Layer 3/4 stateful packet inspection with eBPF/XDP for line-rate filtering. Rule groups, port knocking, and geo-blocking.
Split-horizon DNS, DoH/DoT upstream, DNSSEC validation, and ad/malware/phishing domain blocking via community feed.
Automatic network discovery and topology mapping. Visual graph of all hosts, services, and connections — always up to date.
Deep packet inspection for protocol anomaly detection, exfiltration monitoring, and bandwidth utilization by application.
Live threat intel feeds (IP reputation, domain blocklists, TOR exit nodes) auto-applied to firewall rules.
Real-time dashboards, configurable alert thresholds, webhook/email notifications, and exportable packet captures.
Single binary or Docker image. Runs on commodity x86/ARM hardware — your existing router, a mini-PC, or a VM.
Passive + active network scanning builds a live topology map within minutes. No agents needed on endpoints.
Web UI or API-driven rule management. Rule groups, scheduling, and automatic threat intel integration.
DPI runs at line rate on your edge. Alerts surface anomalies — not just signature matches. Adaptive baselining.
No hidden fees. No automatic upsell. Cancel any time.
Full 47Sentry stack self-hosted. No usage limits, no telemetry.
Hosted dashboard with threat intelligence feeds and alert management.
Studio engineers deploy and configure 47Sentry on your infrastructure.
Get early access to 47Sentry — or explore the full 47Network ecosystem.
Kernel-level perimeter security that runs on commodity hardware — no appliances, no vendor lock-in.
Law firms, healthcare providers, and financial services with dedicated server infrastructure. 47Sentry runs on bare metal at the network edge, filtering traffic at the kernel level before it reaches application servers — no additional appliances needed.
Self-hosted K8s clusters that need network-level enforcement below the application layer. 47Sentry's XDP programs attach to node NICs, providing per-node traffic filtering and topology mapping without touching cluster networking configuration.
Organisations with multiple offices or hybrid infrastructure that need consistent DNS filtering and local resolution fallback. 47Sentry's DNS resilience layer runs locally at each site, ensuring resolution continues if upstream DNS is unavailable or compromised.
Technical deep-dives on the architecture and decisions behind 47Sentry.
Kernel-level network filtering with no appliance required — how Traffic Sentinel, NetMapper, and DNS resilience work under the hood.
47Sentry ships a Prometheus exporter. This guide covers for-loop patterns, multi-window burn rates, and alert routing that keep fatigue from undermining your security posture.
47Sentry integrates with WireGuard for site-to-site connectivity. This guide covers kernel module setup, key management, and building a multi-site mesh from individual tunnels.
PromQL RED/USE method, Loki log correlation, and alert rules from panels — the observability stack inside 47Sentry.