SafeNetworking
Enrich Palo Alto Networks firewall logs with advanced threat intelligence from AutoFocus. Correlate DNS queries, IoT threats, and network events with known malware signatures in real-time.
Quick Start
Get SafeNetworking up and running in minutes
Install dependencies
Configure AutoFocus API
.panrc configuration file in the project root with your AutoFocus API key:Run the setup script
Explore SafeNetworking
Discover key features and capabilities
DNS Threat Enrichment
IoT Threat Detection
Architecture Overview
CLI Reference
Key Features
Real-Time Event Processing
Multi-threaded background workers process threat events as they arrive, enriching them with malware intelligence and confidence scores.
Elasticsearch Integration
Store and query enriched threat events using Elasticsearch with pre-configured Kibana dashboards for visualization.
AutoFocus Integration
Leverage Palo Alto Networks’ AutoFocus threat intelligence cloud to identify malware campaigns, actors, and families.
Service Provider Ready
Built for service providers with support for GTP/SCTP logging, multi-tenant deployments, and high-volume event processing.
Ready to secure your network?
Start enriching your firewall logs with threat intelligence from AutoFocus and gain visibility into malicious activity across your network.
Install SafeNetworking