Pillar 07
The instrumentation behind the engagements — built for our own work, and occasionally built for clients who need the same thing.
Reed Sentinel runs its own tooling rather than reselling somebody else’s console. That matters for two reasons: engagements are not constrained by what a vendor licence permits, and where a client needs something specific, it can be built rather than approximated.
What we check
A self-contained, battery-powered platform that deploys on site and runs the full recon-to-report chain, driven from a phone.
Every outbound connection every tool makes is hash-chained into an append-only log, so scope adherence is provable rather than asserted.
Targets are resolved and validated against the authorised allowlist before execution. Refusal is the default.
Per-client branded documents generated from engagement data, so the report reflects what actually ran.
Posture monitoring between engagements, and automated re-scanning to confirm remediation holds over time.
Where an operational need is specific enough that no product fits, the tool is written for it.
How it works
What the gap actually is, and whether an existing product closes it. Frequently one does, and we will say so.
What it must do, what it must never do, and how its behaviour will be verified.
Delivered with its tests, its documentation and its limitations stated plainly.
Yours to run. No licence, no per-seat charge, no dependency on us to keep it working.
Things we have built
Case Study 01
A round-the-clock operations layer that ingests logs, alerts and signals from across a stack and triages them as they arrive, suppressing routine noise and surfacing genuine threats with the context needed to act. Built to keep an operator looking at the handful of events that matter rather than the thousands that do not.
Case Study 02
Continuous external reconnaissance that maps exposed assets, open ports and leaked credentials as they appear, scores each finding by real-world exploitability, and returns a prioritised remediation order. Perimeter visibility that stays current between engagements rather than expiring with the last report.
Case Study 03
Most networks trust everything inside the perimeter and ship their telemetry to a vendor’s cloud. This one watches from the inside instead: intrusion detection running Suricata and Zeek alongside a DNS firewall, with full logs and packet captures retained on storage the client owns. Rogue devices, malicious domains and anomalous traffic are flagged in real time, and no monitoring data is handed to a third party.
Case Study 04
A door is only as strong as the badge behind it, and a great many off-the-shelf RFID systems fall to a cloner costing less than dinner. An ESP32-based RFID and NFC access system was built with an administrative panel for credentials, schedules and a full entry audit trail — then red-teamed in house with a Flipper Zero, attempting card cloning and replay until the system held.
A twenty-minute call is enough to agree what gets checked and what it costs. Nothing on your systems is touched until you have signed to say we may.
Book a free callarrow_forward