Rule & Signature-Based Threat Detection
Firecradle watches every connection for port scans, traffic floods, odd protocol behavior, and known malware. It then hands you an alert queue ranked by severity. You can act on each alert, mark it reviewed, and export the log.
What Firecradle Detects
There are four alert types. Each one is backed by a clear rule or signature, never a mystery output from a model.
Severity, Triaged for You
Every alert gets one of four severity levels. That way, your team knows what to check first.
From Detection to Acknowledgment
Every alert follows the same steps: detected, acted on, shown on the dashboard, then reviewed by a team member.
Optional Community Threat-Intel Sharing
Appliances can choose to share anonymized signature matches with a community knowledgebase. This helps new attack patterns turn into rules and signatures faster for everyone. You decide per appliance. Nothing is shared unless you turn it on.
Real-World Use Cases
Reconnaissance Before an Attack
An outside address starts probing ports in sequence, looking for something open.
Volumetric Traffic Spike
A sudden flood of connection attempts threatens to fill up the connection table.