Your pentest ended. The probing didn’t.
A pentest shows what was vulnerable at one point in time. Sentinel covers the gap after the report: it tells your team when the perimeter is being mapped again, keeps the evidence, and lets you decide whether to block.
Know when an attacker comes back.
Reconnaissance
See when someone starts mapping exposed infrastructure or looking for paths that should not attract normal users.
Awareness before an incident ticket exists.Exploit probing
Separate common automated attack patterns and scanner behavior from harmless background traffic.
A shorter queue for the security team.Repeat sources
Keep repeated hostile activity tied to the project that observed it instead of losing it across disconnected logs.
Enough context to make a response decision.Edge response
Review the evidence before exporting or pushing confirmed project sources to a Cloudflare list.
No blind auto-blocking.Three steps. No application DNS move.
The basic deployment runs on AISEC’s neutral shared domain. Your production hostname and traffic path do not change. Connect Cloudflare only if the team wants reviewed edge enforcement.
Create
Create one Sentinel deployment inside the authorized AISEC project.
AISEC shows the deployment as active.
Test
Send the built-in synthetic event and confirm that it appears in the project feed.
Test traffic is labeled and cannot become a block candidate.
Choose
Stay in monitoring mode, or connect a project-scoped Cloudflare list for reviewed blocking.
Detection and enforcement have separate status.
Pause it before an authorized pentest.
Pause Sentinel for the affected project before an authorized assessment so scanner traffic is not counted or blocked as hostile, then restore it after the run. Automated maintenance windows exist behind a disabled feature flag and are not active in production.
Before
Record the assessment window, notify the team, and disarm the affected project.
Confirm protection is paused.During
Keep Sentinel disarmed for that project while the authorized scanner runs.
Avoid polluted analytics and self-blocking.After
Restore the project’s configured layers and verify the canary state.
Confirm protection is active again.Do not wait for the next pentest to learn that someone came back.
Start in monitoring mode. One deployment and one verified test event are enough to establish the signal path.