See the network clearly.
Respond with confidence.

NetHarrier brings flow analytics, DDoS detection, and network mitigation into one clear operating view. You stay in control of the data and every response.

Network traffic and threat response, in one system.

Built for ISP, hosting, data-center, and enterprise network teams that need to understand traffic quickly. The final decision stays close to the network.

See what is moving

Turn sampled flows and interface counters into a navigable view by IP, interface, protocol, country, and AS.

  • Per-source and destination traffic
  • AS-to-AS paths and top talkers
  • Interface health and utilization

Find changes that matter

Evaluate thresholds, relative growth, and learned baselines directly on the live stream. Detection does not wait for a database query.

  • Per-vector attack detection
  • Multi-vector fingerprinting
  • Confirmation and decay states

Respond with control

Review the evidence, apply policy, and announce FlowSpec or RTBH through controlled mitigation providers.

  • Dry-run from the first deployment
  • ExaBGP and GoBGP providers
  • TTL, rate, and rule-count limits

The whole network.
Ready to investigate.

Keep live traffic, active attacks, infrastructure health, and mitigation state in one dense operator view. Drill down when the signal changes.

NOC / Overview
NETHARRIER
Live   ACME-NET
OPERATIONSNOC Overview

Last updated 3s ago

INGRESS412 Gbps

↗ 2.1% 1h

EGRESS88 Gbps

↘ 0.4% 1h

PACKETS64.2 Mpps

↗ 1.8% 1h

ACTIVE ATTACKS3

● 1 critical

MITIGATED38 Gbps

4 active rules

DEVICES18/18

● All healthy

Aggregate trafficLast 24 hours

Ingress Egress

Aggregate network traffic A sample mirrored traffic chart with ingress above and egress below the center line.
Active attacks3 incidents
SEVTARGETVECTORRATESTATE
CRIT203.0.113.24UDP/DNS38.1 GbpsMitigating
HIGH2001:db8::42TCP/SYN11.4 GbpsReview
MED198.51.100.8UDP/FRAG4.7 GbpsWatching
Interface utilizationExternal links

18 / 18 up

Interface concept shown with sample data.

Live traffic and wallboard view

Flow explorer and raw samples

Incident fingerprints and history

Devices, peers, and policy state

How NetHarrier works.

Each part of the pipeline has a clear job. Run everything together in a simple deployment, or separate roles as your network grows.

  1. Collect

    Receive sFlow from routers and switches. Poll SNMP for authoritative counters and interface context.

  2. Enrich

    Add interface, prefix, tenant, ASN, geography, and routing context while the flow stays in motion.

  3. Detect

    Evaluate one-second windows in memory. Confirm the event, then build an evidence-rich fingerprint.

  4. Respond

    Apply policy and safety checks before a FlowSpec or RTBH announcement leaves the platform.

Simple deployment

One binary. Separate roles when needed.

RouterssFlow
InterfacesSNMP
RoutingBMP
NetHarriercollect, enrich, detect, mitigate, API
all
ClickHouseTelemetry
PostgreSQLConfig + state

In-process transport is the default. NATS is optional when you need to scale out.

FLOW CONFIDENCEWhat the samples support

1 / √ samples

400+ High
30–400 Range
<30 Low
0 Gap

Know what the data can prove.

Sampled flow data is an estimate. NetHarrier is designed to anchor traffic magnitude to SNMP, use sFlow for composition, and carry sample confidence all the way to the operator.

  • Show a range when sample counts are low.
  • Render unknown intervals as gaps, never false zeroes.
  • Flag policies the current sampling rate cannot reach.
“Unknown” is useful operational information. The interface should say so.

Fast response.
Hard boundaries.

Mitigation changes the network. NetHarrier is designed to keep every automated and manual action inside non-negotiable controls.

Dry-run by default

Monitored-prefix checks

Never-mitigate lists

Per-peer rule caps

Automatic rule TTLs

Complete audit trail

MITIGATION PREVIEWDRY RUN
CRITICAL
DNS reflection203.0.113.24 / 38.1 Gbps
Action
FlowSpec drop
Match
udp, src port 53, dst /32
Peer
edge-ams-01
Rule TTL
60 minutes

Inside monitored prefix

Peer capacity available

Never-mitigate clear

announcement heldReview exact rule →

Own the platform.
Keep a team behind you.

NetHarrier is being built as open-source infrastructure you can inspect, deploy, and adapt. Commercial help will be there for teams that want it.

Your network. Your data. Your deployment.

Run NetHarrier in your own environment. Read the detection path, verify the controls, and contribute improvements that help operators everywhere.

Transparent

Inspect how every signal and response is produced.

Extensible

Add integrations through explicit provider interfaces.

Practical

Start as one binary; split roles only when needed.

View the project on GitHub

Commercial support is planned.

We will help teams design the deployment, tune detection, integrate routing, and operate NetHarrier with confidence.

  • Architecture and rollout guidance
  • Detection and threshold tuning
  • Routing integration and operations

Turnkey appliancesComing later

Bring your first flow into view.

Begin with collection and dry-run detection. Add network-led mitigation when your policies, peers, and team are ready.

Configure exporters Connect telemetry Validate in dry run
NetHarrier is in active development. Setup documentation will ship with the first public release.