Defence, offence and evidence — in one platform. Aegis combines SIEM, WAF, UEBA and NDR with built-in pentesting, a measurable security score and NIS2 evidence — from your first 5 nodes to a fully managed SOC.
Note: the interface and dashboard values shown serve as a demonstration. Aggregated production data below is marked separately.
An anonymised snapshot of the attacks the Aegis production network detects and blocks over the last 90 days.
Instead of five tools, five contracts and five invoices — Aegis brings together everything a SOC needs: defence, offence and evidence, built to work together from day one.
13,000+ active detection rules mapped to the MITRE ATT&CK framework — with real-time event correlation and CVE detection.
Learn more →OWASP Top 10 protections, monitor or protect mode, with auto-block and geo-blocking at the network edge.
Learn more →Anomalies and account takeover detection: suspicious sign-ins, impossible travel, unusual access.
Learn more →Monitoring of outbound connections: C2 channels, data exfiltration and suspicious DNS traffic — spotted and blocked.
Learn more →Vulnerability management with CISA KEV integration — priorities driven by real risk, not by the alphabet.
Learn more →Our own endpoint detection & response with integrations for Bitdefender GravityZone and CrowdStrike plus AV coverage — threat status, verdicts and response actions in one place.
Learn more →MySQL, MariaDB and MSSQL: sign-ins, failed logins and access through phpMyAdmin, adminer or bash-mysql.
Learn more →Tracking of leaked credentials and your domain's exposure — find out before someone exploits it.
Learn more →Runbooks with block / notify / case / webhook / status actions and templates (Brute-force, Ransomware, RCE, DoS, Valid-Accounts, Webshell). 36,000+ executions, auto-block and auto-verify per tenant.
Learn more →Log-scan, fleet forensics and attack-chain reconstruction, with Cinematic Replay of attacks built from collected security events.
Learn more →A readiness pack, audit trail and reports the regulator understands — compliance without manual assembly.
Learn more →Honeypot and canary nodes that lure an attacker into revealing themselves before they reach real systems.
Learn more →What sets Aegis apart is not just a collection of tools, but proprietary engines that work together — detecting, verifying, scoring and explaining.
Our own EDR with a baseline profile and IOC matching on the endpoint — threat status, verdicts and response actions, with integrations for GravityZone and CrowdStrike.
Every alert and pentest finding is additionally verified before escalation. Fewer false positives — more confidence in what you see.
A single risk score per IP, calculated from 8 modules. One number tells you how risky a source is — without manually joining signals.
A multi-LLM analyst that explains incidents, summarises context and suggests the next step — in your language, isolated per tenant.
Aegis turns your security posture into a single measurable score of 0–100 (A–F) per company, tenant or node, and then the recommendation engine gives you concrete, prioritised steps.
The score and recommendations shown are illustrative; actual values are computed from your own data.
Aegis isn't only defence. Continuous authorized pentesting (Automated Security Validation) is built into the SOC and constantly tests your systems like a real attacker — WAN, LAN, web, VPN, DNS and phishing — and provides evidence for NIS2 audit. Every action is authorized, logged and repeatable.
Mapping the attack surface — host:port, DNS, neighbourhood and an "our systems" baseline with a quick risk assessment.
SQLi, IDOR, SSTI, LFI and upload-RCE plus JWT, API, GraphQL and CORS checks — real exploit chains, not just scanning.
Enumeration and CVEs for WordPress, Drupal and others, with auth-bypass checks on ERP systems.
Attack simulations, phishing campaigns, VPN pentesting and WAN and LAN pentesting with AAP attack-path analysis.
A controlled L7 load test with presets and graphs of RPS, latency and error rate — auto-abort the moment the target degrades.
WORM ledger, severity-based gating and hard-block until retest, Lab (SAST) code analysis plus SARIF and PDF reports (HR / EN / SR).
A regulator doesn't just ask you to be secure — it asks you to prove it. Aegis continuously gathers evidence and turns it into reports an auditor understands.
A readiness pack with control evidence, measures and compliance status — audit-ready, with no manual assembly.
Learn more →A module with mapped controls and evidence that guides you through certification preparation and GDPR obligations.
Learn more →Every action in the platform is logged and searchable — 1.1M+ recorded events form an indisputable audit trail.
Learn more →Aegis provides the tools, controls and evidence for compliance. Certification (e.g. ISO 27001) is carried out by an accredited certification body — Aegis currently holds no issued certificates. The figures shown are aggregated and illustrative.
Aegis is built for MSP and MSSP partners: true multi-tenancy with nested "child SOCs", mass deployment and fully separated data per client.
Everything stays in your region: Aegis supports local installation in your own infrastructure or a managed service, with a clearly defined EU data residency policy — and NIS2 readiness from day one.
A lightweight agent for all major platforms — a few minutes per node, with no inbound ports to open.
~ 4 min per nodeEvents are sent by outbound HTTPS over port 443 to an engine that correlates them through 13,000+ rules and automatically blocks threats.
automaticA real-time dashboard, case management and reports — or hand it all to the Managed SOC team.
around 15 min to first monitoringGlobal SIEM tools charge by data volume and demand a team to maintain them. Aegis is built differently.
Predictable per-node billing — log as much as you like, the bill stays the same.
Essential SOC monitoring for small systems that want serious protection.
A full SOC for companies with their own IT team and web applications.
Advanced correlation and integrity monitoring for demanding environments.
SOC and regulatory compliance in a single package.
Our team monitors, tunes and escalates — you run the business.
A white-label platform for partners building their own SOC service.
As a rule, around 15 minutes to first active monitoring. The agent installs in a few minutes per node, and communication goes out over outbound HTTPS on port 443 — with no additional inbound ports to open.
Depending on the chosen model: in your own infrastructure or in a managed service in Croatia. Primary data (logs, events, reports) is stored in HR/EU, while optional third-party integrations process only minimal metadata.
Not necessarily. With the Managed SOC, our team monitors, tunes and escalates threats according to an agreed SLA (8×5, 12×5 or 24×7).
The CORE package starts at 5 nodes and covers even smaller environments — billing is per node, so you pay for exactly what you monitor.
Yes. The SOC + NIS2 package includes a readiness pack, audit trail review and reports aligned with NIS2 requirements.
Linux, Windows and macOS plus Synology NAS, along with firewall and EDR integrations for MikroTik, FortiGate, Barracuda, Bitdefender GravityZone and CrowdStrike, as well as Microsoft 365.
Through the Coverage Score — a measurable score of 0–100 (A–F) per company, tenant or node, computed from your own data. Along with the score you also get prioritised recommendations on what specifically to fix.
Yes — the built-in pentest (automated validation) continuously tests your systems like a real attacker (WAN, LAN, web, VPN, DNS, phishing) with AAP attack-path analysis. Every run requires authorization and Rules of Engagement, and every finding lands in the WORM ledger with a SARIF and PDF report.
Yes. Aegis is true multi-tenant with nested child SOCs, mass deployment, a per-tenant Coverage Score, granular RBAC, white-label branding and an interface in 7 languages.
A demo environment with your real logs — first monitoring, as a rule, in around 15 minutes, with no obligation.