50 vectors, four methods
Per-zone and per-IP thresholds, hour-of-day baselines with z-score, bursts in 100 ms buckets, and custom decoders with BPF/Wanguard syntax.
EdgeWarden collects flows from your routers, detects DDoS in 10-second cycles and mitigates via BGP FlowSpec, RTBH, XDP filtering or diversion to scrubbing. The same engine optimizes inbound and outbound BGP routing. It runs on your own server, with an interface in Brazilian Portuguese.
7-day demo license with every Enterprise feature unlocked.
Analysis cycle, from anomaly to BGP announcement
Attack vectors decoded, from SYN flood to QUIC amplification
Mitigation paths, from FlowSpec to external scrubbing
CDN providers identified automatically
Less carpet-bomb alert noise at a production ISP
Endpoints in REST API v1, documented in OpenAPI
A single Rust engine collects, understands, decides and acts, and logs every decision to ClickHouse for auditing.
NetFlow v5/v9, IPFIX, sFlow v5, SNMP, BMP and packet capture. Every flow is enriched with ASN, GeoIP, rDNS and passive DNS, with no DPI required.
Per-zone thresholds, hour-of-day baselines with z-score, bursts in 100 ms windows, per-prefix carpet bombing, QUIC, spoofing and threat intel.
A deterministic cascade picks the response: local scrubber up to 80% of capacity, external scrubbing, FlowSpec on the vector, or RTBH. The reason is logged.
The BGP announcement goes out within 10 s, the XDP filter acts in the NIC driver and the rule expires on its own. Outside an attack, the engine optimizes cost, latency and capacity.
Real-time KPIs, mirrored In/Out traffic and network status at a glance. Click any point on the chart to open Point-in-time Analysis (Análise do instante) and see exactly what was flowing in that minute.
If the attack fits your scrubber, it is diverted and cleaned in the NIC driver. If it doesn't, it goes to your mitigation provider. On a CGNAT address, EdgeWarden drops only the attack vector via FlowSpec instead of taking dozens of subscribers offline with a blackhole.
The dashboard heatmap, in 3D: each bar is one hour of the week. Drag to rotate and hover to see the count. The 14-day hourly profile also suggests the right threshold for each zone.
Per-zone and per-IP thresholds, hour-of-day baselines with z-score, bursts in 100 ms buckets, and custom decoders with BPF/Wanguard syntax.
Attacks spread across an entire prefix, aggregated per /24 or /48, with a 7-day profile and botnet heuristics.
QUIC floods (UDP/443), DGA, water torture and DNS exfiltration, spoofed sources (BCP38), and threat intel from Spamhaus, Team Cymru and AbuseIPDB.
Over 11 days and 2.4 billion flows from a customer ISP, the new carpet-bomb detector cut alerts from 7,287 to 79 and still caught the real attacks, from 0.6 to 15 Gbps.
In another deployment, 56 of 208 violations came from thresholds set below normal traffic. The hourly profile fixes that.
EdgeWarden's AI never makes up a target: it can only pick an option from a list the engine built from measured data. Before any action, a deterministic guardrail checks confidence, cooldown, time window, token budget, whitelist and CGNAT.
If the AI provider goes down, the system keeps running 100% deterministically. The AI is never in the critical path.
The Attack Analyst (Analista de Ataques) classifies each violation as confirmed attack, likely attack, inconclusive or legitimate spike, explains the evidence and computes the narrowest FlowSpec rule that catches the attack.
Chooses local-pref, community, prepend or blackhole among candidates measured by probes and BMP. The pre-filter skips more than 90% of cycles, and every decision is audited.
More than 60 screens, from raw flows to the board report. Everything ships in the same binary; the license unlocks the features.
Real-time dashboards, Flow Explorer with Sankey diagrams, a network analyzer that needs no SQL, VRF and DPI. See who talks to whom, and over which path.
More than 40 CDNs identified, which link each one comes in on, and how much is already served by caches inside your network.
FlowSpec, RTBH, XDP filtering in the driver, your own scrubber or an external one. CGNAT is never blackholed and the scrubber never goes past 80%.
Traffic Steering, Route Quality, SLA & Failover, Capacity Planning and Cost Optimization. Every Mbps on the right link, at the lowest cost.
Managed Objects with Bronze to Platinum SLAs, per-customer mitigation policy, and a portal with login or a read-only link, on every plan.
REST API v1 with Swagger, Syslog/SIEM (CEF, JSON, RFC 5424), SNMP traps for Zabbix and PRTG, Telegram, email and webhooks.
The installed software is the same on every plan; the license unlocks the features. Start with monitoring and move up to mitigation and traffic engineering without reinstalling anything. Prices in Brazilian reais (BRL).
Straight answers, including what EdgeWarden doesn’t do. Don’t see yours? Ask us on WhatsApp, or check the plan and licensing questions on the Pricing page.
No. It reads the flows and sFlow your routers already export and pushes rules back over BGP (FlowSpec or RTBH). Traffic only passes through EdgeWarden hardware if you run your own scrubber, and even then only the diverted IP, only during mitigation; everything else keeps its normal path.
The engine runs a 10-second analysis cycle (configurable down to 1 s), and the burst detector looks at 100 ms windows. The biggest delay usually comes from the exporter: with NetFlow or IPFIX, add the router’s active timeout, typically 15 to 60 s. For sub-second detection, use sFlow or the Packet Sensor.
Partly. Volumetric HTTP and HTTPS floods are detected by rate and by vector, like any other flood. Low-volume application attacks, such as slow requests or login abuse, look like normal traffic in flow data; put a WAF in front of the application for those.
No. Per-zone thresholds work from the first minute. The statistical baseline uses a 60-minute window, and as history builds up, the 14-day hourly profile starts suggesting better thresholds for each zone.
It works with any router that exports NetFlow v5/v9, IPFIX or sFlow and speaks BGP FlowSpec or RTBH. Juniper, Huawei and MikroTik get vendor-specific features (PBR, filter counters and scrubbing templates); Cisco gets SSH terminal access; everything else runs on the standards.
No. Everything runs on your server: collection, database and dashboard. Only the license talks to the Manager Pro server, with a check every 24 h and a 30-day grace period without contact. AI is optional, receives only the evidence figures, never raw flows, and can run locally with Ollama or vLLM.
Collection, analysis and the dashboard, yes. The XDP filter is a different story: at high volume it needs a NIC with native XDP, such as Intel XL710 or Mellanox ConnectX (mlx5). In a VM with vmxnet3 (kernel 6.3 or newer), the filter tops out around 1 to 2 Gbps.
Current version , released .
Every active license gets each new release through the same command, with no reinstall. Historical data stays intact and the web interface is down for only a few seconds.
# download the stable package cd /opt curl -fLO https://www.edgewarden.com.br/download/flowspec-analyzer-stable.tar.gz # apply it: keeps configuration, environment and logs /opt/flowspec-analyzer/scripts/update.sh /opt/flowspec-analyzer-stable.tar.gz
To roll back to the previous version: update.sh --rollback. The full walkthrough is in the installation guide.
Support is provided in Portuguese, Monday to Friday, 8 a.m. to 6 p.m. (Brasília time).
See EdgeWarden in action with data from your own network.