On-Site SecOps Platform

Machine-speed defence
for enterprise networks

Cyber Sentinel is a three-tier detection and response platform built for organisations running MikroTik infrastructure across distributed sites. Deterministic enforcement at the edge. AI-escalated correlation at the centre.

● Live Deployment 10+ MikroTik Breakouts ~500 Endpoints SOC 2 Aligned IOA-First Detection
See the Platform Discuss Your Network
Tier 0 — Inline
Deterministic Enforcement
µs – ms · No AI

MikroTik firewall + auto-expiring address-lists. Where attacks are actually stopped. Stateless, fail-safe, zero latency penalty.

Tier 1 — Edge Swarm
Lightweight ML Scoring
ms – ~1 s · Small ML

Anomaly and IOA scoring at critical sites. Pushes confirmed blocks down to Tier 0. Escalates high-confidence events upward.

Tier 2 — Central Reasoning
AI Correlation Engine
Seconds · Swarm-of-Experts

Normalise → correlate → Swarm-of-Experts agents. LLM escalation reserved for the high-confidence 1% only.

10+
MikroTik Breakouts Monitored
~500
Endpoints Protected
3
Detection & Response Tiers
24h
Auto-Expiring Block Duration
The Platform

Built around the three-tier invariant

The tiers never mix. Tier 0 never runs AI. Tier 2 never touches the wire directly. This separation is structural — not a policy.

🛡️
IOA-First Detection

Indicators of Attack are detected before indicators of compromise appear. The Security Graph traverses lateral movement paths across the CMDB, linking entities by owner and criticality — not just IP address.

IOA Engine Security Graph CMDB
Real-Time Ingest

NetFlow v9/IPFIX + MikroTik syslog ingested directly via UDP listeners. Events normalised to a single Common Security Schema and published to Redis Streams for sub-second pipeline throughput.

IPFIX Syslog CEF Redis Streams ClickHouse
📊
Operational Dashboard

FastAPI web dashboard over the ClickHouse event store. Drill-down tables, per-router ingest health, reverse DNS resolution, persistent IP aliases, and inline CMDB asset management.

FastAPI ClickHouse Live Ingest Health
🔗
Identity & Asset Integration

Microsoft Graph collector pulls Intune, Entra ID, and Defender TVM data into the CMDB. Every finding carries an owner and criticality rating — enabling zero-trust policy enforcement per asset class.

MS Graph Intune Entra ID Zero-Trust

About

Systems built close to the problem

I'm a software developer and systems architect based in South Africa, focused on practical, production-grade tooling for network security, operational monitoring, and infrastructure automation.

Cyber Sentinel grew out of a live incident response — detecting active brute-force campaigns across MikroTik routers at a large game reserve and building a platform that could respond faster than human operators could react. Everything here is deployed, running, and handling real traffic.

I build across the full stack: Python backends, React frontends, RouterOS scripting, Linux system services, and AI-integrated pipelines. The common thread is operational reliability over theoretical elegance.

Python / FastAPI
MikroTik / RouterOS
ClickHouse / Redis
React / TypeScript
Docker / Podman
Linux / systemd
MS Graph / Entra
PostgreSQL / PostGIS
NetFlow / IPFIX
Electron / Node
LLM / AI Pipelines
ADS-B / RF

Projects

What else is running

A cross-section of production and active development work.

🔥
Active
Smart MikroTik Cyber Defence

Comprehensive firewall and brute-force defence framework for MikroTik routers. Born from a live incident: three active attack campaigns detected and blocked in real time. Deployed across 10+ RouterOS 7 devices.

RouterOS GeoIP Brute-Force Threat Feeds
🖥️
Active
Server Security System

AI-driven multi-server cyber defence platform using local LLM inference (Ollama). Read-only SSH forensics, prompt-injection-guarded analysis, operator-approved remediation plans. Currently handling a live mail-server incident.

FastAPI Ollama React SSH PostgreSQL
🗺️
In Dev
NetTopo Studio

Network Topology Studio — an IPv4 NAT-avoidance focused topology planner. Electron desktop app with Leaflet map, React Flow canvas, live MikroTik SSH pull, device credential vault, and XLSX export.

Electron React Leaflet SQLite MikroTik SSH
🚗
In Dev
Wildlife Fleet Monitoring

Live vehicle movement monitoring integrating the Cartrack Fleet API with ArcGIS spatial layers. Geofence triggers, heatmaps, alerting, and automated reports — built for in-house VM deployment at a game reserve.

FastAPI PostGIS Leaflet Cartrack API ArcGIS
✈️
Pilot
Aircraft Identification (PAAN)

Passive Aircraft Awareness Network for Welgevonden Game Reserve JOC. ADS-B / Mode S receiver-agnostic ingest (HackRF → FlightAware Pro Stick), SQLite event store, live web dashboard, and Raspberry Pi production target.

ADS-B HackRF Raspberry Pi SQLite Python
⚙️
Active
NerdHub

Self-hosted control plane for managing Python apps and Docker/Podman containers on AlmaLinux. REST API, web UI, heartbeat probes, port-conflict detection, GPU monitoring, and ntfy push notifications.

Python FastAPI Podman AlmaLinux systemd

Contact

Let's talk about your network

Whether you're running MikroTik infrastructure, dealing with an active incident, or scoping out a SecOps platform — reach out.

dev@cyber-sentinel.net