
NodeSentinel
Cybersecurity & IT Visibility for Windows Networks
I kept seeing the same gap in small and mid-sized companies: real Windows-heavy infrastructure (network, endpoints, Active Directory) but no affordable way to actually see what's happening inside it. Enterprise observability and security platforms are either too complex, too expensive, or require sending sensitive infrastructure data to someone else's cloud.
So I built NodeSentinel: a local-first Windows app that gives IT teams visibility into their own infrastructure — network discovery, asset inventory/CMDB, endpoint security posture (Firewall/Defender/BitLocker), vulnerability management (NVD + CISA KEV), Active Directory identity risk, a lightweight event-log SIEM, SNMP monitoring, alerts with a full lifecycle, and exportable compliance reports. Everything is correlated through a single explainable risk engine, and everything stays on the customer's own machine — no cloud dependency, no per-seat fees.
It's a functional MVP at this point: most core modules are already built and verified against real data — real network scans, real Windows endpoints, real CVE correlation — not just demo data. Two things are still open: automatic scheduled scanning isn't built yet (scans are triggered manually for now), and AD/LDAP sync has been built but not yet verified end-to-end on a real domain-joined machine.
I'm currently exploring what's next for it, including the possibility of finding someone to take it further. Happy to talk if this is something you'd want to dig into.
If you're interested, I'm open to offers — thinking somewhere in the $8,000–$15,000 range for the codebase, architecture and brand assets, but let's talk.
About
Small and mid-sized companies run real Windows infrastructure but can't afford enterprise visibility tools. NodeSentinel gives them that visibility locally — no cloud, no per-seat fees.

5 Comments
Good question. Honestly, I'd say most of the real value is in the core validated system — network discovery, asset inventory, endpoint security posture, vulnerability correlation (NVD/CISA KEV), SNMP monitoring, and the risk/alerting engine tying it all together. That's the bulk of the engineering, and it works today against real infrastructure without needing AD at all.
The AD/LDAP piece is real, working code — read-only sync, nested-group privilege calculation — but it's additive rather than load-bearing. It makes the product more complete for AD-heavy mid-market shops, but the core product stands on its own without it. So you're not betting on unproven AD magic; you're getting a working visibility/security engine, plus an AD integration that just needs a real domain environment to finish validating end-to-end.
Appreciate you digging into it — good luck with Beryxa too!
This comment was deleted 2 days ago