No rules. No tuning. It just learns.

Your network already knows when something's wrong.

Huginn fingerprints every device, learns what's normal, and alerts when behavior changes. No rules to write, no thresholds to tune. Runs on a $200 mini-PC.

Three steps. Fifteen minutes.

1

Ingest

Point your firewall or gateway at Huginn. One setting, one IP address. Works with any syslog source.

2

Fingerprint

Hyperdimensional vectors identify every device from DHCP, DNS, and traffic patterns. No agents needed.

3

Detect

The prediction-error engine learns what's normal for each device and alerts when behavior shifts.

What makes Huginn different

Behavioral Anomaly Detection

No rules to write, no thresholds to tune. The prediction-error engine learns each device's normal behavior and flags multi-dimensional shifts that single-metric alerts miss.

Device Fingerprinting

Composes MAC OUI, DHCP Option 55, hostnames, DNS patterns, and connection behavior into a single identity vector. "iPhone 15 (94% confidence)" -- not just "Apple device."

Alert Correlation

Spreading activation propagates suspicion across your network graph. When two anomalies converge on the same entity, that's your investigation priority.

Your Way, Your Budget

Pay once and own it forever. No cloud dependency, no phone-home, no per-device fees. MSP pricing available for managed service providers.

Runs Anywhere

Single binary, ~50MB RAM. Runs on a mini-PC, a VM, a Raspberry Pi, or a Docker container. No GPU, no Elasticsearch cluster, no Java.

Broad Integration

First-class CEF parsing for UniFi. Works with any syslog source (RFC 3164/5424) including pfSense, OPNsense, and MikroTik. New parsers added regularly.

Pay once. Own it forever.

Every tier gets the full product. Free forever, or unlock more capacity with a one-time purchase.