Open source · MIT · v0.2.0

Intrusion detection for your home network, explained in plain language.

SentinelAI watches your network's traffic, spots port scans, floods and network sweeps, and tells you what each alert means and what to do about it. It runs on your own hardware.

The SentinelAI dashboard: alerts to review, a table of recent alerts with severity, source and destination, and counts by type.

Real numbers, real traffic

Tested on public data. Misses included.

Three full days of CIC-IDS2017 replayed through the real detection pipeline. Each labelled flow counts as caught only if SentinelAI alerted on that connection while it was happening.

Thresholds tuned on this day

A port scan, an HTTP flood and a botnet, in 9.9 million packets.

AttackCaught
Port scan99.7%
DDoS (HTTP flood)99.9%
Botnet (Ares)23.9%
Normal flows wrongly flagged, check-in rule aside
22 of 380,557
Flagged by the check-in rule (one polling server)
1,441
Normal machines with a false alarm that day
5 of 7

CIC-IDS2017, Canadian Institute for Cybersecurity. Friday's thresholds were partly tuned on the same day. Wednesday and Monday were held out: every threshold was frozen before they were replayed.

  • Botnet flow recall looks low because every check-in before the first alert counts as missed. All five infected machines were flagged, each about 45 minutes after it started.
  • The check-in rule is noisy. It flagged a server that polls an internet service all day on every day tested, and on Monday also two workstations that kept reconnecting to dozens of web services for hours. Timing alone can't tell that apart from malware, and the rule hasn't been tuned to hide it. On a real laptop over 24 hours it flagged a code editor and the Claude apps 50 times, so it's off by default. These results were measured with it on.
  • An earlier version of these results had a scoring bug, found by the held-out Wednesday test. The numbers here are the corrected ones.

Methodology, per-machine results and how to reproduce them

Features

Small enough to understand, useful enough to run.

A handful of readable rules, a dashboard that explains itself, and everything on your own hardware.

01 — Detection

Detection rules you can read

Eight rules, each a few lines of Python with thresholds in one config file.

  • Port scans and network sweeps
  • Connection floods, request floods and distributed floods
  • Traffic bursts and oversized packets
  • Regular check-ins, the pattern botnets use to reach their controller (off by default: everyday apps do it too)

02 — Alerts

Alerts in plain language

Every alert says what happened, whether the source is on your network or the internet, the evidence behind it, and what to do next.

03 — Review

A review workflow

Mark alerts as reviewed one at a time or in bulk. The dashboard only asks for attention while something is unreviewed, then settles back to calm.

04 — Anomaly model

An optional anomaly model

An Isolation Forest trained on your own network's normal traffic flags what doesn't fit. It's off until you train it, and its alerts are never rated high.

05 — Privacy

Private by design

Everything runs on your hardware. It reads packet headers, not contents, and every service listens on 127.0.0.1 only. No account, no cloud.

06 — Demo

See it work in two minutes

make demo replays seven kinds of simulated attack against a full local install, no root needed. The fake internet attackers use addresses reserved for documentation, so they can't be mistaken for real ones.

What it can't do

Know the blind spots before you rely on it.

It can't see Wi-Fi traffic between your own devices

Traffic between two devices on the same Wi-Fi access point never crosses a wire SentinelAI can watch. Traffic to and from the internet is still seen, but a laptop scanning your smart TV over Wi-Fi isn't.

It may not keep up with a busy gigabit network

Packet capture runs in Python. Its speed on a Raspberry Pi hasn't been measured yet, and on a saturated link it may miss packets.

It misses slow attacks and anything inside the payload

Slowloris sends almost no traffic, by design, and was missed completely. Heartbleed lives inside encrypted traffic, which SentinelAI doesn't read. Both were 0% in testing.

It detects, it doesn't block

SentinelAI tells you what's happening. It never drops traffic, so a false alarm can't take your internet down.

What's next

Planned, not built yet.

None of this exists today. Each has a written plan, with what it must do before it ships.

Planned

Raspberry Pi installer

A Raspberry Pi 4 or 5 on a mirror port of your switch, watching every device and starting on boot.

Planned

Phone notifications

High-severity alerts through ntfy, email or a webhook, with quiet hours and rate limits.

Planned

Local AI triage

A model on your own network adds a verdict and a reason to each alert. Advice only: it can never hide or downgrade one.

Read the roadmap

FAQ

Questions people ask.

How is this different from Pi-hole?

Pi-hole blocks ads and trackers by refusing DNS lookups for known domains. SentinelAI doesn't block anything: it watches traffic for attack patterns such as scans, floods and sweeps. They do different jobs and run happily side by side.

Why not Suricata or Zeek?

Suricata matches traffic against thousands of known attack signatures and reads packet contents. Zeek turns traffic into detailed logs for analysts. Both are mature and more thorough. SentinelAI is smaller: a few readable rules, a dashboard that explains each alert, and results published with their misses. If you need an enterprise IDS, use Suricata.

What hardware do I need?

A Mac or Linux machine with Docker. A Raspberry Pi 4 or 5 is planned as the recommended setup, but its installer isn't built yet, so it isn't supported today.

How do I see my whole network, not just one computer?

On its own, SentinelAI sees the traffic of the machine it runs on. To see every device, give it a copy of the traffic: a managed switch with port mirroring (about $30–60) is the simplest and safest; a Raspberry Pi set up as a bridge between your router and your network sees everything but becomes a single point of failure; some routers can capture traffic themselves.

Is it ready to rely on?

Not yet. It's an early release, a learning and home-lab tool rather than a replacement for a professional security product. The numbers on this page are honest, including where it fails.

Is it legal to use?

Only monitor networks you own or have explicit permission to monitor. Capturing other people's traffic without consent is illegal in many countries.

Get started

Run it on your own network.

From source

On a Mac or Linux machine with Docker and make. The demo simulates attacks, so you can see detection working in two minutes.

$ git clone https://github.com/smngvlkz/sentinel.git$ cd sentinel$ make demo   # then open http://localhost:3001

To watch your real network instead, run make setup, set CAPTURE_INTERFACE in .env, then make up and make capture.

Raspberry Pi

Planned

A Raspberry Pi 4 or 5 on a mirror port of your switch, watching every device and starting on boot.

Install steps will appear here once the Raspberry Pi installer is built. See what's next.

Only monitor networks you own or have explicit permission to monitor.