DeGooL Sentinel
A four-layer pipeline: collect everything, normalise to a common schema, reason over it with Claude, and act within policy. Deployed in-region, air-gap capable, no agent required for cloud-native estates.
Ingest everything, normalise once
Agentless cloud connectors, lightweight endpoint sensors and syslog collectors feed a single regional data lake. Telemetry is normalised to OCSF at the edge, so detection logic is written once and runs everywhere.
- 194 first-party connectors, 180+ via open API
- In-region storage with 400-day hot retention
- Deduplication cuts raw volume by 61% pre-index
- No per-gigabyte ingestion pricing
LAYER METRICS
collector.ingest( source: "aws.cloudtrail", schema: "ocsf.v1.4", region: "me-kuwait-1" ) → 812k evt/s
Coverage against MITRE ATT&CK
Detection coverage by tactic, validated quarterly through purple-team exercises and atomic test replay.
Integrations
- AWS CloudTrail
- Azure AD / Entra
- Google Cloud
- Microsoft 365
- CrowdStrike
- SentinelOne
- Palo Alto
- Fortinet
- Cisco Umbrella
- Okta
- Kubernetes
- Proofpoint
- Splunk
- Cloudflare
- Zscaler
- Jira
- ServiceNow
- Slack
- PagerDuty
- Syslog / CEF
+ 180 further connectors via the open ingestion API and syslog/CEF collectors.
Find out what your telemetry is already telling you.
Two-week assessment: we ingest your existing logs, run the Sentinel detection pack, and hand back a prioritised findings report. No agents, no commitment.