Flink SQL streaming detectors (scan detection + session stitching)
467
Flink SQL streaming detectors (scan detection + session stitching).
Part of Cernity — central network detection & response (NDR) analytics for Suricata sensors. Suricata inspects packets at the edge and ships telemetry; Cernity runs the heavy, stateful, Zeek/RITA-style analysis centrally and emits security findings to your SIEM.
Raw network telemetry is analytics input. Security findings are SIEM input.
cernity/flink — Flink SQL streaming detectors (scan detection + session stitching).
See a finding end to end with no live sensor:
docker compose -f deploy/quickstart/docker-compose.yml up
Scales to ~1,000 sensors / ~10 Gbps of edge inspection. Full docs, architecture, and sizing guide: https://github.com/cernity/cernityndr
Source-available under the PolyForm Perimeter License 1.0.1 — use it any way you like, except providing it to others as a competing product. "Cernity" is a trademark of the Cernity Project.
Content type
Image
Digest
sha256:61e5b21f5…
Size
562.6 MB
Last updated
9 days ago
docker pull cernity/flink