Abstract visualization of network signals being correlated into incidents
Detection Engine

Built for the signal, not the noise.

Cloakmint's detection engine continuously models your cloud environment, groups correlated alerts into incidents, and dismisses what doesn't belong before it hits your queue.

Four pillars of adaptive detection

Adaptive Baselining

Cloakmint builds a behavioral model for each account, region, and service in your cloud. When an alert deviates from the learned norm, it gets scored. When it matches normal behavior, it closes automatically.

Sigma-Compatible Rule Engine

Bring your own custom detection rules in Sigma format, or use our built-in rule library mapped to MITRE ATT&CK techniques. Rules are versioned and auditable. No proprietary lock-in.

Multi-Signal Correlation

Groups alerts from disparate sources including CloudTrail, VPC flow logs, WAF events, and IAM activity into a single incident thread. Correlation context is preserved and exportable.

Auto-Close Reasoning Log

Every auto-closed alert includes a structured JSON explanation log detailing why it was dismissed. Analysts can audit, review, and override any auto-close decision. Supports SOC2 audit trail requirements.

What Cloakmint surfaces to your analysts

Four raw alerts correlated into one incident thread, with full context and auto-close reasoning.

INCIDENT Possible credential abuse: lateral movement pattern
Correlated 4 alerts | 14:32:07 UTC
14:31:02
S3 bucket policy modified: prod-config-bucket
IAM principal: arn:aws:iam::9120:role/ci-deploy
CloudTrail
14:31:28
IAM role assumed from unexpected region: us-west-2 (baseline: us-east-1 only)
GuardDuty
14:31:55
Cross-region API calls detected: 14 calls to eu-west-1 within 90s from same principal
CloudTrail
14:32:07
CloudTrail logging suppression attempted: StopLogging call blocked by SCP
CloudTrail

Every auto-close decision is auditable

Compliance teams can audit all auto-close decisions. The JSON reasoning log is structured, queryable, and retained for 90 days by default. It supports SOC2 audit trail requirements without additional tooling.

RBAC ensures each analyst only sees and acts on what their role permits. Every analyst action is logged with a timestamp and user identity.

View security practices
{
  "auto_close_id": "ac_8f2a9b3c",
  "alert_id": "gd_20260502_014",
  "decision": "false_positive",
  "confidence": 0.94,
  "reasoning": {
    "baseline_match": true,
    "technique": null,
    "rule_fired": "aws-ec2-normal-maintenance",
    "environment_context": "scheduled patching window",
    "similar_events_30d": 12
  },
  "closed_at": "2026-05-02T14:18:02Z",
  "reviewer": null,
  "overrideable": true
}

See it work on your cloud environment.

Start a free 14-day trial. No credit card required.

Start Free Trial Book a Demo