FlowFor network operators · Enterprise plans

See the attack in your traffic
before your customers
feel it.

Obiguard Flow reads the NetFlow, IPFIX or sFlow your routers already export, finds DDoS and other abnormal traffic, and turns every incident into an approved, tracked remediation plan. When the answer is to blackhole a target, Flow announces it to your routers over BGP, under your guardrails.

Request a demo →See what it does ↓
Closed demo and proof of concept on request.
Flow formats
NetFlow v5/v9 · IPFIX · sFlow
Mitigation
BGP blackhole (RTBH)
Approvals
Every step, audit logged
Availability
Enterprise plans

Works with routers and switches that export NetFlow, IPFIX or sFlow. Nothing is installed on your routers, and no traffic passes through Flow.

Cisco
Juniper
Huawei
Arista
MikroTik
Ubiquiti
VyOS

Support depends on your device model and licence. Ask us to confirm yours.

01 / Features

Detect it.
Decide it. Block it. Prove it.

📡

Detection

  • Collects NetFlow v5/v9, IPFIX and sFlow
  • Per-destination traffic baselines
  • Detectors for volumetric attacks, SYN floods, amplification, scans, data exfiltration and beaconing
  • Protected objects: the networks and addresses you care about, each on its own baseline
  • A known-services library that tells normal busy services from attacks, kept up to date with signed updates
🔎

Investigation

  • Incidents with a traffic signature: top sources, ports, protocols and packet sizes
  • Traffic explorer and ASN roll-up
  • Incident reports you can hand to a customer or a regulator
✅

Remediation plans

  • A plan on every incident, built from a playbook for its attack type
  • A recommended mitigation per attack type: blackhole, FlowSpec rule, or alert only
  • Drafted router rules and upstream-provider requests, ready to copy and apply
  • Approvals for any step that changes your network, with assignment and a queue of open steps
  • A gate that stops an incident being closed while steps are still open
  • Verification evidence: is the attack still visible, and how does traffic compare with baseline. A person always confirms.
🛑

BGP blackholing (RTBH)

  • Announce and withdraw a blackhole for a single address from the incident, after approval
  • Guardrails: only prefixes inside your declared networks, shortest allowed prefix, a limit on concurrent blackholes and addresses that must never be blackholed
  • A time limit on every block, withdrawn automatically, plus manual withdraw
  • A kill switch that withdraws everything
  • Router setup snippets for common edge routers
  • Optional auto mode for the attack types and minimum severity you choose. Off by default.
🔔

Operations

  • Acknowledge, assign and escalate alerts
  • Notifications to Slack, Teams, Google Chat, email, PagerDuty and webhooks, chosen per event type
  • Maintenance windows, so planned work does not page anyone
  • An audit log of every approval, change and announcement
🤝

Scrubbing partners

  • Flow is the detection and orchestration layer. For attacks too large to blackhole, pair it with your scrubbing provider or your ISP's clean-pipe service
  • The remediation plan drafts the diversion request to your provider and tracks it to completion
02 / How it works

From flow records to a closed incident.

1

Point your routers at Flow

Export NetFlow, IPFIX or sFlow to your Flow collector. No agent on the router and no inline hop.

2

Declare what to protect

Add your networks and the addresses that matter. Flow learns a baseline for each.

3

Detect and plan

When traffic departs from baseline, Flow opens an incident and drafts the remediation plan for that attack type.

4

Approve and mitigate

An approver signs off. Flow announces the blackhole to your routers within your guardrails, then withdraws it when the time limit ends.

03 / FAQ

Common questions.

Enterprise plans

See Flow on your own traffic.

Request a closed demo, or a read-only proof of concept on your flow exports. Tell us which routers you run and which flow format they export.