Crogl is AI for the enterprise SOC. It investigates every alert and threat advisory using the tools and data already in your SOC, in their native formats, without schema normalization. Free for one user. Enterprise for your team under a paid annual agreement.
Crogl is AI for the enterprise SOC. It investigates every alert. It documents every action. Your analysts review the evidence and make the call.
Free and Enterprise
This AMI carries no software license charge. Free is for one user and remains free. It includes all connectors, unlimited skills, unlimited audit trails, username and password access, and direct access to Crogl engineers in the community Slack. You bring your own LLM provider credentials, and your model provider bills that usage.
Enterprise is for SOC teams running Crogl around the clock. The paid annual plan adds unlimited users and investigations, autonomous investigation and threat hunting, single sign-on, role-based access control, and audit log export. It also covers use of your enterprise LLM service and dedicated support with agreed service levels. Pricing is custom and team based. No per-alert, per-investigation, or per-user fees.
Free and Enterprise run the same core platform. The plan determines the features and access available to your team.
What an investigation looks like
An alert lands. Crogl pulls the host and identity context, queries your EDR for process lineage, and checks the authentication record. It pivots to your data lake for anything the SIEM did not retain, then reads the relevant threat advisory. It writes down every query it ran and every result it got back. Your analyst opens the investigation, sees the reasoning, redirects it, and decides what happens next. Crogl handles the investigation. The analyst makes the call.
Crogl records the work in your ticketing or case management system. Auditable, repeatable, inspectable. Every investigation is an artifact you can hand to an auditor, a regulator, or your board.
Works where the data lives
Crogl queries your SIEM, EDR, identity, cloud, data lake, ticketing, and threat intelligence sources in their native formats, without schema normalization. There is no pipeline to build and no index to populate first. You can build connectors and skills for your own tools and workflows.
You bring your own model. Crogl runs against the LLM service you choose and host, including models that stay inside an air-gapped boundary.
Deployment
This AMI runs on Amazon EC2 in your AWS account. You control the deployment, its connections to your tools, and its connection to your model services. Most teams reach their first investigation within minutes of first login. Crogl also runs on premises, in private cloud, and in air-gapped environments. Contact Crogl for those options.
In production today
One defense organization runs Crogl against 60,000 alerts per month across 100TB of data, three SIEMs, and two SOARs, at an impact equivalent to six full-time analysts. Crogl is built for the hardest security environments.
Request Enterprise pricing
Enterprise is purchased through a private offer on the Crogl - AI for Enterprise Security solution in AWS Marketplace. That solution includes this AMI and Crogl Annual Production Support. Open that listing and select Request private offer, or contact Crogl at sales@crogl.com. Licensing and support terms are specified in your Enterprise agreement. AWS infrastructure and model services are billed separately.
Highlights
Investigates every alert. Documents every action. Crogl pulls host and identity context, queries your EDR, pivots to your data lake, and reads the advisory, writing down every query and result. The analyst reviews the reasoning and makes the call.
Works where the data lives. Crogl queries your SIEM, EDR, identity, cloud, and data lake in their native formats, without schema normalization. No pipeline to build. Bring your own model, including one hosted inside an air-gapped boundary.
Free is for one user and remains free: all connectors, unlimited skills, and community Slack access to Crogl engineers. Enterprise adds unlimited users, autonomous investigation, SSO, RBAC, and dedicated support. Request pricing on the Crogl solution.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You install this software from a machine image on your own AWS instance, and the software itself carries no license charge. Pricing here reflects your choice of EC2 instance size, billed per hour of runtime. You pick from five instance types across two families and two sizes within each. Larger instances give more compute for heavier workloads, while the burstable option suits lighter or variable use. You pay only for the hours each instance runs. Your total cost depends on which instance you select and how long you keep it running.
Top-of-mind questions for buyers
Am I charged for an instance when it is stopped or paused?
The software itself carries no license charge, so no software fee applies. AWS meters the instance by hour of runtime, so a stopped instance stops accruing hourly compute charges. Underlying storage attached to a stopped instance may still incur AWS fees, but running time drives the compute cost.
What am I actually paying for if the software has no license fee?
You pay only the hourly rate for the EC2 instance running the machine image. Charges reflect the instance size you select and the hours it runs. There are no per-alert, per-investigation, or per-user software fees, so investigating more alerts does not raise the bill.
How do the five instance options differ for choosing the right size?
You pick from two instance families, each in two sizes, plus one burstable option. The larger size in each family gives more compute for heavier workloads. The burstable option suits lighter or variable use. All five bill per hour of runtime, so your choice sets the hourly rate.
www.crogl.com+1
Helpful?
Vendor refund policy
There are no refunds available for using this product.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
2.10.0
Crogl 2.10.0 runs on a Kubernetes cluster from a Helm chart published with each release, serves the web UI, sign-in and REST API on one address, lets you choose how hard your model thinks, and keeps what an interrupted turn had produced instead of discarding it. Upgrading changes the ports and the configuration keys on every deployment, so read Use One Address for Crogl and the deprecations below before you upgrade.
What is New
Run Crogl on a Kubernetes Cluster
Use One Address for Crogl
Set How Hard the Model Thinks
Read What an Interrupted Turn Produced
Read the Bill of Materials for What You Installed
Deprecations
Server settings ui.port and ui.tls become web.port and web.tls. The old keys still work with a warning for at least two minor releases after this change ships; explicit web. settings take precedence. Server api.port and api.tls are ignored with a warning.
CLI connection settings api.host, api.port, and api.allow_insecure become web.. On an interactive run, the CLI offers to migrate your file. Approval saves the original as crogl.YYYY-MM-DDTHH-MM-SS.yaml, preserves custom values, and omits defaults. The old default port changes from 8082 to 4043; custom ports such as 443 stay as configured. Declining or running noninteractively leaves your file unchanged.
Kubernetes values ports.ui, tls.listeners.ui, and service.ui become their web counterparts. The corresponding api settings and ingress.apiPath are removed. The shared Ingress path remains ingress.uiPath, and the Service name changes from -ui to -web. Update custom values before installing the new chart.
Bug Fixes
The knowledge-graph runs Crogl makes for itself no longer fail when one of your connected tools is unreachable. The entities behind that connector are deferred rather than errored, a connector already known to be down is left out of later batches, and a later run picks the deferred work back up once it answers again.
Routine agent tool traffic no longer fills the server log. Each tool call still records who ran it, what it named, and whether it was allowed, and the HTTP access records are unchanged; setting log_level to debug brings back the full request and response detail while you chase a problem.
A connector-setup card left in a conversation from an earlier release no longer collects credentials. The card says so and asks you to start connector setup again with the assistant, so a credential is never typed into a card that can no longer submit it.
Outstanding dependency vulnerabilities are remediated.
Additional details
Usage instructions
Retrieve Initial Credentials:
After the first boot completes, Crogl writes a one-time credentials file containing the admin password and the startup key. SSH into the instance to retrieve them:
Access the Crogl UI:
Open https://<public-ip-or-dns>:4043 in your browser.
Accept the self-signed certificate warning (or install a CA-signed certificate).
Log in with the admin username and password retrieved from the installation-artifacts.txt file.
On initial login, the Crogl UI will guide you through configuring an LLM provider and at least one connector. Have your LLM API key and connector credentials ready before proceeding.
Support
Vendor support
Users of Free can get help and support through the Crogl Community. Sign up for the community here: <www.crogl.com/community>
For Enterprise users, support options are available with the purchase of an enterprise license. Enterprise is purchased through a private offer on the Crogl - AI for Enterprise Security solution in AWS Marketplace. That solution includes this AMI and Crogl Annual Production Support. Open that listing and select Request private offer, or contact Crogl at sales@crogl.com. Licensing and support terms are specified in your Enterprise agreement. AWS infrastructure and model services are billed separately.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Crogl Production Support provides dedicated technical assistance for organizations running the Crogl AI SOC platform. This service includes deployment support, platform health monitoring, integration troubleshooting across your SIEM, EDR, and ticketing systems, use case development, and ongoing optimization of Crogl's autonomous investigation capabilities. Available for on-premises, private cloud, and air-gapped environments, Crogl Production Support ensures your AI-driven security operations remain performant, current, and aligned with your organization's evolving threat landscape.
Vulcan Attack is an enterprise-grade, unified security platform for GenAI, designed to help enterprises securely adopt large language models (LLMs) with adversarial testing, multilingual risk simulations, and compliance framework alignment.
Linux AMI Image with pre-installed AI EdgeLabs Agent, that provides comprehensive security for IT/Edge infrastructure, clusters, and Kubernetes workloads with an advanced GenAI-powered end-to-end cybersecurity solution. All-in-one platform combines Vulnerability management, EDR, NDR, IPS/ IDS, and container/Kubernetes security in one lightweight autonomous AI agent. Powered by AI Security Assistant and AI-gen Playbooks it's enabling organizations to proactively defend against sophisticated cyber threats with unmatched effectiveness.
The platform ensures top-tier protection based on cost-effective and autonomous deployments that are driven by a set of advanced AI algorithms in order to make threat detection more automated and make it quicker for response."
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.