Everything a firewall rule alone cannot catch
A firewall rule blocks a port or an address. It cannot spot an attack hidden inside allowed traffic, or notice ten failed logins in a row. Firecradle adds a whole layer above the rules: an IDS/IPS engine, threat feeds, automatic banning, and a plain-language score for how exposed you are.
Suricata: watch, or watch and block
Firecradle runs Suricata, a widely used intrusion detection and prevention engine, against published rule sets like Emerging Threats.
Blocklists that update themselves
Some attacks never need a signature match at all, because the address behind them is already known to be bad.
Make attacking your network a waste of time
A few features exist purely to slow attackers down, expose them early, or ban them outright.
Know your own exposure before someone else finds it
Firecradle turns its findings into a score and a scan, not a spreadsheet of raw numbers.
Compliance snapshots, without the consultant
Run a checklist against your setup and export the result as a report, ready to hand to an auditor or a customer.
Locking down who can sign in
Turn on 2FA so a stolen password is not enough on its own. Or connect Firecradle to a directory your company already runs, using LDAP, Active Directory, or RADIUS, so staff sign in with the account they already have. The built-in local admin can always still log in locally, so external sign-in can never lock you out.
How people actually use this
A noisy rule that cried wolf
The problem: One signature keeps firing on totally normal traffic, and the team has started ignoring every alert because of it.
Someone is guessing the admin password
The problem: A remote address keeps trying to log in to the management page, over and over, hoping to get lucky.
Everything here is included
A full security layer, not a bolt-on
Common questions
Is this AI or machine learning?
No. Detection is rule- and signature-based, using published rule sets, plus statistical baselining for the unusual-traffic alerts. Every alert traces back to a specific rule or a specific pattern you can inspect. Nothing here is a black box.
What is the difference between IDS and IPS mode?
IDS mode watches and alerts. IPS mode does the same detection but also blocks the matching traffic inline, before it reaches its target. You pick the mode per deployment.
Can I turn off just one rule instead of a whole feature?
Yes. Every signature has an ID, and you can suppress, threshold, or disable that one ID by itself. This is the fix for a single noisy rule, so you are never stuck choosing between "all alerts" and "no alerts".
Do I need to buy separate threat-intelligence subscriptions?
The core feeds are included and update themselves. Firecradle also supports paid, higher-volume rule sources if you want them later, but you get real protection out of the box.


