Core Engine // 01
Adaptive Security
Autonomous threat detection and response. No analysts. No alert fatigue.
A multi-source security engine that correlates events across 9 monitoring sources and executes bans autonomously.
Live playground
IP Threat Analyzer
How it works
Ingestion
9 monitoring sources — Cowrie, Suricata, Beelzebub, Tetragon eBPF, Sentinel edge node, and four more — feed a unified event stream.
Correlation
A multi-source correlator cross-references IPs across all sources within 10-minute windows. An IP appearing in two or more sources triggers automatic escalation.
Reasoning
A LangGraph agent enriches each threat via AbuseIPDB and geolocation, then reasons on attack patterns and assigns a threat level.
Action
The engine acts without human input — temporary ban, permanent ban, or range block — and executes via UFW and Fail2ban on both local and edge nodes.
Memory
Every ban generates a forensic report with MITRE ATT&CK TTP mapping, ISP, country, and attack vector. Stored in PostgreSQL and indexed in Qdrant for semantic search.
Capabilities
Adaptive thresholds
Auto-tightens ban criteria under sustained attack. The engine learns from volume, not just individual events.
AI honeypot
Beelzebub generates LLM-based trap responses that keep attackers engaged while profiling their techniques.
Edge node
Sentinel — a Hetzner server in Germany — extends coverage to a second geographic perimeter, syncing logs over Tailscale.
MITRE ATT&CK
Every attack is automatically classified against the MITRE framework. No analyst required.
Forensic reports
Post-ban reports include geolocation, ISP, previous attack history, and full TTP breakdown, delivered via Telegram.
Vector memory
Attack patterns are embedded and stored in Qdrant. Semantic search finds similar historical attacks in milliseconds.
What it solves
Most security systems react. This one learns. The difference is not speed — it is that every attack makes the next defense stronger. No alert fatigue. No missed patterns. No manual triage.
Case Studies
education
CAASM para Educación: Mitigación de Riesgos sin SOC Dedicado - Un Estudio de Caso
Este estudio de caso analiza la implementación de una solución de Gestión de Sup...
45% — Reducción del tiempo de respuesta a incidentes
saas
Detección de Movimiento Lateral en Redes SaaS: IA Comportamental y Mitigación de Riesgos
El presente estudio analiza la detección de movimiento lateral en redes corporat...
35% — Reduction in Mean Time to Detect (MTTD)
retail
CAASM para Retail: Mitigación Proactiva de Riesgos sin SOC Dedicado - Un Estudio de Caso
Este estudio de caso analiza la implementación de una solución de Gestión Contin...
3 horas — Tiempo Medio de Detección (MTTD)
Work with this engine
Get in touch →