Crogl is AI for enterprise security. It investigates across your existing tools and documents the work so your analysts can review the evidence and make the call. Deploy in your AWS account with Free for a single user, or choose Enterprise for your team under a paid annual agreement.
Crogl investigates across your existing security stack. It gathers context, queries your tools, and follows the evidence across alerts and threat advisories. Your analysts can review each step, change direction, and decide what happens next.
Every investigation leaves a record. Crogl documents the queries, evidence, and findings in the platform and can record the work in your ticketing or case management system. Your team receives an investigation it can review, share, and use to make a decision.
Your data stays in the systems you already use. Crogl queries your SIEM, EDR, identity, cloud, data lake, and threat intelligence sources in their native formats, without schema normalization. You can build connectors and skills for your own tools and workflows.
This AMI runs on Amazon EC2 in your AWS account. You control the deployment and its connections to your tools and model services. For other deployment options, including on-premises and air-gapped environments, contact Crogl.
Free is for one user and remains free. It includes all connectors, unlimited skills and audit trails, username and password access, and community support. Free and Enterprise use the same core platform; the plan determines the features and access available.
Enterprise is for SOC teams running Crogl around the clock. The paid annual plan includes unlimited users and investigations, autonomous investigations and threat hunting, single sign-on, role-based access control, audit log export, use of your enterprise LLM service, and dedicated support with agreed service levels. Pricing is custom and team based, with no per-alert, per-investigation, or per-user fees.
For Enterprise pricing, select Request private offer on the Crogl - AI for Enterprise Security solution linked under Resources. The solution includes this AMI and Annual Production Support; software licensing and support are specified in your Enterprise agreement. AWS infrastructure and separately contracted model services are additional costs.
Highlights
Follow the evidence. Crogl investigates across your existing security tools and documents the queries, findings, and conclusions. Your analysts review the work and make the call.
Work with the tools you have. Crogl queries your data in its native format, without schema normalization. Run it in your AWS account and build connectors and skills for your own environment.
Start with Free for one user. Choose Enterprise for team access, autonomous operations, and dedicated support under a paid annual agreement. Request Enterprise pricing through the Crogl multi-product solution.
decision-making rather than data retrieval.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You install this software from a machine image on your own AWS instance, and the software itself carries no license charge. Pricing here reflects your choice of EC2 instance size, billed per hour of runtime. You pick from five instance types across two families and two sizes within each. Larger instances give more compute for heavier workloads, while the burstable option suits lighter or variable use. You pay only for the hours each instance runs. Your total cost depends on which instance you select and how long you keep it running.
Top-of-mind questions for buyers
Am I charged for an instance when it is stopped or paused?
The software itself carries no license charge, so no software fee applies. AWS meters the instance by hour of runtime, so a stopped instance stops accruing hourly compute charges. Underlying storage attached to a stopped instance may still incur AWS fees, but running time drives the compute cost.
What am I actually paying for if the software has no license fee?
You pay only the hourly rate for the EC2 instance running the machine image. Charges reflect the instance size you select and the hours it runs. There are no per-alert, per-investigation, or per-user software fees, so investigating more alerts does not raise the bill.
How do the five instance options differ for choosing the right size?
You pick from two instance families, each in two sizes, plus one burstable option. The larger size in each family gives more compute for heavier workloads. The burstable option suits lighter or variable use. All five bill per hour of runtime, so your choice sets the hourly rate.
www.crogl.com+1
Helpful?
Vendor refund policy
There are no refunds available for using this product.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
2.9.0
Crogl 2.9.0 shows you the subagents working on your question, filters the Jobs and Runs lists by who owns a job, and lets Crogl research an API before it writes a connector for it. It also repairs signing in after a session expires, and makes starting Crogl on a slow host both reliable and quiet.
What is New
See the Subagents Working on Your Question
Filter Jobs and Runs by Who Owns Them
Let Crogl Research an API Before It Writes the Connector
Bug Fixes
Signing in again after a session expired while you were away no longer requires clearing the browsers stored data by hand. A session that ran out with no chance to renew could leave Crogl unable to reach its own login page, which read as a broken deployment rather than an expired session.
Starting Crogl on a slow host no longer fails before the server is ready: crogl.sh up waits up to five minutes for the server to answer. An install that supplies local administrator credentials could previously give up after 30 seconds while Crogl carried on starting, finish without creating that administrator, and leave every later sign-in failing with the same generic error as a wrong password. A server that exits instead of starting is reported straight away, with the end of its startup output, rather than after the rest of that wait.
An install is no longer buried in harmless warnings from Crogl and the tools it runs. Errors still appear, as do the warnings worth acting on such as a signature, certificate, or permission problem, and --verbose shows all of it.
Starting a local installation preserves the bootstrap secrets that unlock your existing database, including when its configuration is regenerated. Keep the database and its matching bootstrap files together.
Additional details
Usage instructions
Retrieve Initial Credentials:
After the first boot completes, Crogl writes a one-time credentials file containing the admin password and the startup key. SSH into the instance to retrieve them:
Access the Crogl UI:
Open https://<public-ip-or-dns>:4043 in your browser.
Accept the self-signed certificate warning (or install a CA-signed certificate).
Log in with the admin username and password retrieved from the installation-artifacts.txt file.
On initial login, the Crogl UI will guide you through configuring an LLM provider and at least one connector. Have your LLM API key and connector credentials ready before proceeding.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Crogl Production Support provides dedicated technical assistance for organizations running the Crogl AI SOC platform. This service includes deployment support, platform health monitoring, integration troubleshooting across your SIEM, EDR, and ticketing systems, use case development, and ongoing optimization of Crogl's autonomous investigation capabilities. Available for on-premises, private cloud, and air-gapped environments, Crogl Production Support ensures your AI-driven security operations remain performant, current, and aligned with your organization's evolving threat landscape.
Vulcan Attack is an enterprise-grade, unified security platform for GenAI, designed to help enterprises securely adopt large language models (LLMs) with adversarial testing, multilingual risk simulations, and compliance framework alignment.
Pre-installed and security-hardened OpenClaw AI agent AMI. Launch an EC2 instance, add your credentials, and start using your agent. Ready to configure out of the box.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance targeted specifically at GPU optimized AMIs. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.