The average manual block takes 15–30 minutes. Rapid Reaktor does it in seconds. Self-hosted, configurable, and auditable down to the source alert that triggered every single block.
Turn firewall events into instant enforcement automatically. No scripts. No delays. No analyst bottlenecks.
Palo Alto Firewall
Attack activity is detected in real time
No dashboards, no waiting, no manual triage
Rapid Reaktor Engine
Extracts attacker IPs instantly
Builds and updates block lists automatically
No scripts. No analyst bottlenecks.
Your Firewall
Firewall enforces blocks automatically
Attackers are stopped before they retry or pivot
Always Active
Every new attack strengthens your defense
Your block lists evolve in real time
No agents. No complex integrations. No humans in the loop.
Rapid Reaktor parses raw syslog and extracts the attacker IP, not whatever address happens to sit first in the line. NAT gateways and reverse proxies bury the real source behind a chain of other addresses, and most tooling either blocks the wrong one or needs a hand-tuned regex per alert type. Rapid Reaktor resolves it correctly out of the box. No per-rule tuning. No manual cleanup.
Rapid Reaktor is the EDL — not a feed that syncs to one, the authoritative blocklist server your firewall already polls. An IP gets added, the firewall picks it up on the next poll. Zero extra config once it's pointed at us. No API keys. No third-party sync to trust or troubleshoot.
Two ports. One docker compose up. Runs on-prem, on hardware you already own — no cloud dependency, no vendor onboarding call, no data leaving your network. Live and blocking within the hour.
Configure exactly what earns a block: alert type, threshold count, regex pattern, source scope. Require three hits before an IP gets added. Scope rules to specific firewall sources. Suppress the noisy alerts that would otherwise trigger false positives. Nothing gets blocked without a rule you wrote.
Every block expires automatically on a schedule you set. Static blocklists only grow — entries pile up, nobody prunes them, and eventually a legitimate user gets locked out by a rule nobody remembers writing. Rapid Reaktor blocks are temporary by default. You decide how long they last.
Rapid Reaktor generates a ready-to-deploy Palo Alto configuration and pushes it to the firewall over SSH. Most integrations mean pointing your firewall at a URL and hoping the object references line up. This is a generated, tested config pushed directly. No manual object creation. No copy-pasting CLI commands.
Running more than one firewall? A live status view shows DAG connectivity and EDL sync health across the whole fleet. One box going stale is easy to miss when you're only watching the one in front of you. Rapid Reaktor shows every firewall at once, so you know exactly which are current and which need attention.
Every automated block is logged: triggering alert, matched rule, IP, timestamp. Nothing is a black box — when someone asks why an IP got blocked, you have the full chain of evidence in seconds, not an afternoon of log spelunking. Export to CSV for incident review or compliance audits.