Your network already knows when something's wrong.
Huginn fingerprints every device, learns what's normal, and alerts when behavior changes. No rules to write, no thresholds to tune. Runs on a $200 mini-PC.
Three steps. Fifteen minutes.
Ingest
Point your firewall or gateway at Huginn. One setting, one IP address. Works with any syslog source.
Fingerprint
Hyperdimensional vectors identify every device from DHCP, DNS, and traffic patterns. No agents needed.
Detect
The prediction-error engine learns what's normal for each device and alerts when behavior shifts.
What makes Huginn different
Behavioral Anomaly Detection
No rules to write, no thresholds to tune. The prediction-error engine learns each device's normal behavior and flags multi-dimensional shifts that single-metric alerts miss.
Device Fingerprinting
Composes MAC OUI, DHCP Option 55, hostnames, DNS patterns, and connection behavior into a single identity vector. "iPhone 15 (94% confidence)" -- not just "Apple device."
Alert Correlation
Spreading activation propagates suspicion across your network graph. When two anomalies converge on the same entity, that's your investigation priority.
Your Way, Your Budget
Pay once and own it forever. No cloud dependency, no phone-home, no per-device fees. MSP pricing available for managed service providers.
Runs Anywhere
Single binary, ~50MB RAM. Runs on a mini-PC, a VM, a Raspberry Pi, or a Docker container. No GPU, no Elasticsearch cluster, no Java.
Broad Integration
First-class CEF parsing for UniFi. Works with any syslog source (RFC 3164/5424) including pfSense, OPNsense, and MikroTik. New parsers added regularly.
Pay once. Own it forever.
Every tier gets the full product. Free forever, or unlock more capacity with a one-time purchase.