Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
sentinel-mcp — Autonomous AI-powered cyber defense system using MCP, Gemini 2.0 Flash, Dynatrace observability and MongoDB. Google Cloud Hackathon submission. | Kitploit
Tools/GitLabGitLab/reyjesusq/sentinel-mcp
Defensive ToolsCloud SecurityIntrusion DetectionIncident ResponseAI SecurityAnomaly Detection
GitLabreyjesusq/sentinel-mcp

sentinel-mcp

Autonomous AI-powered cyber defense system using MCP, Gemini 2.0 Flash, Dynatrace observability and MongoDB. Google Cloud Hackathon submission.

View Repository
223 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

SentinelMCP — AI-Powered Cyber Defense System

Google Cloud Hackathon submission — Autonomous threat detection and remediation orchestrated by Google Cloud Agent Builder (Vertex AI Agent), powered by Gemini 2.0 Flash, Model Context Protocol (MCP), and Dynatrace observability.

Agent Builder Gemini 2.0 Flash Dynatrace MongoDB MCP Protocol


The Problem

Security teams face 30-minute MTTD and 4-hour MTTR for typical incidents. By the time a human analyst detects the attack, writes the firewall rule, and deploys it, the damage is done.

The Solution

SentinelMCP reduces MTTD to < 30 seconds and MTTR to < 30 seconds by deploying a Google Cloud Agent Builder agent that receives Dynatrace anomaly webhooks, reasons over them with Gemini 2.0 Flash, and invokes real defense tools via MCP — acting on live infrastructure, not just alerting.

Dynatrace webhook  →  Agent Builder receives alert  →  Gemini reasons  →  MCP tools execute  →  Threat neutralized
       1 s                        2 s                      8 s                  15 s                  25 s total

The result: an incident lifecycle that previously required a human analyst and 4 hours now completes autonomously in under 30 seconds, with a full audit trail in MongoDB and distributed traces in Jaeger.


Architecture

┌──────────────────────────────────────────────────────────────────────┐
│                         SANDBOX ENVIRONMENT                          │
│                                                                      │
│   ┌─────────────┐   100–1000 req/s   ┌──────────────────────────┐   │
│   │  attacker   │ ──────────────────►│    victim-service        │   │
│   │ (DDoS/SQLi) │                    │    port 8080             │   │
│   └─────────────┘                    │    /admin/* control API  │   │
│                                      └────────────┬─────────────┘   │
└───────────────────────────────────────────────────│──────────────────┘
                                                    │ metrics + anomaly webhook
                   ┌────────────────────────────────▼─────────────────┐
                   │         Dynatrace Mock  (anomaly engine)          │
                   │  Threat Risk Score → fires POST /alerts/simulate  │
                   └────────────────────────┬─────────────────────────┘
                                            │ webhook
          ┌─────────────────────────────────▼──────────────────────────┐
          │          Google Cloud Agent Builder  (Vertex AI Agent)      │
          │  ┌──────────────────────────────────────────────────────┐  │
          │  │  Gemini 2.0 Flash  ──  reasons over threat context   │  │
          │  │  Tool manifest  ──  dynamically fetched from MCP     │  │
          │  │  HITL gate  ──  halts if confidence < threshold      │  │
          │  └──────────────────────────────────────────────────────┘  │
          └──────────────┬─────────────────────────┬───────────────────┘
                         │ REST calls                │ audit write
         ┌───────────────▼──────┐      ┌────────────▼──────────┐
         │  MCP Server  :8001   │      │  MongoDB 7.0  Atlas   │
         │  11 real tools       │      │  incidents + traces   │
         └───────────┬──────────┘      └───────────────────────┘
                     │ acts on live infra
         ┌───────────▼──────────┐
         │  FastAPI  :8000      │
         │  victim-service :8080│
         └──────────────────────┘

                   ┌──────────────────────────────────────────────────┐
                   │              OBSERVABILITY STACK                  │
                   │  OTel Collector ──► Jaeger  (distributed traces)  │
                   │  Prometheus ──────────────► Grafana               │
                   └──────────────────────────────────────────────────┘

Key design principle: Graceful degradation + Human-in-the-Loop (HITL). The Agent Builder agent halts safely and hands control back to the operator when it cannot reach a decision with sufficient confidence — it never guesses on critical infrastructure.


Live Demo — Google Cloud Run

All three services are deployed and running on Google Cloud Run:

ServiceURL
Command Center (Dashboard)https://sentinel-api-62d3d66zda-uc.a.run.app/dashboard
Swagger API Docshttps://sentinel-api-62d3d66zda-uc.a.run.app/docs
Health Checkhttps://sentinel-api-62d3d66zda-uc.a.run.app/health
MCP Tool Cataloghttps://sentinel-mcp-62d3d66zda-uc.a.run.app/mcp/tools
Victim Servicehttps://victim-service-62d3d66zda-uc.a.run.app

Run a live attack against production:

.\attack.production.ps1 status   # verify all services healthy
.\attack.production.ps1 ddos     # DDoS — Gemini blocks IPs + rate limit
.\attack.production.ps1 sql      # SQL Injection — Gemini activates WAF
.\attack.production.ps1 brute    # Brute Force — Gemini blocks source IPs
.\attack.production.ps1 stop     # reset defenses

The attacker container runs locally and targets the Cloud Run victim-service over HTTPS. Watch the Command Center dashboard for the full detection → reasoning → neutralization cycle in real time.


How it uses Google Cloud Agent Builder

Google Cloud Agent Builder (Vertex AI ReasoningEngine) is the central orchestrator of SentinelMCP. The implementation lives in sentinel_mcp/agent/agent_builder.py.

SentinelAgent inherits from vertexai.preview.reasoning_engines.Queryable — the official Agent Builder programmatic interface — and can run locally or be deployed to the managed Agent Builder service with a single command.

ResponsibilityImplementation
Webhook intakeSentinelAgent.query(incident=...) — called by Agent Builder on every Dynatrace alert
Tool declarations6 MCP tools registered as Vertex AI FunctionDeclaration objects in set_up()
ReasoningGemini 2.0 Flash reads threat context + tool catalog, selects the minimum tools, auto-invokes them
HITL gateIf Gemini returns no tool calls (confidence < threshold), escalate_to_humans=True is emitted
AuditEvery tool call logged in MongoDB Atlas + exported as OTel span to Jaeger

Key code — sentinel_mcp/agent/agent_builder.py:

class SentinelAgent(reasoning_engines.Queryable):

    def set_up(self):
        # MCP tools as Vertex AI FunctionDeclarations — Gemini selects at runtime
        mcp_tools = Tool(function_declarations=[
            FunctionDeclaration(name="block_ip_address", ...),
            FunctionDeclaration(name="activate_waf", ...),
            FunctionDeclaration(name="rate_limit_requests", ...),
            FunctionDeclaration(name="scale_service", ...),
            FunctionDeclaration(name="collect_forensic_logs", ...),
            FunctionDeclaration(name="analyze_attack_pattern", ...),
        ])
        self._model = GenerativeModel("gemini-2.0-flash-001", tools=[mcp_tools])
        self._chat = self._model.start_chat()
Download Tool