Now in public beta

Security observabilityfrom one API call

Your WAF covers the perimeter. SOCWarden watches what gets through, enriching every event with threat intelligence, behavioral detection and risk scoring.

<5ms
Ingestion latency
99.9%
Uptime SLA
15+
Threat feeds & OSINT APIs
0-100
Risk score per event

Live detection

See SOCWarden in Action

Every event enriched with GeoIP, threat intelligence, behavioral signals and a composite risk score. All in real time.

Event Stream, Default Project
Live
TimeEventRiskLevel
2m agoauth.login.failure87high
5m agoadmin.user.created12low
8m agoauth.login.failure95critical
12m agoapi.key.generated4safe
18m agoauth.password.reset72high

Features

Complete security observability

Built for engineering teams with no dedicated SOC. Automates detection, scoring and alerting so you can focus on shipping.

15+
feeds & APIs

Threat Intelligence

15+ bulk threat feeds plus 9 real-time API enrichment sources (AbuseIPDB, GreyNoise, Shodan InternetDB, Pulsedive, HIBP, WHOIS, and 3 LLM providers). Every event enriched automatically with zero add-on cost.

29
detectors

Behavioral Detection

21 behavioral, sequence, and kill-chain detectors including brute force, impossible travel, credential spray, account takeover, data exfiltration, server persistence, and 5 kill chain patterns.

0-100
range

Risk Scoring

Composite 0-100 score per event. Combines event type base score, threat feeds, behavioral signals and external OSINT confidence.

100+
techniques

MITRE ATT&CK + OWASP

Every alert tagged with MITRE T-codes and OWASP Top 10 categories. Static lookup, no runtime cost. Audit-ready from day one.

LLM
powered

AI Alert Summaries

LLM-generated plain-English explanations for every alert. What happened, why it matters and recommended action. No JSON deciphering.

<2MB
binary

Server Agent

Lightweight agent binary for SSH, file integrity, process monitoring and Docker events. Ships to the same POST /v1/events endpoint.

Developer experience

Ship secure features faster

SDKs for Laravel, Node.js, Python, Go, Browser and a raw HTTP API. Integrate in under 2 minutes. Every SDK auto-collects IP, user agent and request context.

  • Single endpoint: POST /v1/events
  • Auto-context collection (IP, UA, geo)
  • 202 Accepted in <5ms, zero blocking
  • Queue-backed async enrichment
use SOCWarden\Facades\SOCWarden;

// After a successful login
SOCWarden::track(
    event: 'auth.login.success',
    actor: $user,
);

// โ†’ 202 Accepted ยท Enriched in <5ms

Enrichment engine

Alert detection & threat classification

Every event passes through three enrichment layers. Here's what a real high-risk event looks like after processing.

Enrichment Result, evt_7f3a9c
event auth.login.failureip 203.0.113.50time 2m ago
GeoIP & Network
country ๐Ÿ‡ท๐Ÿ‡บ Russia (Moscow)
asn AS12345 - DataCenter LLC
type Hosting / Datacenter
Threat Intelligence
Tor Exit Node, Tor Project
Spamhaus DROP, listed since 2025-11-03
AbuseIPDB, 98% confidence, 342 reports
Behavioral Detection
Brute Force, 12 failed attempts in 3 min
Impossible Travel, NY โ†’ Moscow in 14 min
Risk Score
87/100
Level
HIGH
MITRE ATT&CK
T1110.001
Password Guessing
OWASP
A07:2021
Auth Failures
Alert โ†’ Slack #securityAlert โ†’ PagerDuty (P2)Alert โ†’ Email (admin@)

Security

Built with security in mind

GDPR Ready

Data isolation per organization. Right to deletion. Data export on request. Full audit logging.

Data Encrypted

TLS 1.3+ in transit. AES-256 at rest. API keys bcrypt-hashed. Secrets never stored in plaintext.

Row-Level Security

Row-level security for tenant isolation. Organization-scoped queries. No data leakage between tenants.

Integrations

Seamless integration partners

Alert channels and SDKs that work out of the box. Connect your stack in minutes.

Slack
Discord
Telegram
PagerDuty
Email
Microsoft Teams
Webhook
Laravel
Node.js
Python
Go
Browser
REST API

Pricing

Simple pricing, serious security

Start free. Scale as you grow. Yearly = 2 months free.

Free

$0/mo
2,500/mo events
Events exceeding 2,500/mo are dropped
  • 1 project ยท 1 member
  • Email alerts
  • 7-day retention
  • GeoIP + threat feed matching
  • Brute force detection
  • Event explorer
Get Started

Starter

$12/mo
$120/yr save 2 months
25,000/mo events
Overage: $0.40/1k events
  • 3 projects ยท 3 members
  • Email + Telegram
  • 30-day retention
  • Full OSINT + AbuseIPDB
  • Impossible travel + geo-anomaly
  • 2 server agents
  • AI summaries (dashboard)
Start Free Trial

7-day free trial, no credit card required

Business

$99/mo
$990/yr save 2 months
500,000/mo events
Overage: $0.20/1k events
  • Unlimited everything
  • PagerDuty + MS Teams
  • 90-day retention
  • SSO (SAML/OIDC)
  • SIEM forwarding
  • Unlimited agents
  • SOC 2 compliance dashboard
  • Auto-block rules
Start Free Trial

7-day free trial, no credit card required

No contracts. Cancel anytime. All threat intelligence included.

Ready to secure your application?

Free tier included. No credit card required. Full threat intelligence from day one.