Collects your FortiGate, MikroTik, WatchGuard and Keenetic logs, isolates real attacks with A.I. correlation. 5 incidents instead of 500 alerts — a SIEM that thinks like an analyst.
Installation is not complicated. Your firewall is already sending syslog — we listen and interpret it.
Show the syslog IP of your FortiGate, MikroTik, WatchGuard, Keenetic devices. Installation in 5 minutes, RouterOS script is ready. You do not need to install additional software on a device.
7-layer analysis: parser → GeoIP → threat intel → pattern match → A.I. scoring → correlation → incident clustering. Reduces noise, shows only real threats.
Each event comes with MITRE ATT&CK tags, timeline, access status. Confirm, resolve, mark false positive — MTTR is measured. KVKK and ISO 27001 reports are prepared automatically.
Splunk / QRadar level features, but without the clutter. Designed specifically for installation.
Automatically clusters alarms into contextual events. 5 clustering rules, MITER mapping, A.I. summary, access status detection.
Port scan, SMTP brute, password spray, multi-stage campaign, after-hours access, mail flood — firewall + mail + Windows.
Two-step verification with Google Authenticator. All user actions are recorded. Ready evidence for KVKK.
IP location, ISP, abuse score. AbuseIPDB, Blocklist.de, Tor exit integration. Automatic blacklist and cooldown management.
Multiple customers in one panel. Data isolation guaranteed. Ideal for MSSP and agencies. Separate report per tenant.
Add it to the home screen on Android and iOS and use it as an application. Notifications, offline access, responsive design.
Legal log retention period is ready. Hash signed archives, audit reports, retention policy management.
Turkish explanation for each high score log with Oxi 6 Model.
Auto-Mode: threat score 90+ IPs automatic blacklist. Integrated blocking with firewall. All actions are in the audit log.
Ask logs with natural language:"Are there any suspicious incidents last night?"A.I. scans all logs, creates filters, shows evidence. Speech memory.
Perform 7-step analysis of an IP or user with one click. Allowlist, past alarms, threat intel, geographic information — with A.I. verdict.
Plesk/Postfix e-mail traffic — who sends it to whom? SMTP brute force detection, banner sweep, compensated account analysis, outbound spam.
Incident archives signed by HMAC-SHA256. It is court evidence. Integrity verification, chain of evidence, 5651 compliant.
A.I. dynamically learns thresholds and automatically filters false positives. 56 rules are automatically loaded depending on the device type. Activated with one click.
Slack, Teams, n8n, Jira, your own SOAR — critical events are sent via HMAC-signed HTTP POST. Retry logic included.
Plesk/Postfix mail logs are signed and archived with HMAC-SHA256. 2 years retention, court evidence, KVKK compliant.
SSE alarm strip, MITER heatmap, world map and customizable widgets — real-time updates while the panel is open.
Unknown log format learned It is learned in the phase; It turns into the official device type (e.g. pfSense) with approval and promotion from the panel.
The raw log is a nightmare. Thousands of them flow every second. We give you:"Describe what is happening right now in 5 sentences".
No credit card required. 1 device, 500K log/month, 7 days retention included. Installation in 15 minutes, See the first report the same day.