Crogl is AI for the enterprise SOC. It investigates every alert and threat advisory using the tools and data already in your SOC, in their native formats, without schema normalization. Free for one user. Enterprise for your team under a paid annual agreement.
Crogl is AI for the enterprise SOC. It investigates every alert. It documents every action. Your analysts review the evidence and make the call.
Free and Enterprise
This AMI carries no software license charge. Free is for one user and remains free. It includes all connectors, unlimited skills, unlimited audit trails, username and password access, and direct access to Crogl engineers in the community Slack. You bring your own LLM provider credentials, and your model provider bills that usage.
Enterprise is for SOC teams running Crogl around the clock. The paid annual plan adds unlimited users and investigations, autonomous investigation and threat hunting, single sign-on, role-based access control, and audit log export. It also covers use of your enterprise LLM service and dedicated support with agreed service levels. Pricing is custom and team based. No per-alert, per-investigation, or per-user fees.
Free and Enterprise run the same core platform. The plan determines the features and access available to your team.
What an investigation looks like
An alert lands. Crogl pulls the host and identity context, queries your EDR for process lineage, and checks the authentication record. It pivots to your data lake for anything the SIEM did not retain, then reads the relevant threat advisory. It writes down every query it ran and every result it got back. Your analyst opens the investigation, sees the reasoning, redirects it, and decides what happens next. Crogl handles the investigation. The analyst makes the call.
Crogl records the work in your ticketing or case management system. Auditable, repeatable, inspectable. Every investigation is an artifact you can hand to an auditor, a regulator, or your board.
Works where the data lives
Crogl queries your SIEM, EDR, identity, cloud, data lake, ticketing, and threat intelligence sources in their native formats, without schema normalization. There is no pipeline to build and no index to populate first. You can build connectors and skills for your own tools and workflows.
You bring your own model. Crogl runs against the LLM service you choose and host, including models that stay inside an air-gapped boundary.
Deployment
This AMI runs on Amazon EC2 in your AWS account. You control the deployment, its connections to your tools, and its connection to your model services. Most teams reach their first investigation within minutes of first login. Crogl also runs on premises, in private cloud, and in air-gapped environments. Contact Crogl for those options.
In production today
One defense organization runs Crogl against 60,000 alerts per month across 100TB of data, three SIEMs, and two SOARs, at an impact equivalent to six full-time analysts. Crogl is built for the hardest security environments.
Request Enterprise pricing
Enterprise is purchased through a private offer on the Crogl - AI for Enterprise Security solution in AWS Marketplace. That solution includes this AMI and Crogl Annual Production Support. Open that listing and select Request private offer, or contact Crogl at sales@crogl.com. Licensing and support terms are specified in your Enterprise agreement. AWS infrastructure and model services are billed separately.
Highlights
Investigates every alert. Documents every action. Crogl pulls host and identity context, queries your EDR, pivots to your data lake, and reads the advisory, writing down every query and result. The analyst reviews the reasoning and makes the call.
Works where the data lives. Crogl queries your SIEM, EDR, identity, cloud, and data lake in their native formats, without schema normalization. No pipeline to build. Bring your own model, including one hosted inside an air-gapped boundary.
Free is for one user and remains free: all connectors, unlimited skills, and community Slack access to Crogl engineers. Enterprise adds unlimited users, autonomous investigation, SSO, RBAC, and dedicated support. Request pricing on the Crogl solution.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You install this software from a machine image on your own AWS instance, and the software itself carries no license charge. Pricing here reflects your choice of EC2 instance size, billed per hour of runtime. You pick from five instance types across two families and two sizes within each. Larger instances give more compute for heavier workloads, while the burstable option suits lighter or variable use. You pay only for the hours each instance runs. Your total cost depends on which instance you select and how long you keep it running.
Top-of-mind questions for buyers
Am I charged for an instance when it is stopped or paused?
The software itself carries no license charge, so no software fee applies. AWS meters the instance by hour of runtime, so a stopped instance stops accruing hourly compute charges. Underlying storage attached to a stopped instance may still incur AWS fees, but running time drives the compute cost.
What am I actually paying for if the software has no license fee?
You pay only the hourly rate for the EC2 instance running the machine image. Charges reflect the instance size you select and the hours it runs. There are no per-alert, per-investigation, or per-user software fees, so investigating more alerts does not raise the bill.
How do the five instance options differ for choosing the right size?
You pick from two instance families, each in two sizes, plus one burstable option. The larger size in each family gives more compute for heavier workloads. The burstable option suits lighter or variable use. All five bill per hour of runtime, so your choice sets the hourly rate.
www.crogl.com+1
Helpful?
Vendor refund policy
There are no refunds available for using this product.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
2.11.0
Crogl 2.11.0 lets a scheduled job run a program, not only a prompt, and lets an administrator pause every scheduled job at once. On Amazon EKS, one command now installs Crogl. The crogl CLI gains skill management, paging and filtering on every list, a confirmation before a delete, and exit codes a pipeline can act on. Some CLI commands are renamed and the old names are removed. If you script the CLI or call the REST API directly, read Deprecations before you upgrade. Upgrade the CLI on every machine that connects to the server.
What is New
Run a Program on a Schedule
Pause Every Scheduled Job at Once
Install Crogl on Amazon EKS with One Command
Manage Your Skills From the CLI
Page, Filter, and Sort Every List
Confirm Before a Destructive crogl Command
Tell a Command Failure Apart From a Rejected Sign-In
Sign In Machine-to-Machine on Microsoft Entra
Tell a Command Failure Apart From a Rejected Sign-In
0: success.
1: the operation failed, for example a server or network error.
2: the command was invalid, for example a bad argument or an incomplete sign-in configuration.
3: Crogl or your identity provider rejected your sign-in.
Deprecations
set-config and set-models change only the keys you name. replace-config and replace-models reset every key you leave out to its default.
The -api-proxy and -connector-type command aliases are removed. Use the connector and connector-package names in their place.
--proxy becomes --connector on add-connector-header, update-connector-header, and delete-connector-header. --type becomes --package on create-connector.
List endpoints now return the rows under data, with a next cursor when more remain, and take $limit, $sort, $count, and $start. Pages hold 100 rows by default and at most 500. An integration that reads a list response as a bare array must read data instead.
A request body with an attribute the endpoint does not know is rejected with 400, and a Content-Type other than application/json with 415.
Replacing a connectors OAuth2 configuration is PUT /connectors/{id}/oauth2 rather than a POST.
Bug Fixes
An upgrade from an installation older than local sign-in no longer breaks sign-in. The installer switches the server and CLI to local sign-in and saves each original configuration beside it.
The credential card the assistant shows while it researches an API accepts your credentials again. Crogl encrypts them and never sends them to the assistant.
The admin dashboard shows host CPU, memory, and disk health on a Kubernetes deployment, the same as on a single-host install.
The installer now points at the troubleshooting page and support@crogl.com when something goes wrong.
Additional details
Usage instructions
Retrieve Initial Credentials:
After the first boot completes, Crogl writes a one-time credentials file containing the admin password and the startup key. SSH into the instance to retrieve them:
Access the Crogl UI:
Open https://<public-ip-or-dns>:4043 in your browser.
Accept the self-signed certificate warning (or install a CA-signed certificate).
Log in with the admin username and password retrieved from the installation-artifacts.txt file.
On initial login, the Crogl UI will guide you through configuring an LLM provider and at least one connector. Have your LLM API key and connector credentials ready before proceeding.
Support
Vendor support
Users of Free can get help and support through the Crogl Community. Sign up for the community here: <www.crogl.com/community>
For Enterprise users, support options are available with the purchase of an enterprise license. Enterprise is purchased through a private offer on the Crogl - AI for Enterprise Security solution in AWS Marketplace. That solution includes this AMI and Crogl Annual Production Support. Open that listing and select Request private offer, or contact Crogl at sales@crogl.com. Licensing and support terms are specified in your Enterprise agreement. AWS infrastructure and model services are billed separately.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Crogl Production Support provides dedicated technical assistance for organizations running the Crogl AI SOC platform. This service includes deployment support, platform health monitoring, integration troubleshooting across your SIEM, EDR, and ticketing systems, use case development, and ongoing optimization of Crogl's autonomous investigation capabilities. Available for on-premises, private cloud, and air-gapped environments, Crogl Production Support ensures your AI-driven security operations remain performant, current, and aligned with your organization's evolving threat landscape.
CEI DARTS deploys agentic AI to convert business specifications into production-ready code, documentation, and test cases with embedded governance for regulated enterprise teams.
Vulcan Attack is an enterprise-grade, unified security platform for GenAI, designed to help enterprises securely adopt large language models (LLMs) with adversarial testing, multilingual risk simulations, and compliance framework alignment.
AlertAI provides a single-click Security & AI FinOps gateway for AI Apps and Agents with zero code changes. Enforce 9 Standards EU AI Act, NIST and GDPR compliance using 500+ pre-configured rules to block LLM, RAG, and MCP threats in real-time. Ensure enterprise-grade safety and budget oversight with automated OWASP, MITRE alignment and 6 months of free AI cost optimization.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.