generic exploit detection
- Limited: Without Sentinel Core cannot correlate specific CVE vulnerabilities with active exploits. Recommended to use together for maximum value.
Threat Intelligence
Q: What sources of threat intelligence do you use?
A: Free (included):
- MISP (community feeds)
- AlienVault OTX (Open Threat Exchange)
- AbuseIPDB
- Talos Intelligence (Cisco)
Payment (optional):
- Shodan API ($59/month, recommended for maximum coverage)
- VirusTotal API
- Recorded Future (enterprise)
Q: Are my vulnerabilities shared?
A: No.. Intellidog download IoC from external sources but not charge Your data. Optionally you can contribute anonymous IoC to MISP community (opt-in).
Q: How up-to-date are the IoCs?
A: Sync every 4 hours with external sources. For zero-day critical: instant sync on manual request or automatic alert.
Exploit Detection
Q: How are certain if a vulnerability is exploited?
A: Multi-source correlation via Intellidog module:
- Vulnerability (from Sentinel Core if integrated, or generic detection)
- IoC match match: traffic/syscall corresponding to known exploits
- Pattern analysis: typical post-exploitation sequences (shell spawn, download file, lateral movement)
- Timeline: Timely suspicious events close to scanning port
Confidence: Low (<30%), Medium (30-70%), High (70-90%), Confirmed (90%+).
Q: How many false positives does Intellidog generate?
A: Dipende da threshold confidence. Configurazione default (Medium confidence): ~5-10% falsi positivi. Con tuning dopo 2 settimane: <2%.
Q: Does Intellidog also analyze encrypted traffic (HTTPS)?
A: Only metadata (IP, port, volume, timing). Payload HTTPS is not inspectable without SSL interception (which we do not implement for privacy). For web apps, you need WAF with SSL decryption.
Virtual Patching
Q: What is virtual patching in Intellidog?
A: Temporary protection when official patch is unavailable or unenforceable (leased system). Example:
- CVE-2024-1234 on Apache 2.2 (EOL, no patch)
- Intellidog creates Firedog rule: blocks HTTP requests with exploit pattern
- Protected system without updating Apache
Q: Virtual patch is safe as a real patch?
A: No, it's a mitigation not a definitive fix. Virtual patch reduces attack surface but does not eliminate vulnerabilities. Use only as a temporary solution or for non patchable systems.
Q: How long does it take to create virtual patches?
A: โ Automatico per CVE con exploit pubblico: <1 ora
- Custom vulnerability manual: 1-3 days (require analysis)
Q: Can Virtual patch block legitimate traffic?
A: Yes, if too aggressive. Intellidog includes testing mode: virtual patch in "alert only" for 24-48h, then if zero false positives โ activation block.
Integration and Workflow
Q: Does Intellidog work automatically or requires manual intervention?
A: Configurable mode:
- Automatic (default): Automatic detection + alert, suggested virtual patching (requires human approval)
- Semi-automatic: Detection + virtual patching automatic for Critical, alert for High/Medium
- Manual: Only detection, all actions require approval
Q: I can integrate threat intel custom (e.g. Internal IoC?
A: Yes, manual upload CSV/JSON or REST API for custom feeds. Compatible format STIX 2.0/2.1.
Q: Intellidog generates dedicated reports?
A: Yes, integrated into the MicroSIEM dashboard with dedicated section:
- Timeline attacks with forensic evidence
- IoC match report
- Virtual patch status
- Threat hunting results Export PDF/JSON for audit documentation.
Q: Does Intellidog work with Firedog?
A: Yes, native integration:
- PCAP law from Firedog for exploit analysis
- Firedog Command for Virtual Patching (Autolock)
- Correla threat intelligence with firewall events
Performance and Requirements
Q: Intellidog impact MicroSIEM performance?
A: Minimum impact:
- CPU: +10-15% for correlateon engine
- RAM: +200-300MB for IoC cache
- Disk: +50MB for local threat intel database
- Network: Sync IoC consumes ~100MB/day
Q: Do you need Shodan for a fee?
A: No, but recommended. Basic functionality with free feeds OK. Shodan API ($59/month) adds:
- Internet-wide scanning for exposed assets
- Historical date for verification
- Enrichment vulnerability with real-world exposure date
๐ Integration Pack
Q: What does Integration Pack include?
A: โ Auto API communication between MicroSIEM (with/without Intellidog), Sentinel Core and Firedog
- Unified Dashboard (single bread of glass)
- Automated workflow (6 defaults + custom)
- Setup wizard for configuration
- Document integration playbook
Q: Integration Pack works with MicroSIEM Base or Need Intellidog?
A: It works with both, but with Intellidog get advanced workflow:
- Without Intellidog: Alert forwarding, hardening automation, compliance sync
- With Intellidog: Exploit-driven response, virtual patching orchestrated, threat hunting multi-tool
Q: Can I buy Integration Pack without all the tools?
A: It needs at least 2 tools from the suite. Workflow available depend on active tools.
Any more questions?
๐ง Contact us: info@dognet.tech
๐ Knowledge Base: docs.dognet.tech (under construction)
CONTACT US
Contact Sales Team
Dognet Technologies SRL
Via XXV April 47, 24055
Colony to the Serius (Bg)
Tel: 351.5568240 | 352.0321176
Mail: info@dognet.tech
PI and CF: 04867480164
BG N.R.E.A. 495176
Italy
Pages
Proudly powered by WordPress


