Cyber Sentinel
Automated, AI-driven security ecosystem for network monitoring, threat intelligence gathering, and incident response.
Project
Security & Compliance
DNS
AI & Automation
Data
Platform
๐ฏ Project Purpose
Cyber Sentinel turns raw DNS traffic into decisions. Every new domain seen on the network is checked against threat intelligence, scored by an AI agent and โ if malicious โ blocked, without anyone reading logs.
๐ก๏ธ Problems Solved
- Analysis fatigue: thousands of DNS queries a day are filtered and scored automatically; only real threats reach a human.
- Scattered CTI: VirusTotal, ThreatFox and URLhaus results are combined into one 1โ5 score with a rationale in English and Polish.
- Slow response: confirmed malicious domains are added to the Pi-hole denylist and reported by email straight away.
- Exposed secrets: all API keys and credentials live in HashiCorp Vault, not in containers or the repo.
โ๏ธ How It Works
- Rules first, AI second: a rule-based score is computed in PostgreSQL; a Gemini AI agent in n8n reviews it, using past verdicts from pgvector memory, within limits set in the database.
- Noise filtering: Tranco top domains, a manual allow-list and trusted infrastructure are skipped before any API call.
- Configuration outside the workflow: thresholds, prompts (versioned), allow-lists and threat levels are edited in the AI Config web UI and stored in the database โ the workflow only reads them. Every change is audited.
- Hardened infrastructure: Raspberry Pi 5, Docker images pinned by digest, Nginx with TLS in front of every service, deployed end-to-end with Ansible.
๐ Documentation
๐ค Author
ลukasz Dejko
Automation Engineer ยท Backend Developer
LinkedIn ยท GitHub ยท Cybersecurity Blog ยท Gravatar
Automation Engineer ยท Backend Developer
LinkedIn ยท GitHub ยท Cybersecurity Blog ยท Gravatar