Security Analyst
Security Agent
Threat detection before they become incidents.
What it does
Your always-on CISO. Connect your log sources and the Security Agent starts watching: failed authentication floods, off-hours admin access, bulk data exports, new superuser creation, scanner patterns. When a threat fires, it emails you immediately, posts to Slack, and files a ticket to your PM Agent. Behavioral baselines learn what "normal" looks like for each entity — anomalies are flagged relative to that baseline, not just static rules.
Ingests logs from Datadog, CloudWatch, Papertrail, and GitHub. Detects brute force, credential stuffing, data exfiltration, privilege escalation, and 7+ threat patterns in real time.
What it watches & does
- Brute force + credential stuffing detection
- Off-hours admin access alerts
- Bulk data export anomaly detection (baseline-aware)
- New superuser / privilege escalation tracking
- Repeated 403 scanner pattern detection
- GitHub secret scanning alerts
- Datadog, CloudWatch, Papertrail, GitHub connectors
- Custom HTTP webhook for any log source
- Daily security briefing email
- Slack alerts for HIGH+ severity events
- Chat with your Security Agent
Things it catches
- 847 failed logins from 192.168.1.1 in 10 minutes — brute force alert fired
- Bulk data export: 45 MB by alice@corp.com at 2am (12× her baseline) — critical alert
- New superuser created via GRANT statement — instant notification
- GitHub secret scanning: AWS key exposed in commit — critical alert fired in 60 seconds
- 2,300 × 403 responses from 45.67.89.1 in 5 minutes — scanner pattern detected
Plans
- Up to 3 log sources
- Core threat detection (brute force, failed logins, off-hours access)
- Email alerts on HIGH+ severity events
- Daily security briefing email
- Chat with your Security Agent
- Unlimited log sources
- Real-time threat detection (7+ rules)
- Datadog, CloudWatch, Papertrail, GitHub connectors
- Custom HTTP webhook
- Email + Slack alerts (HIGH+ severity)
- Behavioral baseline learning
- Daily security briefing email
- Ticket integration with PM Agent
- Chat with your Security Agent
- Everything in Pro
- Custom detection rules (write your own)
- Threat intelligence feeds (known bad IPs, CVE matching)
- Weekly executive security report (risk score, trends, top threats)
- SOC 2 + ISO 27001 evidence export
- Access review automation
- Priority support
Ready to put Security Agent to work?
Set it up in a few minutes — connect your tools and go.










Sensart Technologies