View the demo

Flow analytics and DDoS defence in one console

Heimnull turns the flow data from your routers into a live view of your network, and stops DDoS attacks on IPv4 and IPv6 by sending FlowSpec rules and blackholes back over BGP.

The Live page: traffic in and out, packets, flows, hosts and attacks as figures with sparklines; a traffic chart with inbound above the line and outbound below; protocols; top hosts, remote ASNs and applications; uplinks, countries and an events feed. A red strip at the top shows a carpet bombing attack in progress. An attack page for a fragment flood on 203.0.113.117: peak 1.98 Gbps, 417 sources, mitigated with FlowSpec. The chart shows traffic before and during the attack and marks when the FlowSpec rule went out. Below: the fingerprint and the FlowSpec rule built from it, top sources, source networks, the mitigation timeline and the triggered limits. Explore, last 5 minutes, broken down by remote AS, with a filter bar and views for top talkers, prefixes, ASNs, flow records, paths, a world map, hour of week and packet sizes. Explore's flow records view: raw records with time, direction, protocol, source, destination, ports, flags, bytes, packets, application, ASNs and exporter.

Live

Your whole network at a glance, every second. Any attack in progress sits in a red strip across the top of every page.

  • Eight figures with sparklines: in, out, packets, flows, identified, hosts, attacks, routes announced
  • Top lists for your hosts, remote ASNs and applications
  • Uplinks against their capacity, in and out
  • Events: attacks, mitigations, BGP and router changes

IPv4 and IPv6, all the way through

Plenty of flow and DDoS tools still leave IPv6 out, or only half support it. Heimnull treats both address families the same, from the first flow record to the route it announces.

Collection

NetFlow v9, IPFIX and sFlow v5 records for both, from the same routers and the same export.

Analytics

IPv6 hosts and prefixes get the same top lists, pages and flow records as IPv4, and Live shows your IPv6 share.

Detection

Attacks on IPv6 hosts and prefixes are caught like any other. The carpet bombing in the tour is aimed at an IPv6 /48.

Mitigation

FlowSpec rules and blackholes for both address families, announced to your routers over BGP.

Running in an afternoon

Heimnull is one container on one Linux server. Nothing changes in your network until you choose to let it announce routes.

  1. Start the server

    One Docker Compose command on Debian 13. The first visit to the web page creates your admin account.

  2. Point your routers at it

    Send NetFlow v9, IPFIX or sFlow v5. Routers show up as soon as they send, and traffic appears on Live within seconds.

  3. Add BGP when you're ready

    One iBGP session per router. Turn on FlowSpec or blackholes one hostgroup at a time, after a dry run.

What else is in there

The tour shows four pages. These are the rest.

Analytics

  • Pages for every host, ASN, prefix and country
  • Applications named from feeds, ASNs, reverse DNS and your rules
  • Interfaces with SNMP, errors and 95th percentile
  • Saved searches and CSV export

Detection

  • Limits per host and hostgroup
  • Flex rules by port, ASN, country or size
  • Carpet bombing across a prefix
  • Baselines learned per hour of the week
  • Outbound attacks from your own hosts

Mitigation

  • FlowSpec: discard, rate-limit, redirect, remark
  • Blackholes with your communities
  • Escalate FlowSpec into blackholes
  • Checks against your networks and whitelist
  • One-click withdraw all

Operations

  • Email and Telegram alerts
  • Roles and API tokens
  • Audit log with before and after
  • Config export and import

Want early access?

If you run your own routers and want to see Heimnull on your own traffic, write to us for early access.

info@heimnull.com