RAPID REAKTOR
System Status: Active Defense

Your Firewall Should Block Attackers Automatically. Now It Can.

The average manual block takes 15–30 minutes. Rapid Reaktor does it in seconds. Self-hosted, configurable, and auditable down to the source alert that triggered every single block.

monitor_heart Recent Activity
+ added 45.76.112.34 → ssh-blocklist 2s ago
+ added 91.134.22.187 → brute-force 5s ago
+ added 185.220.101.53 → vpn-threats 12s ago
+ added 77.88.55.241 → ssh-blocklist 28s ago
+ added 162.55.18.247 → brute-force 45s ago
+ added 51.89.153.112 → ssh-blocklist 1m ago
Total Rules
23
Active Rules
18
Total Actions
1,847
Actions (24h)
92

From Detection to Block in Seconds

Turn firewall events into instant enforcement automatically. No scripts. No delays. No analyst bottlenecks.

warning

Detection

Palo Alto Firewall

Attack activity is detected in real time
No dashboards, no waiting, no manual triage

bolt

Automated Response

Rapid Reaktor Engine

Extracts attacker IPs instantly
Builds and updates block lists automatically
No scripts. No analyst bottlenecks.

shield

Instant Blocking

Your Firewall

Firewall enforces blocks automatically
Attackers are stopped before they retry or pivot

autorenew

Continuous Defense

Always Active

Every new attack strengthens your defense
Your block lists evolve in real time

How It Works

No agents. No complex integrations. No humans in the loop.

Auto-Extract IPs

Rapid Reaktor parses raw syslog and extracts the attacker IP, not whatever address happens to sit first in the line. NAT gateways and reverse proxies bury the real source behind a chain of other addresses, and most tooling either blocks the wrong one or needs a hand-tuned regex per alert type. Rapid Reaktor resolves it correctly out of the box. No per-rule tuning. No manual cleanup.

Dynamic EDL Management

Rapid Reaktor is the EDL — not a feed that syncs to one, the authoritative blocklist server your firewall already polls. An IP gets added, the firewall picks it up on the next poll. Zero extra config once it's pointed at us. No API keys. No third-party sync to trust or troubleshoot.

Docker Deployable

Two ports. One docker compose up. Runs on-prem, on hardware you already own — no cloud dependency, no vendor onboarding call, no data leaving your network. Live and blocking within the hour.

Granular Trigger Logic

Configure exactly what earns a block: alert type, threshold count, regex pattern, source scope. Require three hits before an IP gets added. Scope rules to specific firewall sources. Suppress the noisy alerts that would otherwise trigger false positives. Nothing gets blocked without a rule you wrote.

Smart TTL Management

Every block expires automatically on a schedule you set. Static blocklists only grow — entries pile up, nobody prunes them, and eventually a legitimate user gets locked out by a rule nobody remembers writing. Rapid Reaktor blocks are temporary by default. You decide how long they last.

One-Click Firewall Config

Rapid Reaktor generates a ready-to-deploy Palo Alto configuration and pushes it to the firewall over SSH. Most integrations mean pointing your firewall at a URL and hoping the object references line up. This is a generated, tested config pushed directly. No manual object creation. No copy-pasting CLI commands.

Fleet-Wide Visibility

Running more than one firewall? A live status view shows DAG connectivity and EDL sync health across the whole fleet. One box going stale is easy to miss when you're only watching the one in front of you. Rapid Reaktor shows every firewall at once, so you know exactly which are current and which need attention.

Audit & Compliance Logging

Every automated block is logged: triggering alert, matched rule, IP, timestamp. Nothing is a black box — when someone asks why an IP got blocked, you have the full chain of evidence in seconds, not an afternoon of log spelunking. Export to CSV for incident review or compliance audits.

View the Audit Log Schema →