Skip to main content
Security services

Everything a firewall rule alone cannot catch

A firewall rule blocks a port or an address. It cannot spot an attack hidden inside allowed traffic, or notice ten failed logins in a row. Firecradle adds a whole layer above the rules: an IDS/IPS engine, threat feeds, automatic banning, and a plain-language score for how exposed you are.

Rule- and signature-based · not AI or machine learning

Suricata: watch, or watch and block

Firecradle runs Suricata, a widely used intrusion detection and prevention engine, against published rule sets like Emerging Threats.

Detect and block, inline
Firecradle can just watch traffic and warn you, or sit inline and drop the bad packets before they land. You choose.
Published rule sets
Rules come from Emerging Threats and other public sources, updated on a schedule. Nothing is a secret formula.
Tune one rule, not the whole thing
One rule too noisy? Silence just that rule by its ID. The rest of the protection keeps running.
Every alert has a reason
Each alert points at the exact rule that fired. You can read the rule yourself and see why it matched.
Firecradle IDS/IPS screen showing engine status, mode toggle between IDS and IPS, loaded rule count, and a list of recent alerts with source address and action taken
Every alert names the exact signature that matched. Nothing here is a guess.

Blocklists that update themselves

Some attacks never need a signature match at all, because the address behind them is already known to be bad.

Known-bad address lists
Groups like Spamhaus, DShield, and FireHOL track addresses already caught attacking someone. Firecradle blocks them automatically.
Feeds update themselves
New bad addresses get added and old ones drop off on a schedule. You never touch a list by hand.
Block by country
Never do business in a certain country? Block every address from it in one setting.

Make attacking your network a waste of time

A few features exist purely to slow attackers down, expose them early, or ban them outright.

Automatic banning
Guess a password wrong too many times and Firecradle bans that address on the spot, the way fail2ban works.
Honeypots and tarpits
A honeypot is a fake target nobody legitimate has a reason to touch. A tarpit is a honeypot that answers very slowly, wasting an attacker’s time. Either way, touching one proves someone is up to no good.
Port knocking
The management port stays invisible to scanners until you knock in the right pattern first. Nothing to attack if you can’t even see it.
Rogue DHCP and ARP-spoof detection
A second, unauthorized address server or a device lying about its own address both get flagged the moment they appear.

Know your own exposure before someone else finds it

Firecradle turns its findings into a score and a scan, not a spreadsheet of raw numbers.

Unusual-traffic alerts
Firecradle learns what normal traffic looks like on your network, then flags patterns that break from it. This is statistics, not a black box.
Self-scan
On a schedule, Firecradle scans its own open ports and services, the way an attacker would, and tells you what is exposed.
A security score in plain language
One score, from "needs work" to "strong", instead of a wall of numbers. Click through to see exactly what is pulling it down.
Firecradle security posture screen showing an overall score labelled Strong, with a breakdown of checks passed and a short list of recommended fixes
One score in plain language. Click any line to see why.

Compliance snapshots, without the consultant

Run a checklist against your setup and export the result as a report, ready to hand to an auditor or a customer.

PCI
The checklist for handling card payments. Useful if you take payments on your network.
HIPAA
The checklist for handling health records. Useful for clinics and healthcare offices.
CIS-lite
A shorter, general good-hygiene checklist for everyone else. A sensible baseline even if no regulation requires it.
Firecradle compliance screen showing PCI, HIPAA and CIS-lite checklists, each with a pass or fail count and an export report button
A checklist you can run in minutes, and export as a report.

Locking down who can sign in

2FA
Two-factor sign-in for every admin account
LDAP
Sign in with your company directory
AD
Sign in with your Windows domain account
RADIUS
Sign in through an existing RADIUS server

Turn on 2FA so a stolen password is not enough on its own. Or connect Firecradle to a directory your company already runs, using LDAP, Active Directory, or RADIUS, so staff sign in with the account they already have. The built-in local admin can always still log in locally, so external sign-in can never lock you out.

How people actually use this

A noisy rule that cried wolf

The problem: One signature keeps firing on totally normal traffic, and the team has started ignoring every alert because of it.

What Firecradle does:
Find the rule by its ID in the alert record
Suppress just that one rule, not the whole rule set
Every other signature keeps watching, uninterrupted
Alerts start meaning something again

Someone is guessing the admin password

The problem: A remote address keeps trying to log in to the management page, over and over, hoping to get lucky.

What Firecradle does:
Firecradle counts the failed attempts from that address
After a set number, that address is banned automatically
The ban shows up in the dashboard with a plain reason
A password guesser never gets enough tries to matter

Everything here is included

A full security layer, not a bolt-on

Suricata IDS/IPS, with detect-only or inline-block modes
Per-signature tuning: suppress, threshold, or disable by rule ID
Threat-intelligence feeds that update on a schedule
GeoIP and country blocking
Automatic banning of brute-force attackers
Honeypots, tarpits, and port knocking
Rogue DHCP and ARP-spoof detection
Unusual-traffic alerts based on statistical baselining, not AI
Scheduled self-scan of your own attack surface
A plain-language security posture score
PCI, HIPAA, and CIS-lite compliance snapshots with an export
Two-factor authentication and LDAP/Active Directory/RADIUS sign-in

Common questions

Is this AI or machine learning?

No. Detection is rule- and signature-based, using published rule sets, plus statistical baselining for the unusual-traffic alerts. Every alert traces back to a specific rule or a specific pattern you can inspect. Nothing here is a black box.

What is the difference between IDS and IPS mode?

IDS mode watches and alerts. IPS mode does the same detection but also blocks the matching traffic inline, before it reaches its target. You pick the mode per deployment.

Can I turn off just one rule instead of a whole feature?

Yes. Every signature has an ID, and you can suppress, threshold, or disable that one ID by itself. This is the fix for a single noisy rule, so you are never stuck choosing between "all alerts" and "no alerts".

Do I need to buy separate threat-intelligence subscriptions?

The core feeds are included and update themselves. Firecradle also supports paid, higher-volume rule sources if you want them later, but you get real protection out of the box.

A security layer you can actually explain to an auditor

IDS/IPS, threat feeds, and compliance snapshots are part of every Firecradle appliance. Try it free for 30 days.

No credit card required · Cancel anytime · 30-day free trial