SinonSentinel includes a Hardware Abstraction Layer (HAL) that detects and utilises dedicated AI accelerator hardware. When a Hailo-10H NPU is present, security classification tasks run at sub-millisecond latency, catching threats before they execute, not after.
Each model is a 1-D CNN classifier optimised for the Hailo-10H architecture. Models are trained on real-world security datasets (EMBER, NSL-KDD, URLhaus, OpenPhish, Tranco, Bambenek, MalwareBazaar, DikeDataset) with synthetic augmentation for rare attack classes.
Endpoint Security
Threat Classification (10 classes): benign, malware, ransomware, trojan, worm, adware, spyware, rootkit, exploit, APT
Malware Classification (10 classes): clean, PE malware, script, document, packed, obfuscated, dropper, backdoor, keylogger, miner
LOLBin Detection (8 classes): benign admin, recon, credential access, lateral movement, defence evasion, persistence, exfiltration, execution
Ransomware Behavioural (6 classes): normal I/O, bulk rename, shadow copy delete, rapid enumeration, encryption pattern, ransom note drop
Network & Identity
DNS Threat Scoring (7 classes): clean, DGA, typosquat, homograph, tunnel, fast-flux, malicious redirect
Network Traffic Analysis (7 classes): normal, scan, DoS, exfiltration, C2 beacon, lateral movement, brute force
Encrypted Traffic (7 classes): legitimate TLS, malware C2, Tor, VPN tunnel, cryptominer, SSL stripping, expired cert abuse
Identity Threat (8 classes): normal login, impossible travel, credential stuffing, password spray, MFA fatigue, session hijack, privilege escalation, dormant account
Email, Cloud & Insider
Phishing Detection (5 classes): legitimate, phishing, spear phishing, whaling, smishing
Email Attachment Risk (7 classes): safe document, macro-enabled, password-protected archive, LNK shortcut, ISO image, HTML smuggling, polyglot file
URL Risk Classification (8 classes): benign, credential harvest, drive-by download, watering hole, malvertising, SEO poisoning, tech support scam, cryptojacking
File Classification (5 classes): benign, suspicious, malicious, encrypted, packed
Anomaly Detection (4 classes): normal, suspicious, anomalous, critical
Insider Threat (7 classes): normal, data hoarding, access escalation, off-hours bulk download, resignation risk, policy violation, unauthorised tool
Cloud Threat (8 classes): normal, privilege escalation, resource hijack, S3 exfiltration, container escape, crypto mining, IAM persistence, public exposure