The attack stops at the edge. Customer traffic keeps flowing.

EdgeWarden collects flows from your routers, detects DDoS in 10-second cycles and mitigates via BGP FlowSpec, RTBH, XDP filtering or diversion to scrubbing. The same engine optimizes inbound and outbound BGP routing. It runs on your own server, with an interface in Brazilian Portuguese.

7-day demo license with every Enterprise feature unlocked.

Legitimate inbound 0 Outbound traffic Attack dropped 0
Speaks your edge's language
  • NetFlow v5/v9
  • IPFIX
  • sFlow v5
  • SNMP v1/v2c/v3
  • BMP
  • BGP FlowSpec
  • RTBH
  • RPKI
  • GoBGP
  • ExaBGP
  • eBPF/XDP
  • nftables
  • Juniper
  • Huawei
  • MikroTik
  • Cisco
10s

Analysis cycle, from anomaly to BGP announcement

50

Attack vectors decoded, from SYN flood to QUIC amplification

7

Mitigation paths, from FlowSpec to external scrubbing

40+

CDN providers identified automatically

−98.9%

Less carpet-bomb alert noise at a production ISP

46

Endpoints in REST API v1, documented in OpenAPI

collect → detect → decide → mitigate

From flow to filter in four steps

A single Rust engine collects, understands, decides and acts, and logs every decision to ClickHouse for auditing.

01

Collect

NetFlow v5/v9, IPFIX, sFlow v5, SNMP, BMP and packet capture. Every flow is enriched with ASN, GeoIP, rDNS and passive DNS, with no DPI required.

02

Detect

Per-zone thresholds, hour-of-day baselines with z-score, bursts in 100 ms windows, per-prefix carpet bombing, QUIC, spoofing and threat intel.

03

Decide

A deterministic cascade picks the response: local scrubber up to 80% of capacity, external scrubbing, FlowSpec on the vector, or RTBH. The reason is logged.

04

Mitigate and optimize

The BGP announcement goes out within 10 s, the XDP filter acts in the NIC driver and the rule expires on its own. Outside an attack, the engine optimizes cost, latency and capacity.

interface

Your whole network on one screen

Real-time KPIs, mirrored In/Out traffic and network status at a glance. Click any point on the chart to open Point-in-time Analysis (Análise do instante) and see exactly what was flowing in that minute.

Network overview
AS65000 · 4 active exporters
Throughput
14.2Gbps
Flows/second
2,140
Packets/second
1.82Mpps
Active attacks
0
In/Out traffic InboundOutboundAttack
Network status
Network protected
No active attacks
Packet filters12
Violations (24h)15
    Interface in Brazilian Portuguese, light and dark themes My Dashboards (Meus Dashboards): 16 widgets and 4 ready-made templates Executive PDF report
    mitigation

    Seven ways to stop an attack. The engine picks the right one.

    If the attack fits your scrubber, it is diverted and cleaned in the NIC driver. If it doesn't, it goes to your mitigation provider. On a CGNAT address, EdgeWarden drops only the attack vector via FlowSpec instead of taking dozens of subscribers offline with a blackhole.

    1. Divert to your own scrubberUp to 80% of measured capacity, with a health watchdog every 10 s
    2. External scrubbingAnnouncement to your contracted mitigation provider, with anti-hijack safeguards
    3. FlowSpec on the vector onlyDiscard or rate-limit the attack traffic; mandatory for CGNAT
    4. RTBH/32 or /128 blackhole: the last resort, never the first
    Mitigation effectiveness AttackLegitimate traffic
    FlowSpec applied
    detection

    Attacks keep a schedule. EdgeWarden learns yours.

    The dashboard heatmap, in 3D: each bar is one hour of the week. Drag to rotate and hover to see the count. The 14-day hourly profile also suggests the right threshold for each zone.

    Illustrative data · drag to rotate

    50 vectors, four methods

    Per-zone and per-IP thresholds, hour-of-day baselines with z-score, bursts in 100 ms buckets, and custom decoders with BPF/Wanguard syntax.

    IPv4 and IPv6 carpet bombing

    Attacks spread across an entire prefix, aggregated per /24 or /48, with a 7-day profile and botnet heuristics.

    QUIC, DNS and spoofing

    QUIC floods (UDP/443), DGA, water torture and DNS exfiltration, spoofed sources (BCP38), and threat intel from Spamhaus, Team Cymru and AbuseIPDB.

    7,287 → 79

    Less noise, same attacks caught

    Over 11 days and 2.4 billion flows from a customer ISP, the new carpet-bomb detector cut alerts from 7,287 to 79 and still caught the real attacks, from 0.6 to 15 Gbps.

    In another deployment, 56 of 208 violations came from thresholds set below normal traffic. The hourly profile fixes that.

    operational AI

    The AI suggests. The guardrail decides.

    EdgeWarden's AI never makes up a target: it can only pick an option from a list the engine built from measured data. Before any action, a deterministic guardrail checks confidence, cooldown, time window, token budget, whitelist and CGNAT.

    If the AI provider goes down, the system keeps running 100% deterministically. The AI is never in the critical path.

    Claude (Anthropic)OpenAILocal OllamavLLMLM StudioGroqOpenRouter
    Off100% deterministic automation
    ObserveDecides and logs, doesn't apply
    ProposeYou approve each action with a click
    AutomaticApplies within set limits

    Attack Analyst Enterprise New

    The Attack Analyst (Analista de Ataques) classifies each violation as confirmed attack, likely attack, inconclusive or legitimate spike, explains the evidence and computes the narrowest FlowSpec rule that catches the attack.

    BGP traffic decision engine Enterprise New

    Chooses local-pref, community, prepend or blackhole among candidates measured by probes and BMP. The pre-filter skips more than 90% of cycles, and every decision is audited.

    who it's for

    Built for the people who run the edge

    • Regional and fiber ISPs. Stop volumetric attacks before they saturate your transit link, and see where it pays to request a cache or open peering at the IX.
    • Data centers and hosting. Protect each customer with its own zone and policy, filter in the NIC driver with eBPF/XDP, and track the 95th percentile of every link.
    • Transit and resale. Sell DDoS protection as a service, with per-customer policy and portal.
    • Coming from WANGuard? The importer reads IP Zones from .wan and .csv files, and Custom Decoders accept the syntax you already use.
    Example Fiber Customer · AS65010live
    Traffic3.8 Gbps
    Packets412 kpps
    Attacks (7 d)2
    Commit usage (5 Gbps)
    72%SLA Gold
    Refreshes every 30 sPowered by EdgeWarden
    plans

    One binary, three plans

    The installed software is the same on every plan; the license unlocks the features. Start with monitoring and move up to mitigation and traffic engineering without reinstalling anything. Prices in Brazilian reais (BRL).

    Compare plans

    technical questions

    Questions engineers ask before the trial

    Straight answers, including what EdgeWarden doesn’t do. Don’t see yours? Ask us on WhatsApp, or check the plan and licensing questions on the Pricing page.

    Does EdgeWarden sit in the traffic path?No

    No. It reads the flows and sFlow your routers already export and pushes rules back over BGP (FlowSpec or RTBH). Traffic only passes through EdgeWarden hardware if you run your own scrubber, and even then only the diverted IP, only during mitigation; everything else keeps its normal path.

    How long does it take to detect an attack?10 s cycle

    The engine runs a 10-second analysis cycle (configurable down to 1 s), and the burst detector looks at 100 ms windows. The biggest delay usually comes from the exporter: with NetFlow or IPFIX, add the router’s active timeout, typically 15 to 60 s. For sub-second detection, use sFlow or the Packet Sensor.

    Does it protect against layer 7 attacks?Volumetric only

    Partly. Volumetric HTTP and HTTPS floods are detected by rate and by vector, like any other flood. Low-volume application attacks, such as slow requests or login abuse, look like normal traffic in flow data; put a WAF in front of the application for those.

    Do I have to wait through a learning period?No

    No. Per-zone thresholds work from the first minute. The statistical baseline uses a 60-minute window, and as history builds up, the 14-day hourly profile starts suggesting better thresholds for each zone.

    Will it work with my routers?Flow + BGP

    It works with any router that exports NetFlow v5/v9, IPFIX or sFlow and speaks BGP FlowSpec or RTBH. Juniper, Huawei and MikroTik get vendor-specific features (PBR, filter counters and scrubbing templates); Cisco gets SSH terminal access; everything else runs on the standards.

    Does my traffic data leave my network?No

    No. Everything runs on your server: collection, database and dashboard. Only the license talks to the Manager Pro server, with a check every 24 h and a 30-day grace period without contact. AI is optional, receives only the evidence figures, never raw flows, and can run locally with Ollama or vLLM.

    Does it run in a virtual machine?With a caveat

    Collection, analysis and the dashboard, yes. The XDP filter is a different story: at high volume it needs a NIC with native XDP, such as Intel XL710 or Mellanox ConnectX (mlx5). In a VM with vmxnet3 (kernel 6.3 or newer), the filter tops out around 1 to 2 Gbps.

    for current customers

    Already running EdgeWarden?

    Current version , released .

    Every active license gets each new release through the same command, with no reinstall. Historical data stays intact and the web interface is down for only a few seconds.

    Update an existing installation
    # download the stable package
    cd /opt
    curl -fLO https://www.edgewarden.com.br/download/flowspec-analyzer-stable.tar.gz
    
    # apply it: keeps configuration, environment and logs
    /opt/flowspec-analyzer/scripts/update.sh /opt/flowspec-analyzer-stable.tar.gz

    To roll back to the previous version: update.sh --rollback. The full walkthrough is in the installation guide.

    Ready to protect your edge?

    See EdgeWarden in action with data from your own network.