Crogl is a compound AI system for security operations.
By learning your workflows and working directly with
non-normalized data, Crogl autonomously investigates
alerts, works tickets, and executes threat hunts with
full audit-ability.
Crogl works directly with your existing security data
without requiring normalization, learning your
analysts' actual workflows rather than forcing them to
adapt to vendor schemas. Every AI decision is fully
auditable with complete transparency into reasoning
and evidence chains, making it ideal for highly
regulated and privacy-constrained data estates. The
result: faster MTTR, reduced alert fatigue, and a SOC
that scales without adding headcount all while
maintaining complete control and privacy by design.
Highlights
Crogl doesn't just automate steps. It adapts to your SOC, working autonomously to investigate alerts, work tickets, execute threat hunts, check
compliance, and elevate human expertise.
Crogl works directly with non-normalized security data across your entire
environment, eliminating 40% of analyst time currently lost to normalization and context-switching.
Crogl queries your SIEM, EDR, cloud platforms, and threat intel feeds in their native languages - SPL, KQL, and beyond - correlating findings automatically so analysts can focus on
decision-making rather than data retrieval.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You run Crogl at no software charge, so pricing reflects only the AWS compute you choose. Each dimension is a separate EC2 instance type billed by the hour. Your cost scales with the instance you select: options range from smaller general-purpose types like t3.small up to compute-optimized (c4.2xlarge, c3.2xlarge), memory-optimized (r3.large), general-purpose (m1.xlarge, m3.xlarge, t2.xlarge, t3.xlarge), and GPU-based (g2.2xlarge) sizes. You pick the instance matching your workload, and you pay for the hours it runs. There are no per-alert, per-investigation, or per-user fees.
Top-of-mind questions for buyers
Am I charged for the software when an EC2 instance is stopped or idle?
The Crogl software carries no charge, so stopping an instance ends the hourly compute billing for that instance. A stopped instance does not accrue hourly compute fees. You may still pay AWS for attached storage on a stopped instance, but no running-time compute charge applies.
Does my bill change based on how many alerts I investigate or how many analysts sign in?
No. Your cost is driven only by the EC2 instance-hours you run, not by activity inside Crogl. Whether you review 10 alerts or 10,000, and whether 10 or 100 analysts work, there are no per-alert, per-investigation, or per-user charges.
What am I actually paying for when I select a dimension like c4.2xlarge or r3.large?
Each dimension is one AWS EC2 instance type, billed per hour it runs. The name reflects the compute, memory, and GPU profile of that instance. You pick the size matching your workload and pay for the hours it stays running.
www.crogl.com+1
Helpful?
Vendor refund policy
There are no refunds available for using this product.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
1.2.20
We are excited to announce the release of Crogl 1.2.20! This update introduces instance-wide skill sharing for admins, makes Crogl easier to install across a wider range of environments, smooths out LM and connector configuration, and completes the rename from "Extensions" to "Connectors." We encourage all customers to upgrade.
What's New
Skill Sharing
Expanded Linux Installer Support
Docker Preflight and Remediation
Slimmer Installer Prerequisites
Unified LLM and Connector Configuration
Test Connection for Built-in Connectors
Connector API Path Rename
Bug Fixes
Fixed a pagination issue that caused the agent to miss recent comments and work notes in ServiceNow incidents with long activity histories.
Fixed an issue that prevented the local admin account from being able to see investigations created from its chat sessions.
Additional details
Usage instructions
Retrieve Initial Credentials:
After the first boot completes, Crogl writes a one-time credentials file containing the admin password and the startup key. SSH into the instance to retrieve them:
Access the Crogl UI:
Open https://<public-ip-or-dns>:4043 in your browser.
Accept the self-signed certificate warning (or install a CA-signed certificate).
Log in with the admin username and password retrieved from the installation-artifacts.txt file.
On initial login, the Crogl UI will guide you through configuring an LLM provider and at least one connector. Have your LLM API key and connector credentials ready before proceeding.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.