View the demo

Flow analytics and DDoS defence in one console

Heimnull turns the flow data from your routers into a live view of your network, and stops DDoS attacks by sending FlowSpec rules and blackholes back over BGP.

The Live page: traffic in and out, packets, flows, hosts and attacks as figures with sparklines; a traffic chart with inbound above the line and outbound below; protocols; top hosts, remote ASNs and applications; uplinks, countries and an events feed. A red strip at the top shows a carpet bombing attack in progress. An attack page for a fragment flood on 203.0.113.117: peak 1.98 Gbps, 417 sources, mitigated with FlowSpec. The chart shows traffic before and during the attack and marks when the FlowSpec rule went out. Below: the fingerprint and the FlowSpec rule built from it, top sources, source networks, the mitigation timeline and the triggered limits. Explore, last 5 minutes, broken down by remote AS, with a filter bar and views for top talkers, prefixes, ASNs, flow records, paths, a world map, hour of week and packet sizes. Explore's flow records view: raw records with time, direction, protocol, source, destination, ports, flags, bytes, packets, application, ASNs and exporter.

Live

Your whole network at a glance, every second. Any attack in progress sits in a red strip across the top of every page.

  • Eight figures with sparklines: in, out, packets, flows, identified, hosts, attacks, routes announced
  • Top lists for your hosts, remote ASNs and applications
  • Uplinks against their capacity, in and out
  • Events: attacks, mitigations, BGP and router changes

Running in an afternoon

Heimnull is one container on one Linux server. Nothing changes in your network until you choose to let it announce routes.

  1. Start the server

    One Docker Compose command on Debian 13. The first visit to the web page creates your admin account.

  2. Point your routers at it

    Send NetFlow v9, IPFIX or sFlow v5. Routers show up as soon as they send, and traffic appears on Live within seconds.

  3. Add BGP when you're ready

    One iBGP session per router. Turn on FlowSpec or blackholes one hostgroup at a time, after a dry run.

What else is in there

The tour shows four pages. These are the rest.

Analytics

  • Pages for every host, ASN, prefix and country
  • Applications named from feeds, ASNs, reverse DNS and your rules
  • Interfaces with SNMP, errors and 95th percentile
  • Saved searches and CSV export

Detection

  • Limits per host and hostgroup
  • Flex rules by port, ASN, country or size
  • Carpet bombing across a prefix
  • Baselines learned per hour of the week
  • Outbound attacks from your own hosts

Mitigation

  • FlowSpec: discard, rate-limit, redirect, remark
  • Blackholes with your communities
  • Escalate FlowSpec into blackholes
  • Checks against your networks and whitelist
  • One-click withdraw all

Operations

  • Email and Telegram alerts
  • Roles and API tokens
  • Audit log with before and after
  • Config export and import

Want early access?

If you run your own routers and want to see Heimnull on your own traffic, write to us for early access.

info@heimnull.com