Unified SOC platform · data in the EU or your own infrastructure

Security doesn't end with an alert.
It ends with proof.

Defence, offence and evidence — in one platform. Aegis combines SIEM, WAF, UEBA and NDR with built-in pentesting, a measurable security score and NIS2 evidence — from your first 5 nodes to a fully managed SOC.

First monitoring in about 15 minutes Outbound communication over port 443 Per-node billing, not per ingest
app.aegis.hr/nadzor
Illustration · demo data
Overview
SIEM events
WAF
UEBA
NDR
Vulnerabilities
NIS2 reports
Cases
Monitored nodes
0
all online
Detected / month
0
auto-triage
Open cases
0
2 in triage
NIS2 readiness
0
audit trail active
Detections per daylast 30 days
Threats by severity
Critical112
High1.408
Medium9.260
Low16.651
Most threats are triaged automatically
Real-time event example DEMO
CRIT14:02:11Brute-force SSH · 185.220.x.x → web serverAUTO-BLOCK
High13:57:48WAF: SQLi attempt · /api/loginBLOCKED
Medium13:44:03UEBA: login outside working hours · user accountTRIAGE

Note: the interface and dashboard values shown serve as a demonstration. Aggregated production data below is marked separately.

13.000+
active detection rules
380M+
security logs processed
280.000+
automatic threat blocks
7
platform interface languages
Aggregated, anonymised and illustratively rounded production metrics from the Aegis network.
380M+logs processed
280.000+automatic blocks
36.000+SOAR executions
13.000+detection rules
19.000+security cases
10.000+pentest findings
2,9Mlogins analyzed
6,7Mprocess events
99.000+alerts processed
98.000+TI indicators
7interface languages
380M+logs processed
280.000+automatic blocks
36.000+SOAR executions
13.000+detection rules
19.000+security cases
10.000+pentest findings
2,9Mlogins analyzed
6,7Mprocess events
99.000+alerts processed
98.000+TI indicators
7interface languages
Threat Intelligence

Aggregated threat data

An anonymised snapshot of the attacks the Aegis production network detects and blocks over the last 90 days.

MITRE attack techniques

Click a technique for details.

Attacks per month

Click a month for details.

Top attacker countries

Click a country for details.

Attack source networks (ASN / ISP)

Click a network for details.
Data source: Aegis production network. Values are aggregated and anonymized and do not reveal the identity of users or individual systems. Snapshot: July 2026.
⬇ Download Critical.txt threat feed
Free community feed — masked /24 networks (privacy), format IP;MITRE;Attempts;Country;Organization. Refreshed regularly.
Platform

57+ modules.
One dashboard.

Instead of five tools, five contracts and five invoices — Aegis brings together everything a SOC needs: defence, offence and evidence, built to work together from day one.

SIEM — logs and correlation

13,000+ active detection rules mapped to the MITRE ATT&CK framework — with real-time event correlation and CVE detection.

Learn more

WAF — web application protection

OWASP Top 10 protections, monitor or protect mode, with auto-block and geo-blocking at the network edge.

Learn more

UEBA + ATO — user behaviour

Anomalies and account takeover detection: suspicious sign-ins, impossible travel, unusual access.

Learn more

NDR — network detection

Monitoring of outbound connections: C2 channels, data exfiltration and suspicious DNS traffic — spotted and blocked.

Learn more

Vulnerabilities — CVE tracking

Vulnerability management with CISA KEV integration — priorities driven by real risk, not by the alphabet.

Learn more

AegisEDR — our own EDR + integrations

Our own endpoint detection & response with integrations for Bitdefender GravityZone and CrowdStrike plus AV coverage — threat status, verdicts and response actions in one place.

Learn more

DAM — database monitoring

MySQL, MariaDB and MSSQL: sign-ins, failed logins and access through phpMyAdmin, adminer or bash-mysql.

Learn more

Dark Web — exposure monitor

Tracking of leaked credentials and your domain's exposure — find out before someone exploits it.

Learn more

SOAR — Autopilot response

Runbooks with block / notify / case / webhook / status actions and templates (Brute-force, Ransomware, RCE, DoS, Valid-Accounts, Webshell). 36,000+ executions, auto-block and auto-verify per tenant.

Learn more

Forensics — attack analysis

Log-scan, fleet forensics and attack-chain reconstruction, with Cinematic Replay of attacks built from collected security events.

Learn more

NIS2 / ISO / GDPR — evidence pack

A readiness pack, audit trail and reports the regulator understands — compliance without manual assembly.

Learn more

Canary — deception layer

Honeypot and canary nodes that lure an attacker into revealing themselves before they reach real systems.

Learn more
cPanel SecuritySAST / LabVPN ManagerDNS and neighborhoodAttack path analysisPhishing simulationsGeo-blocking … 57+ modules in total
Aegis engines

Four in-house engines
under the hood

What sets Aegis apart is not just a collection of tools, but proprietary engines that work together — detecting, verifying, scoring and explaining.

AE

AegisEDREndpoint Detection & Response

Our own EDR with a baseline profile and IOC matching on the endpoint — threat status, verdicts and response actions, with integrations for GravityZone and CrowdStrike.

AV

AegisVerifyAuto-verification of findings

Every alert and pentest finding is additionally verified before escalation. Fewer false positives — more confidence in what you see.

AG

AegisGODUnified threat score

A single risk score per IP, calculated from 8 modules. One number tells you how risky a source is — without manually joining signals.

AM

AegisMindAI analyst (per-tenant)

A multi-LLM analyst that explains incidents, summarises context and suggests the next step — in your language, isolated per tenant.

COVERAGE SCORE

Know exactly how secure you are —
and what to fix.

Aegis turns your security posture into a single measurable score of 0–100 (A–F) per company, tenant or node, and then the recommendation engine gives you concrete, prioritised steps.

Illustration · demo data
78/100
Score B
FDCBA
A score per company, tenant or individual node — with history over time.

Recommendations — next steps

Prioritized by real risk, not chronologically.
High
3 servers without MFA on SSHEnable keys and two-factor sign-in on exposed hosts.
High
Critical CVE on an edge serviceKEV-flagged vulnerability — patch recommended within 48 hours.
Medium
WAF in "monitor" mode on 2 applicationsSwitch to "protect" for active blocking of attacks at the network edge.
Low
Enable canary nodesAn early signal of compromise before an attacker reaches your real systems.

The score and recommendations shown are illustrative; actual values are computed from your own data.

Offensive security · differentiator

We don't wait for the attack.
We strike first — with permission.

Aegis isn't only defence. Continuous authorized pentesting (Automated Security Validation) is built into the SOC and constantly tests your systems like a real attacker — WAN, LAN, web, VPN, DNS and phishing — and provides evidence for NIS2 audit. Every action is authorized, logged and repeatable.

◆ Continuous Threat Exposure Management (CTEM)

Recon and discovery

Mapping the attack surface — host:port, DNS, neighbourhood and an "our systems" baseline with a quick risk assessment.

Web-app attacks

SQLi, IDOR, SSTI, LFI and upload-RCE plus JWT, API, GraphQL and CORS checks — real exploit chains, not just scanning.

Multi-CMS and ERP

Enumeration and CVEs for WordPress, Drupal and others, with auth-bypass checks on ERP systems.

Red / Purple Team

Attack simulations, phishing campaigns, VPN pentesting and WAN and LAN pentesting with AAP attack-path analysis.

DDoS resilience test

A controlled L7 load test with presets and graphs of RPS, latency and error rate — auto-abort the moment the target degrades.

Evidence framework

WORM ledger, severity-based gating and hard-block until retest, Lab (SAST) code analysis plus SARIF and PDF reports (HR / EN / SR).

10.000+findings across tests
5.300+WORM ledger records
AAPAttack path analysis
SARIF + PDFreports in HR / EN / SR
Aggregated metrics from built-in tests · rounded for illustration.
Every run requires authorization — consent, a signer and Rules of Engagement. Never a packet flood.
Request a pentest demo
Compliance and evidence

From monitoring to proof —
in one click.

A regulator doesn't just ask you to be secure — it asks you to prove it. Aegis continuously gathers evidence and turns it into reports an auditor understands.

NIS2 Evidence Pack

A readiness pack with control evidence, measures and compliance status — audit-ready, with no manual assembly.

Learn more

ISO 27001 and GDPR — controls

A module with mapped controls and evidence that guides you through certification preparation and GDPR obligations.

Learn more

Full audit trail

Every action in the platform is logged and searchable — 1.1M+ recorded events form an indisputable audit trail.

Learn more

Aegis provides the tools, controls and evidence for compliance. Certification (e.g. ISO 27001) is carried out by an accredited certification body — Aegis currently holds no issued certificates. The figures shown are aggregated and illustrative.

MSSP · Multi-tenant

One platform.
Unlimited number of clients.

Aegis is built for MSP and MSSP partners: true multi-tenancy with nested "child SOCs", mass deployment and fully separated data per client.

True multi-tenancyFully separated data, users and rules per client.
Child SOCsNested child SOCs under your parent SOC.
Mass deploymentAgents and modules across dozens of nodes at once (Mass Deploy).
Per-tenant CoverageSecurity score and reports separately for each client.
Granular RBACPrecise roles and permissions — who sees and can do what.
Per-tenant brandingYour own logo and colours per client (white-label).
7 interface languagesInterface in 7 languages, selectable per tenant.
Remote managementTurn modules on and off on child SOCs from the parent SOC.
Partner SOC (you)
Client Aon-prem
Client Bmanaged
Client Chosting
DATA SECURITY

Your data stays
under your control.

Everything stays in your region: Aegis supports local installation in your own infrastructure or a managed service, with a clearly defined EU data residency policy — and NIS2 readiness from day one.

Clearly defined EU data residencyPrimary data (logs, events, reports) is stored in HR/EU; optional third-party integrations process only minimal metadata.
Outbound HTTPS over port 443The agent does not require opening any inbound ports. In environments with restricted outbound traffic, Aegis destinations need to be allowed.
Local installation or managed serviceYou choose where your data lives — on-prem, in your data center or with us.
Works with what you already have
LinuxWindowsmacOS SynologyMikroTikFortiGate BarracudaGravityZoneCrowdStrikeMicrosoft 365
HOW IT WORKS

From installation to first monitoring in around 15 minutes

1

Install the agent

A lightweight agent for all major platforms — a few minutes per node, with no inbound ports to open.

~ 4 min per node
2

The SDS engine correlates

Events are sent by outbound HTTPS over port 443 to an engine that correlates them through 13,000+ rules and automatically blocks threats.

automatic
3

You have control

A real-time dashboard, case management and reports — or hand it all to the Managed SOC team.

around 15 min to first monitoring
COMPARISON

Why companies switch to Aegis

Global SIEM tools charge by data volume and demand a team to maintain them. Aegis is built differently.

CRITERION
Aegis
TYPICAL GLOBAL SIEM
Billing model
Per node — predictable
Per ingest — grows with data
Data location
✓ Croatia / EU
US or „EU region" in the cloud
Time to first monitoring
about 15 minutes
weeks or months of integration
WAF + UEBA + NDR included
 In the platform
 Separate products and licenses
Built-in pentest (automated validation)
 Built-in, on demand
 Once a year, external
NIS2 reports
 Built-in
Manual assembly
Support in Croatian
 Local team, SLA up to 24×7
 A ticket in another time zone
Packages

Grow from 5 nodes to MSSP partner

Predictable per-node billing — log as much as you like, the bill stays the same.

How many nodes do you monitor?
15 nodes
3306090120+
Recommended package: SOC — 15 nodesRequest a quote

CORE

5 nodes

Essential SOC monitoring for small systems that want serious protection.

  • Agent monitoring
  • SIEM rules
  • Automatic blocking
  • Email / webhook alerts
Send an inquiry
MOST POPULAR

SOC

15 nodes

A full SOC for companies with their own IT team and web applications.

  • Full SIEM
  • WAF monitor / protect
  • Multi-tenant RBAC
  • Case management
Request a demo

SOC PRO

30 nodes

Advanced correlation and integrity monitoring for demanding environments.

  • Advanced correlation
  • FIM — file integrity
  • CIS baseline
  • CVE / vulnerability review
Send an inquiry

SOC + NIS2

50 nodes

SOC and regulatory compliance in a single package.

  • Everything in SOC PRO
  • NIS2 readiness pack
  • Audit trail review
  • Compliance reports
Send an inquiry

MANAGED SOC

50+ nodes

Our team monitors, tunes and escalates — you run the business.

  • Active alert triage
  • Rule tuning
  • Escalations per SLA
  • SLA: 8×5 / 12×5 / 24×7
Send an inquiry

MSSP

100+ nodes

A white-label platform for partners building their own SOC service.

  • White-label branding
  • Multi-tenant
  • Starter / Growth / Scale tiers
  • Partner support
Become a partner
Not sure which package? Send an inquiry — we'll propose a configuration to match your environment.
Frequently asked questions

Everything you ask before a demo call

How long does setup take? +

As a rule, around 15 minutes to first active monitoring. The agent installs in a few minutes per node, and communication goes out over outbound HTTPS on port 443 — with no additional inbound ports to open.

Where is my data? +

Depending on the chosen model: in your own infrastructure or in a managed service in Croatia. Primary data (logs, events, reports) is stored in HR/EU, while optional third-party integrations process only minimal metadata.

Do I need my own IT team? +

Not necessarily. With the Managed SOC, our team monitors, tunes and escalates threats according to an agreed SLA (8×5, 12×5 or 24×7).

What if I only have 3 servers? +

The CORE package starts at 5 nodes and covers even smaller environments — billing is per node, so you pay for exactly what you monitor.

Do you support NIS2 compliance? +

Yes. The SOC + NIS2 package includes a readiness pack, audit trail review and reports aligned with NIS2 requirements.

Which systems do you support? +

Linux, Windows and macOS plus Synology NAS, along with firewall and EDR integrations for MikroTik, FortiGate, Barracuda, Bitdefender GravityZone and CrowdStrike, as well as Microsoft 365.

How do you measure how secure we are? +

Through the Coverage Score — a measurable score of 0–100 (A–F) per company, tenant or node, computed from your own data. Along with the score you also get prioritised recommendations on what specifically to fix.

Does Aegis run the pentest on its own? +

Yes — the built-in pentest (automated validation) continuously tests your systems like a real attacker (WAN, LAN, web, VPN, DNS, phishing) with AAP attack-path analysis. Every run requires authorization and Rules of Engagement, and every finding lands in the WORM ledger with a SARIF and PDF report.

Do you offer a platform for MSP partners? +

Yes. Aegis is true multi-tenant with nested child SOCs, mass deployment, a per-tenant Coverage Score, granular RBAC, white-label branding and an interface in 7 languages.

See Aegis on your own data

A demo environment with your real logs — first monitoring, as a rule, in around 15 minutes, with no obligation.

Request demo access +385 95 906 7874
Odgovaramo isti radni dan · info@aegis.hr