sentinel-kit

🛡️ Sentinel Kit Documentation

Welcome to Sentinel Kit, the unified security platform that simplifies SOC and DFIR operations through automated deployment and streamlined management.

Sentinel-Kit architecture


🚀 Getting Started

New to Sentinel Kit? Start here:

  1. Getting Started Guide
    • Understanding .env central configuration file
    • Initial platform deployment using the launcher
    • Creating your first admin user
    • Accessing the platform components
  2. Data Ingestion Setup
    • Configure log sources and collection agents
    • Advanced datasource configuration for various data types
    • Monitor data ingestion health and performance
  3. Sigma Rules Management
    • Create custom detection rules using Sigma format
    • Import community detection rules
    • Rule testing and validation workflows
  4. Alert Management & Investigation
    • Alert triage and investigation procedures
    • Using the integrated dashboard vs Kibana
    • Response actions and case management
  5. Monitoring & Health
    • Platform health monitoring with Grafana
    • Service status checking and troubleshooting
    • Performance optimization guidelines

📋 Quick Reference

Platform Access Points

Launcher Commands

./launcher.ps1 start    # Start all services
./launcher.ps1 stop     # Stop all services  
./launcher.ps1 status   # Check service health
./launcher.ps1 logs     # View real-time logs

🎯 Platform Overview

Sentinel Kit integrates multiple security tools into a unified platform:

Core Components

Key Features


🆘 Support & Community