SentriCore provides kernel‑level security for Red Hat Linux environments, monitoring file system calls to detect attacks such as rootkits, ransomware, and data exfiltration before they reach user space. It ships with pre‑built MITRE ATT&CK rule templates and integrates with SIEM platforms like Splunk, Sumo Logic, and Microsoft Sentinel, while supporting automated deployment via Ansible Automation Platform.
Funding
Funding not disclosed
Founders
Product
Problem
Red Hat Linux systems that support critical infrastructure are increasingly targeted by sophisticated attacks that operate below the user‑space layer, such as rootkits, fileless malware, and kernel‑level exploits. Traditional security tools that focus on user‑space processes or network traffic often miss these threats, leaving organizations exposed to data exfiltration, ransomware, and system compromise.
Solution
SentriCore delivers kernel‑level security specifically for Red Hat Linux environments by monitoring file system calls in real time. The platform leverages pre‑built MITRE ATT&CK rule templates to provide immediate protection against known tactics while allowing customers to author custom policies for unique threat models. A granular policy engine evaluates each system call, dramatically reducing false‑positive alerts and enabling faster detection of malicious activity. Seamless integration with leading SIEM solutions such as Splunk, Sumo Logic, and Microsoft Sentinel consolidates alerts into existing monitoring workflows. Deployment, configuration, and ongoing response are automated through Ansible Automation Platform, simplifying operations across large, heterogeneous Red Hat deployments.
Target Audience
Primary customers are operators of critical infrastructure—such as energy, manufacturing, and telecommunications—who run Red Hat Enterprise Linux and require deep, kernel‑level protection integrated with their existing SIEM and automation tooling.
Features
- Real‑time monitoring of kernel file system calls to detect attacks at the lowest execution layer
- Pre‑built MITRE ATT&CK rule templates covering rootkits, fileless malware, ransomware, data exfiltration, and log tampering
- Granular policy engine that filters noise and minimizes false‑positive alerts
- Native integrations with Splunk, Sumo Logic, and Microsoft Sentinel for centralized alert management
- Automated provisioning, policy updates, and incident response via Ansible Automation Platform
- Support for custom rule creation to address organization‑specific threat scenarios