Your pentest ended. The probing didn’t.

A pentest shows what was vulnerable at one point in time. Sentinel covers the gap after the report: it tells your team when the perimeter is being mapped again, keeps the evidence, and lets you decide whether to block.

Hostile probe observednew activity
SignalSomeone is mapping or testing the perimeter.
EvidenceSource, target, timing and repeat behavior stay together.
DecisionMonitor it or send a reviewed source to the edge.
Detection is automatic. Enforcement remains under your control.
The gapA clean pentest does not cover what happens after it ends
The noiseRaw access logs rarely tell the team what deserves attention
The riskAutomatic blocking without evidence can break legitimate traffic
The answerEarly warning, project context, and a reviewed response path

Know when an attacker comes back.

Reconnaissance

See when someone starts mapping exposed infrastructure or looking for paths that should not attract normal users.

Awareness before an incident ticket exists.

Exploit probing

Separate common automated attack patterns and scanner behavior from harmless background traffic.

A shorter queue for the security team.

Repeat sources

Keep repeated hostile activity tied to the project that observed it instead of losing it across disconnected logs.

Enough context to make a response decision.

Edge response

Review the evidence before exporting or pushing confirmed project sources to a Cloudflare list.

No blind auto-blocking.

Three steps. No application DNS move.

The basic deployment runs on AISEC’s neutral shared domain. Your production hostname and traffic path do not change. Connect Cloudflare only if the team wants reviewed edge enforcement.

Create

Create one Sentinel deployment inside the authorized AISEC project.

AISEC shows the deployment as active.

Test

Send the built-in synthetic event and confirm that it appears in the project feed.

Test traffic is labeled and cannot become a block candidate.

Choose

Stay in monitoring mode, or connect a project-scoped Cloudflare list for reviewed blocking.

Detection and enforcement have separate status.

Pause it before an authorized pentest.

Pause Sentinel for the affected project before an authorized assessment so scanner traffic is not counted or blocked as hostile, then restore it after the run. Automated maintenance windows exist behind a disabled feature flag and are not active in production.

Before

Record the assessment window, notify the team, and disarm the affected project.

Confirm protection is paused.

During

Keep Sentinel disarmed for that project while the authorized scanner runs.

Avoid polluted analytics and self-blocking.

After

Restore the project’s configured layers and verify the canary state.

Confirm protection is active again.

Do not wait for the next pentest to learn that someone came back.

Start in monitoring mode. One deployment and one verified test event are enough to establish the signal path.

Open Sentinel