See probing.
Control the response.
Catch hostile probing between pentests. See where it comes from and block reviewed sources through Cloudflare.
See the activity
- Source and request
- Target and timing
- Repeated activity
Start without
moving your DNS.
Use an AISEC-managed hostname. Your application traffic stays where it is.
Compare plansAdd a canary
Create a decoy in your project’s Sentinel page.
CheckIts hostname appears in the deployment.
Activate protection
Arm the deployment and link its hostname from a location you control.
CheckVerify setup shows what is active or needs attention.
Check the feed
Use Test fire and look for the labeled event.
CheckThis tests the feed, not public reachability or blocking.
See it.
Then stop it.
Review hostile sources, then block them with a Cloudflare rule.
Review in AISEC
Inspect confirmed or repeated hostile sources from your project.
- Test events are excluded.
- Other customers’ observations are excluded.
Block in Cloudflare
Connect a scoped token, a dedicated IP list and a blocking rule.
A list update alone does not block traffic. Each approved push replaces the dedicated list.
Running a pentest? Pause Sentinel.
Keep your own scanner out of the threat feed and blocklist.
Before the run
Notify your team. Pause the project’s deployments and review existing edge blocks.
During the run
Keep Sentinel paused for that project.
After the run
Restore protection and run Verify setup.
Pausing Sentinel does not remove existing Cloudflare blocks.
Keep watch between releases.
Sentinel requires a supported workspace plan. It is not included in Single Pentest. Compare plans