Skip to content

Cyber Sentinel

Automated, AI-driven security ecosystem for network monitoring, threat intelligence gathering, and incident response.

Project

version license last commit stars

Security & Compliance

Dependabot OpenSSF Scorecard Trivy CodeQL

DNS

Pi-hole Unbound Passive DNS

AI & Automation

n8n Google Gemini pgvector

Data

PostgreSQL

Platform

docker ansible vault Nginx Prometheus Python Raspberry Pi

๐ŸŽฏ Project Purpose

Cyber Sentinel turns raw DNS traffic into decisions. Every new domain seen on the network is checked against threat intelligence, scored by an AI agent and โ€” if malicious โ€” blocked, without anyone reading logs.

๐Ÿ›ก๏ธ Problems Solved

  • Analysis fatigue: thousands of DNS queries a day are filtered and scored automatically; only real threats reach a human.
  • Scattered CTI: VirusTotal, ThreatFox and URLhaus results are combined into one 1โ€“5 score with a rationale in English and Polish.
  • Slow response: confirmed malicious domains are added to the Pi-hole denylist and reported by email straight away.
  • Exposed secrets: all API keys and credentials live in HashiCorp Vault, not in containers or the repo.

โš™๏ธ How It Works

  • Rules first, AI second: a rule-based score is computed in PostgreSQL; a Gemini AI agent in n8n reviews it, using past verdicts from pgvector memory, within limits set in the database.
  • Noise filtering: Tranco top domains, a manual allow-list and trusted infrastructure are skipped before any API call.
  • Configuration outside the workflow: thresholds, prompts (versioned), allow-lists and threat levels are edited in the AI Config web UI and stored in the database โ€” the workflow only reads them. Every change is audited.
  • Hardened infrastructure: Raspberry Pi 5, Docker images pinned by digest, Nginx with TLS in front of every service, deployed end-to-end with Ansible.

๐Ÿ“š Documentation

๐Ÿ—๏ธ Architecture
Containerized stack, DNS pipeline, service dependency map
๐Ÿš€ Deployment
Ansible IaC โ€” one command, modular playbooks
๐Ÿณ Docker Compose
Services, IPs, exposed ports, hardening, volumes
๐Ÿค– n8n Workflow
AI agent pipeline: enrichment, scoring, alerts, auto-block
๐Ÿ—„๏ธ Database Schema
PostgreSQL + pgvector, partitioning & retention
๐Ÿ” Vault & Secrets
Zero-secrets policy, KV v2 provisioning via Ansible

๐Ÿ‘ค Author

Lukasz Dejko
ลukasz Dejko
Automation Engineer ยท Backend Developer
LinkedIn ยท GitHub ยท Cybersecurity Blog ยท Gravatar