See what is moving
Turn sampled flows and interface counters into a navigable view by IP, interface, protocol, country, and AS.
- Per-source and destination traffic
- AS-to-AS paths and top talkers
- Interface health and utilization
NetHarrier brings flow analytics, DDoS detection, and network mitigation into one clear operating view. You stay in control of the data and every response.
Built for ISP, hosting, data-center, and enterprise network teams that need to understand traffic quickly. The final decision stays close to the network.
Turn sampled flows and interface counters into a navigable view by IP, interface, protocol, country, and AS.
Evaluate thresholds, relative growth, and learned baselines directly on the live stream. Detection does not wait for a database query.
Review the evidence, apply policy, and announce FlowSpec or RTBH through controlled mitigation providers.
Keep live traffic, active attacks, infrastructure health, and mitigation state in one dense operator view. Drill down when the signal changes.
Last updated 3s ago
↗ 2.1% 1h
↘ 0.4% 1h
↗ 1.8% 1h
● 1 critical
4 active rules
● All healthy
Ingress Egress
18 / 18 up
Interface concept shown with sample data.
Live traffic and wallboard view
Flow explorer and raw samples
Incident fingerprints and history
Devices, peers, and policy state
Each part of the pipeline has a clear job. Run everything together in a simple deployment, or separate roles as your network grows.
Receive sFlow from routers and switches. Poll SNMP for authoritative counters and interface context.
Add interface, prefix, tenant, ASN, geography, and routing context while the flow stays in motion.
Evaluate one-second windows in memory. Confirm the event, then build an evidence-rich fingerprint.
Apply policy and safety checks before a FlowSpec or RTBH announcement leaves the platform.
One binary. Separate roles when needed.
In-process transport is the default. NATS is optional when you need to scale out.
1 / √ samples
Sampled flow data is an estimate. NetHarrier is designed to anchor traffic magnitude to SNMP, use sFlow for composition, and carry sample confidence all the way to the operator.
“Unknown” is useful operational information. The interface should say so.
Mitigation changes the network. NetHarrier is designed to keep every automated and manual action inside non-negotiable controls.
Dry-run by default
Monitored-prefix checks
Never-mitigate lists
Per-peer rule caps
Automatic rule TTLs
Complete audit trail
Inside monitored prefix
Peer capacity available
Never-mitigate clear
NetHarrier is being built as open-source infrastructure you can inspect, deploy, and adapt. Commercial help will be there for teams that want it.
Run NetHarrier in your own environment. Read the detection path, verify the controls, and contribute improvements that help operators everywhere.
Inspect how every signal and response is produced.
Add integrations through explicit provider interfaces.
Start as one binary; split roles only when needed.
We will help teams design the deployment, tune detection, integrate routing, and operate NetHarrier with confidence.
Turnkey appliancesComing later
Begin with collection and dry-run detection. Add network-led mitigation when your policies, peers, and team are ready.