HLD Sentinel
Verification current

Verified product benchmark

Sentinel performance, measured and verified.

Three confirmed product outcomes. Every number is tied to a frozen baseline, raw counts, a published formula and an automated reproduction test.

Benchmark ID
SB-2026-08-24.1
Corpus
sentinel-controlled-corpus-v1
Last verified
24 August 2026

Confirmed results

The claims and the evidence beneath them

+80% Verified

increase in detection coverage

Sentinel identified 18 of 20 labelled attack scenarios, compared with 10 for the frozen fixed-signature baseline.

Fixed-signature baseline10 of 20 scenarios
Sentinel multi-layer detection18 of 20 scenarios
(18 detected − 10 detected) ÷ 10 detected × 100 = 80%

Recalculated from the frozen, expected-malicious scenario manifest; scenario IDs and detector mappings are asserted by the automated suite.

60% Verified

fewer analyst review items

Sentinel consolidated 100 related alerts into 40 incident groups by target and time window.

Alert-by-alert review100 alerts
Sentinel incident correlation40 incidents
(100 alerts − 40 incidents) ÷ 100 alerts × 100 = 60%

Executed through Sentinel’s production clusterAlerts/triageAlerts path using frozen alert, target, tenant and timestamp fixtures.

45% Verified

fewer manual routing decisions

Sentinel automatically routed 45 of 100 independent incidents that cleared both the critical-risk and high-confidence thresholds.

Manual routing for every incident100 manual decisions
Sentinel threshold-based routing55 analyst decisions
(100 decisions − 55 analyst decisions) ÷ 100 decisions × 100 = 45%

Executed through Sentinel’s production incident scoring and routing path; both score ≥85 and confidence ≥0.85 are required.

Verification protocol

How verification works

A result is marked verified when HLD Group’s automated benchmark reproduces it from the frozen comparison inputs and matches every raw count and formula shown on this page.

Verification owner
HLD Group automated benchmark suite
Execution environment
Deterministic in-process execution with frozen synthetic fixtures
01

Freeze the comparison

Corpus, expected labels, baseline behaviour, thresholds and calculation rules are fixed before execution.

02

Run identical inputs

The baseline and Sentinel receive the same controlled inputs. No result is normalised or selectively removed after the run.

03

Assert raw outcomes

Automated tests assert the numerator, denominator, production-path result and published percentage together.

04

Reproduce before release

A claim remains verified only while the benchmark repeats exactly against the named corpus version.

External comparison framework

How Sentinel is compared with open-source and industry references

We use public, vendor-neutral references to define the control, classify the attack behaviours and keep the scoring consistent. Sentinel and the control receive the same inputs; only the detection and triage capabilities differ.

01

Open-source detection control

The control is limited to fixed signatures and indicators, following Sigma’s vendor-neutral rule structure and severity conventions. Behavioural baselining and cross-source correlation are disabled. This isolates the additional coverage produced by Sentinel’s multi-layer engine.

Sigma Specification 2.1.0
02

Industry attack taxonomy

Each eligible scenario is classified by adversary behaviour using MITRE ATT&CK Enterprise. Scenarios are counted once, even when multiple detectors fire, preventing duplicate alerts from inflating coverage. The same relevant technique set is used for both sides.

MITRE ATT&CK Enterprise v19
03

Operational outcome measures

Detection, analysis and routing are measured as separate outcomes. Following NIST incident-response guidance, we publish the raw event, incident and decision counts rather than combining them into a proprietary score.

NIST SP 800-61r3
Inputs
Identical on both sides
Open-source control
Signature + IOC only
Coverage unit
Unique labelled scenario
Scoring
Raw counts, then formula

Detection corpus

20 labelled scenarios across 7 security families

The coverage test compares a fixed-signature rules baseline with Sentinel’s combined signature, behavioural and correlation layers. A scenario counts once when at least one mapped detector produces the expected detection.

Coverage layerBaselineSentinel
Fixed signature and IOC1010
Behavioural baseline06
Cross-source correlation02
Total detected10 / 2018 / 20

Evaluate Sentinel against your environment.

Run a scoped evaluation with the baseline and acceptance criteria agreed in advance.

Request a Sentinel evaluation