Crogl is a compound AI system for security operations.
By learning your workflows and working directly with
non-normalized data, Crogl autonomously investigates
alerts, works tickets, and executes threat hunts with
full audit-ability.
Crogl works directly with your existing security data
without requiring normalization, learning your
analysts' actual workflows rather than forcing them to
adapt to vendor schemas. Every AI decision is fully
auditable with complete transparency into reasoning
and evidence chains, making it ideal for highly
regulated and privacy-constrained data estates. The
result: faster MTTR, reduced alert fatigue, and a SOC
that scales without adding headcount all while
maintaining complete control and privacy by design.
Highlights
Crogl doesn't just automate steps. It adapts to your SOC, working autonomously to investigate alerts, work tickets, execute threat hunts, check
compliance, and elevate human expertise.
Crogl works directly with non-normalized security data across your entire
environment, eliminating 40% of analyst time currently lost to normalization and context-switching.
Crogl queries your SIEM, EDR, cloud platforms, and threat intel feeds in their native languages - SPL, KQL, and beyond - correlating findings automatically so analysts can focus on
decision-making rather than data retrieval.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You run Crogl at no software charge, so pricing reflects only the AWS compute you choose. Each dimension is a separate EC2 instance type billed by the hour. Your cost scales with the instance you select: options range from smaller general-purpose types like t3.small up to compute-optimized (c4.2xlarge, c3.2xlarge), memory-optimized (r3.large), general-purpose (m1.xlarge, m3.xlarge, t2.xlarge, t3.xlarge), and GPU-based (g2.2xlarge) sizes. You pick the instance matching your workload, and you pay for the hours it runs. There are no per-alert, per-investigation, or per-user fees.
Top-of-mind questions for buyers
Am I charged for the software when an EC2 instance is stopped or idle?
The Crogl software carries no charge, so stopping an instance ends the hourly compute billing for that instance. A stopped instance does not accrue hourly compute fees. You may still pay AWS for attached storage on a stopped instance, but no running-time compute charge applies.
Does my bill change based on how many alerts I investigate or how many analysts sign in?
No. Your cost is driven only by the EC2 instance-hours you run, not by activity inside Crogl. Whether you review 10 alerts or 10,000, and whether 10 or 100 analysts work, there are no per-alert, per-investigation, or per-user charges.
What am I actually paying for when I select a dimension like c4.2xlarge or r3.large?
Each dimension is one AWS EC2 instance type, billed per hour it runs. The name reflects the compute, memory, and GPU profile of that instance. You pick the size matching your workload and pay for the hours it stays running.
www.crogl.com+1
Helpful?
Vendor refund policy
There are no refunds available for using this product.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
2.6.0
Crogl 2.6.0 establishes whether the hosts in an investigation were vulnerable when the event happened, sets up an MCP connector from a request in chat, and warns an administrator when the deployment host is running short on CPU, memory, or disk.
What is New
Vulnerability Context in Investigations
Create an MCP Connector from Chat
Know When the Host Runs Short on CPU, Memory, or Disk
Choose Which Ticketing Connector the Dashboard Shows
Token Limits Default to the Models Maximum
Send Files Without a Message
See How Much Each Report Section Holds
Additional details
Usage instructions
Retrieve Initial Credentials:
After the first boot completes, Crogl writes a one-time credentials file containing the admin password and the startup key. SSH into the instance to retrieve them:
Access the Crogl UI:
Open https://<public-ip-or-dns>:4043 in your browser.
Accept the self-signed certificate warning (or install a CA-signed certificate).
Log in with the admin username and password retrieved from the installation-artifacts.txt file.
On initial login, the Crogl UI will guide you through configuring an LLM provider and at least one connector. Have your LLM API key and connector credentials ready before proceeding.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Crogl Production Support provides dedicated technical assistance for organizations running the Crogl AI SOC platform. This service includes deployment support, platform health monitoring, integration troubleshooting across your SIEM, EDR, and ticketing systems, use case development, and ongoing optimization of Crogl's autonomous investigation capabilities. Available for on-premises, private cloud, and air-gapped environments, Crogl Production Support ensures your AI-driven security operations remain performant, current, and aligned with your organization's evolving threat landscape.
This product has charges associated with it for seller support. Croogo is an open source content management system (CMS) based on CakePHP, designed for flexibility and ease of use.
This product has charges associated with it for seller support. Croogo is an open source content management system (CMS) based on CakePHP, designed for flexibility and ease of use.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.