See probing.
Control the response.

Catch hostile probing between pentests. See where it comes from and block reviewed sources through Cloudflare.

ReconnaissanceMapping exposed paths
Exploit probesTesting attack patterns
Repeat sourcesReturning to the same project
Sentinel

See the activity

  • Source and request
  • Target and timing
  • Repeated activity
Block with CloudflareAfter review and setup
Detects activity on active decoys, not every application request.

Start without
moving your DNS.

Use an AISEC-managed hostname. Your application traffic stays where it is.

Compare plans
  1. Add a canary

    Create a decoy in your project’s Sentinel page.

    Check

    Its hostname appears in the deployment.

  2. Activate protection

    Arm the deployment and link its hostname from a location you control.

    Check

    Verify setup shows what is active or needs attention.

  3. Check the feed

    Use Test fire and look for the labeled event.

    Check

    This tests the feed, not public reachability or blocking.

See it.
Then stop it.

Review hostile sources, then block them with a Cloudflare rule.

Review in AISEC

Inspect confirmed or repeated hostile sources from your project.

  • Test events are excluded.
  • Other customers’ observations are excluded.

Block in Cloudflare

Connect a scoped token, a dedicated IP list and a blocking rule.

Verify the rule in Cloudflare.

A list update alone does not block traffic. Each approved push replaces the dedicated list.

Running a pentest? Pause Sentinel.

Keep your own scanner out of the threat feed and blocklist.

  1. Before the run

    Notify your team. Pause the project’s deployments and review existing edge blocks.

  2. During the run

    Keep Sentinel paused for that project.

  3. After the run

    Restore protection and run Verify setup.

Pausing Sentinel does not remove existing Cloudflare blocks.

Keep watch between releases.

Open AISEC

Sentinel requires a supported workspace plan. It is not included in Single Pentest. Compare plans