Skip to main content
Threat Detection & IPS/IDS

Rule & Signature-Based Threat Detection

Firecradle watches every connection for port scans, traffic floods, odd protocol behavior, and known malware. It then hands you an alert queue ranked by severity. You can act on each alert, mark it reviewed, and export the log.

๐Ÿ”Ž Based on rules and signatures - never a hidden AI model

What Firecradle Detects

There are four alert types. Each one is backed by a clear rule or signature, never a mystery output from a model.

Port Scan
Many connection attempts hit blocked or unusual ports from one source. This is the classic sign someone is scouting your network.
DDoS
A flood of traffic aims to overwhelm an interface, a service, or the connection table.
Anomaly
Traffic that breaks from normal connection or protocol patterns. It gets flagged for review, even with no known signature match.
Malware
Traffic that matches a known bad pattern, such as malware check-ins or exploit attempts.

Severity, Triaged for You

Every alert gets one of four severity levels. That way, your team knows what to check first.

Low
Just for your information. No action needed right away.
Medium
A suspicious pattern. Worth looking into.
High
Active probing, or a confirmed signature match. Review it soon.
Critical
An attack is happening right now. Needs attention immediately.

From Detection to Acknowledgment

Every alert follows the same steps: detected, acted on, shown on the dashboard, then reviewed by a team member.

Alert Lifecycle
Detected
A rule or signature matches live traffic. Firecradle creates an alert with the type, severity, source address, and packet count.
Action Taken
Depending on the mode you chose, the matching traffic is logged or blocked right away.
Surfaced
The alert shows up on the dashboard with full detail: a description, a timestamp, and the packets seen.
Acknowledged
A team member reviews the alert and marks it as handled for the audit trail.
Sample Alert Record
Type
port_scan
Severity
medium
Source IP
203.0.113.99
Packets
245
Action taken
blocked
Acknowledged
false
Description
Multiple connection attempts to blocked ports
AcknowledgeExport Log

Optional Community Threat-Intel Sharing

Appliances can choose to share anonymized signature matches with a community knowledgebase. This helps new attack patterns turn into rules and signatures faster for everyone. You decide per appliance. Nothing is shared unless you turn it on.

Real-World Use Cases

Reconnaissance Before an Attack

An outside address starts probing ports in sequence, looking for something open.

โœ…A port scan alert fires once the pattern crosses the detection threshold
โœ…It shows up on the dashboard right away, marked medium severity
โœ…The source address and packet count are logged for the security team
โœ…A team member marks the alert as reviewed once they check it

Volumetric Traffic Spike

A sudden flood of connection attempts threatens to fill up the connection table.

โœ…A DDoS alert fires, marked critical severity
โœ…The bad traffic gets blocked at the firewall right away
โœ…Full packet and timestamp detail is ready for log export
โœ…The dashboard shows the spike next to normal traffic levels for comparison

Key Advantages

โœ…Clear detection: every alert traces to a defined rule or signature, never a mystery model
โœ…Four alert types covered: port scans, traffic floods, anomalies, and malware signatures
โœ…A severity-ranked queue, from low to critical, shows your team what to check first
โœ…A full audit trail: mark alerts reviewed and export logs as compliance proof
โœ…Community-fed: optional signature sharing keeps detection up to date

See Every Threat Before It Becomes a Problem

Rule and signature-based threat detection, included in every Firecradle appliance.

No credit card required ยท Cancel anytime ยท 30-day free trial