BinaryWebEngine bundles WAF, HIDS/NIDS, malware scanning, ML anomaly detection, kill chain reconstruction, and threat intelligence into a single engine with a real-time dashboard, capable of monitoring a single server or scaling across an entire fleet.
A tour of the core BinaryWebEngine interface. Explore the main panels and security engines that power the platform.
A unified command center providing live alerts, kill chain visualization, WAF activity, a MITRE heatmap, and fleet health across all hosts.

186 signatures across 25 attack categories inspect every request inline and block injection, XSS, and abuse before it lands.

Deep analysis and classification of security incidents across hosts. Real-time events map directly to the MITRE ATT&CK framework with complete detail on the triggered rule, threat severity, matching logs, and actionable resolution steps to accelerate incident response.

Integration with global threat intelligence feeds like AbuseIPDB, combined with JA3 TLS fingerprinting, to automatically flag suspicious IPs. The platform also embeds a security AI assistant and a false-positive advisor to help analysts filter noise and understand threat patterns.

Granular tracking of authentication events across system entrypoints (SSH, RDP, Web). Distinguishes successful vs. failed logins, displays authentication activity logs over time, and isolates brute-force attacks or suspicious geo-locations attempting credential stuffing.

Detailed compliance reports, SIEM forwarding, SOAR notifications, and Hub & Spoke fleet management over mTLS for enterprise scale.

Accelerate triage with an integrated LLM security companion that queries fleet telemetry, identifies critical attacks, and performs automated threat investigations.

A conversational chat interface that empowers analysts to query system health, retrieve alert metrics, and determine immediate priorities.

Provides real-time system metrics alongside a breakdown of unresolved, high, and critical alerts with exact resource usage correlation.

Evaluates context to separate noise (e.g. local loopbacks) from genuine external threats, recommending critical paths for manual review.

Flags external threat IPs, checking registries, hosting providers (ASNs), and historical AbuseIPDB report counts to determine reputation.
Deployment details, CLI reference, detection modules, and the complete REST API are all documented in the BinaryWebEngine docs.
Read the Docs →