Inspiration

I wanted to fix India's cybersecurity infrastructure and make it self-sufficient — not dependent on imported tools that only catch attacks they've already seen. SOCs here drown in 10,000+ alerts a day, and CERT-In has logged 1.59M+ incidents, while signature-based defenses miss anything novel. Project Sentinel is my attempt at resilient, homegrown infra — and the foundation for a cybersecurity company I want to build.

What it does

Sentinel is a dual-layer cyber resilience platform. Active Honeypot (a Chrome extension) lures and traps phishing/scams at the browser level. SwarmSentinel — an AI swarm running on a decaying Pheromone Graph — correlates weak signals across entities, detects real threats without needing known signatures, and auto-contains them (block, revoke, snapshot) in under a second.

How we built it

Mapped why SOCs fail — siloed tools, signature dependency, alert fatigue Built the Pheromone Graph in NetworkX — nodes as entities, decaying edges as interactions Layered a swarm on top: Scouts scan, Soldiers converge, Queen (Gemini LLM) decides FastAPI + Python async backend for non-blocking ingestion under load Active Honeypot as a Chrome extension, feeding real-time intel back to the swarm Benchmarked against phishing, fraud, takeover, and benign-traffic scenarios

Challenges we ran into

Tuning decay rate — too fast loses slow attackers, too slow brings back alert fatigue Keeping response sub-second while adding LLM reasoning Hitting 100% detection and 0.0% false positives at once Making the honeypot convincing without risking real user data Designing solo for future scale (Kafka, live feeds, digital twin)

Accomplishments that we're proud of

100% detection rate, 0.0% false positives ~508ms mean time to detect, ~718ms mean time to respond 0.06ms p99 enqueue latency, zero dropped events under surge First Runner-Up, Project Expo — NM KAUNYAK 2026

What we learned

A swarm of narrow agents beats one heavy detector Sub-second response is an engineering discipline, not a hope Behavior beats signatures — correlation catches what blocklists miss

What's next for Sentinel

WhatsApp threat coverage Live honeypot feeds Digital twin simulation for safer testing Kafka-based scaling beyond the current prototype

Built With

  • built-with-as-in-what-languages-used-built-with:-python
  • chrome
  • extension
  • fastapi
  • gemini-llm
  • javascript
  • networkx
Share this project:

Updates

Submission history