Experiencing a breach? Contact us
turingtower

CRUDGuard

Threat detection and investigation for your databases

CRUDGuard ingests activity from your databases and any other log source, and turns it into threat narratives with entities, timelines, behavioural context, and explicit confidence levels.

Get started

The database is the target

Every breach that matters ends at the data layer, where customer records, credentials, and financial and health data live. CRUDGuard runs a SIEM-style ingest, detect, and triage workflow scoped to that layer. It reads the query and connection activity your databases already emit and works out who is behind each action, what that account has done before, and whether the behaviour fits a known threat.

Core Workflow

What the analyst actually sees

CRUDGuard entity association map for an account, showing a graph of connected accounts, databases, and IPs with a highlighted attack path and evidence-weighted edges

Entity Graph

Accounts, hosts, and databases become persistent objects with behavioural history. Relationships are computed from real activity and scored by evidence weight, so an attack path reads at a glance.

CRUDGuard behavioural fingerprint for an account, showing intent activity over time, intent transitions, and a drift multiplier above threshold

Threat Narratives

Behavioural sequences become stories, and related stories build into a hypothesis an analyst can follow as a single timeline, with the behavioural drift that triggered it scored against the entity's own baseline.

CRUDGuard evidence panel for a database, showing evidence strength, evidence row count, and a list of recent stories and hypotheses

Replayable Evidence

Raw observations never change. Every hypothesis and story keeps the evidence rows behind it, so any finding can be replayed against what it rests on when an auditor or regulator asks.

From raw activity to triage-ready narratives

step i

Ingest

Connect PostgreSQL, MySQL, MSSQL, IBM Informix, MongoDB, Oracle, cloud-native stores, or any other log source. The adapter-driven architecture brings a new telemetry source online in minutes to hours and normalizes it into one cross-referenced stream.

step ii

Detect

Temporal patterns are evaluated per entity against the live stream. Threshold violations and slow behavioural drift both register, turning multi-step attack sequences into trackable stories with explicit evidence chains.

step iii

Investigate

Each hypothesis arrives with a confidence score and its MITRE ATT&CK mapping, ranked so analysts work the strongest signals first. Every one opens with its full timeline and the exact evidence chain that produced it.

What's in the product

Behavioural drift detection

Each entity is scored against its own baseline with Jensen-Shannon Divergence, catching slow drift that no single rule would trip.

Path exposure

Paths from suspicious entities to crown-jewel data are mapped continuously, so lateral movement shows up before compromise completes.

Story engine

Threshold violations and behavioural sequences become stories you can track, each with the evidence chain that built it.

Hypothesis and case automation

High-confidence hypotheses open cases on their own, each carrying the story chain and MITRE technique that triggered it.

Entity lifecycle tracking

First-seen and reactivation events fire with no training period, so a dormant account that resurfaces gets noticed.

Exclusions as institutional memory

Suppression rules are preserved as analytical decisions, each one time-bounded and tracked by how often it fires.

Real-world use case

CRUDGuard answers the questions an alert never asks: what is this entity, what has it done before, does this fit a known threat pattern, and how confident are we?

See it run on your database traffic