Pillar 07

Sec & Ops Tooling

The instrumentation behind the engagements — built for our own work, and occasionally built for clients who need the same thing.

Reed Sentinel runs its own tooling rather than reselling somebody else’s console. That matters for two reasons: engagements are not constrained by what a vendor licence permits, and where a client needs something specific, it can be built rather than approximated.

Sec & Ops Tooling — Reed Sentinel

What we check

What we check

The field device

A self-contained, battery-powered platform that deploys on site and runs the full recon-to-report chain, driven from a phone.

Tamper-evident logging

Every outbound connection every tool makes is hash-chained into an append-only log, so scope adherence is provable rather than asserted.

Scope enforcement in code

Targets are resolved and validated against the authorised allowlist before execution. Refusal is the default.

Automated reporting

Per-client branded documents generated from engagement data, so the report reflects what actually ran.

Monitoring and re-scan

Posture monitoring between engagements, and automated re-scanning to confirm remediation holds over time.

Bespoke tooling

Where an operational need is specific enough that no product fits, the tool is written for it.

How it works

How it works

01

Understand the need

What the gap actually is, and whether an existing product closes it. Frequently one does, and we will say so.

02

Specify

What it must do, what it must never do, and how its behaviour will be verified.

03

Build and verify

Delivered with its tests, its documentation and its limitations stated plainly.

04

Hand over

Yours to run. No licence, no per-seat charge, no dependency on us to keep it working.

Things we have built

Things we have built

Sentinel — autonomous security operations layer

Case Study 01

Sentinel — Autonomous SOC

A round-the-clock operations layer that ingests logs, alerts and signals from across a stack and triages them as they arrive, suppressing routine noise and surfacing genuine threats with the context needed to act. Built to keep an operator looking at the handful of events that matter rather than the thousands that do not.

Aegis — continuous external attack-surface mapping

Case Study 02

Aegis — Attack-Surface Mapper

Continuous external reconnaissance that maps exposed assets, open ports and leaked credentials as they appear, scores each finding by real-world exploitability, and returns a prioritised remediation order. Perimeter visibility that stays current between engagements rather than expiring with the last report.

Case Study 03

Network Sentinel

Most networks trust everything inside the perimeter and ship their telemetry to a vendor’s cloud. This one watches from the inside instead: intrusion detection running Suricata and Zeek alongside a DNS firewall, with full logs and packet captures retained on storage the client owns. Rogue devices, malicious domains and anomalous traffic are flagged in real time, and no monitoring data is handed to a third party.

Case Study 04

Hardened Access Control

A door is only as strong as the badge behind it, and a great many off-the-shelf RFID systems fall to a cloner costing less than dinner. An ESP32-based RFID and NFC access system was built with an administrative panel for credentials, schedules and a full entry audit trail — then red-teamed in house with a Flipper Zero, attempting card cloning and replay until the system held.

You will know the price before you commit.

A twenty-minute call is enough to agree what gets checked and what it costs. Nothing on your systems is touched until you have signed to say we may.

Book a free callarrow_forward