Crow-Eye Sentinel

RELEASING SOON

Enterprise-Grade Forensic Visibility & Predictive Defense
Distributed, Scalable, and Proactive. The depth of a full forensic investigation at the speed of your network.

Crow-Eye Sentinel delivers the granular, exhaustive details of a complete forensic investigation cycle simultaneously across thousands of endpoints.

But Sentinel doesn't just react to the past—it anticipates the future. By feeding deep endpoint data into our User Behavior Analytics (UBA) engine, Sentinel detects indicators of malicious intent, allowing you to neutralize insider threats before the data ever leaves your network.

Apply to the Design Partner Program
Scroll

Forensics Without Compromise.
Defense Without Delay.

Traditional incident response forces you to choose between speed and depth. Sentinel delivers both, bringing the exhaustive artifact parsing power of Crow-Eye to every endpoint in your organization.

Full-Cycle Forensics at Scale

Forget shallow triage. Sentinel agents execute complete forensic data collection and artifact parsing locally. Get the exhaustive details of a manual, deep-dive endpoint investigation at enterprise scale, ensuring no registry key, prefetch file, or event log is left unexamined.

Proactive User Behavior Analytics (UBA)

Shift from reactive analysis to proactive defense. Sentinel continuously analyzes endpoint artifacts to baseline normal employee behavior. It immediately flags anomalous activities, unauthorized staging, or pre-exfiltration behavior—stopping insider threats before a breach occurs.

Adaptive Correlation & Semantic Mapping

Powered by Wing Rules: One size does not fit all in enterprise security. Sentinel’s correlation engine utilizes advanced semantic mapping to automatically stitch together disparate network artifacts into a unified narrative. Powered by Wing Rules, your lead investigators define the logic, hyper-optimizing forensics against unique threat vectors and architectural realities.

Retrospective Forensics (Zero Evidence Loss)

Sentinel doesn’t just wait for an investigator to initiate a scan. You can configure deep-dive artifact collections to execute automatically on continuous schedules or instantly trigger based on specific network conditions. This creates a historical forensic safety net. Even if a highly stealthy attack isn't discovered until months later, you will have the exact, granular forensic snapshot captured at the precise moment the initial breach occurred. No more lost evidence due to log rollovers or attacker cleanup.

Frictionless EDR Augmentation

Sentinel is designed for absolute stability. It runs silently alongside your existing EDR solutions (like CrowdStrike, Microsoft Defender, or SentinelOne) without causing kernel panics, resource conflicts, or operational friction. It provides the deep, granular forensic context that standard EDRs leave behind.

Universal SIEM/SOAR Forwarding

Feed your central nervous system. Seamlessly push parsed forensic timelines, UBA alerts, and Wing Rule detections directly to Splunk, Elastic, Microsoft Sentinel, QRadar, or any webhook-enabled SOAR. Empower your automated playbooks with true forensic intelligence without forcing analysts to leave their single pane of glass.

Differential Forensic Analysis (Delta View)

Visualize the exact delta between two points in time. Sentinel's Comparison View allows investigators to instantly identify new persistence mechanisms, altered artifacts, or deleted evidence between scheduled scans, highlighting the evolving footprint of an adversary across the investigation timeline.

Integrated Case Management

Streamline your investigative workflow with built-in case management. Organize findings, track lead progression, and review critical changes in key forensic artifacts across the entire investigation timeline, ensuring a verifiable and audit-ready record of your work.

Engineered for the Enterprise

Built to operate seamlessly in the most demanding, secure, and bandwidth-constrained network environments.

Distributed Deep-Dive Sensors

Lightweight agents push the heavy lifting to the edge. By performing local forensic parsing, edge computing ensures your central server is never bogged down by raw data processing.

Secure Staging (RAM-First)

Your data's security is absolute. Sentinel uses SQLCipher with RAM-locked 256-bit AES keys. Evidence is encrypted in memory before it ever touches the disk on the target endpoint.

High-Ratio Compression

Forensic visibility shouldn't break your network. Zstandard (zstd) compression minimizes bandwidth impact, allowing for mass data collection even over strained connections.

Centralized Control Plane

Maintain absolute sovereignty over your data. Host your own control server to visualize your entire fleet, correlate UBA alerts, and manage complex investigations from a single dashboard.

Transparent Telemetry

Predictable, usage-based licensing metrics. Scale as you grow with a True-Up model that never blocks critical incident response. (Note: Telemetry is strictly for licensing—your forensic data never leaves your hosted environment).

Help Build Sentinel.
Shape the Standard.

Sentinel is releasing soon — and a small group of design partners is shaping it right now.

We're inviting a limited number of IR firms, MSSPs, internal security teams, and forensic labs to work directly with us before launch. You bring the reality of frontline investigations; we build Sentinel around it. In exchange, you get early enterprise access on the best terms we will ever offer — and a permanent voice in what it becomes.

The open-source Crow-Eye engine is free forever. Sentinel is the paid enterprise platform built on top of it. Design partners get in first, at the best terms we will ever offer.

What design partners get

  1. Early Sentinel access at design-partner terms. A select few design partners will receive Sentinel free during the program. All other design partners receive it at a significantly reduced price — well below general-availability pricing. Either way, you deploy across your fleet and run it on real cases while you help shape it.
  2. A permanent voice in the roadmap. Your Wing Rules, your detections, your reporting needs, your architecture. Lead investigators define the logic — and as a design partner, you define what we build next. Sentinel is built with the people who use it, not for an imagined buyer.
  3. Preferential pricing locked in for launch. When the program ends and Sentinel goes to general availability, design partners keep preferred terms no later customer will get.
  4. Early access to every capability. Delta View, retrospective forensics, SIEM/SOAR forwarding, new UBA detections — you run them before public release, and an edge your competitors don't yet have.
  5. Recognition, if you want it. Be credited as a founding design partner of a respected open-source-rooted DFIR platform. Or stay completely private — your call.
  6. A direct line to the team building it. Not a support queue. Real conversations with the people who wrote the engine.
A note on access: A small number of design partners — chosen by fit and depth of involvement — will receive Sentinel free during the program. All remaining design partners receive significantly reduced pricing. We keep the free tier limited so we can work closely with each partner in it.

Contribute to the field

Design partners can also help build Eye-Describe — the open, byte-level knowledge base of Windows forensic artifacts — and be credited as an educational source. Your expertise becomes part of how the next generation of investigators learns the evidence.

Who it's for

You run real investigations — incident response, insider threat, compliance, or criminal forensics — and you want forensic depth across your whole fleet, not shallow triage. If that's you, we want to build with you.

Sentinel — Frequently Asked Questions

What security leaders ask before bringing forensic depth to a whole fleet.

What is Crow-Eye Sentinel?

Sentinel is the enterprise tier of Crow-Eye. It takes the same full-depth forensic investigation Crow-Eye performs on one machine and runs it across a fleet — distributed agents on thousands of Windows endpoints, reporting into central case management.

How is Sentinel different from an EDR?

An EDR is built to detect and alert in real time. Sentinel is built to reconstruct what actually happened, at fleet scale: it parses and correlates the same deep Windows artifacts a forensic examiner would, so you get an investigable timeline rather than a stream of alerts.

How many endpoints can Sentinel handle?

Sentinel is designed for thousands of endpoints. Agents collect and parse locally and forward results, so the work scales with the fleet instead of funnelling every raw artifact to one server.

Does Sentinel integrate with our SIEM?

Yes. Sentinel forwards findings to your existing SIEM, so fleet-wide forensic results land in the pipeline your analysts already watch rather than in another separate console.

Who is the Design Partner Program for?

Incident response firms, MSSPs, internal security teams and forensic labs. Design partners get early enterprise access and shape the product before general availability, on preferential terms locked in at launch.

Is Crow-Eye itself still free?

Yes. The Crow-Eye forensics engine stays free and open-source under GPL-3.0 for single-machine investigation. Sentinel is the separate enterprise tier for running that same depth across a fleet.

Apply to join

We're keeping the group small and reading every application personally.