Everything your network is doing. Visible in minutes.
ISP
Regional data service providers are the backbone of every region.
IX Peering
Every country depends on efficiently functioning backbone networks and peering nodes.
Datacenter
Data centers and content providers are the fabric of our digital civilization.
Built for your environment
Every network architecture has specific visibility needs. FLOWCUTTER delivers the right depth of traffic analysis for your environment — without forcing you to adapt to a generic platform.
For ISP
When traffic changes, know what happened in minutes.
Troubleshoot issues faster, investigate DDoS-related behavior, and respond with evidence when customers are affected.

Deep NetFlow Traffic Diagnostics

Automated Anomaly & DDoS Detection

Outbound Malware & Abuse Detection

Vulnerability Scan

Regulatory Data Retention

Software-Based Flow Probe

Multi-Tenant Customer Separation

SNMP & Network Telemetry Integration

NIS2 & Audit Readiness

For IX Peering
See more than port activity.
Port statistics show activity. FLOWCUTTER reveals what is actually moving across the fabric — and where unusual traffic behavior begins.

L2 & East-West Traffic Visibility

Automated Anomaly & DDoS Detection

Tenant Flow Monitoring

Partner Traffic Diagnostics

Multi-Tenant Visibility Isolation

Infrastructure Vulnerability Scan

SNMP & Fabric Telemetry Integration

NIS2 & Audit Readiness

For Data centers
Investigate internal traffic issues with more clarity.
When unusual behavior starts inside the environment — FLOWCUTTER helps identify where it began and what changed.

Inbound Traffic Analysis

Automated Anomaly & DDoS Detection

Tenant-to-Tenant Flow Monitoring

East-West Workload Visibility

Multi-Tenant Traffic Isolation

Infrastructure Vulnerability Scan

SNMP-Based Capacity Monitoring

Incident Forensic Flow History

NIS2 & Audit Readiness

From alert to answer.
4 minutes

real cases. real networks.
What network teams solved with FLOWCUTTER
Platform capabilities

Deep NetFlow diagnostics
Flow-based troubleshooting can reveal much more in comparison to traditional approach based on SNMP-like data. Flow data such as NetFlow, IPFIX, sFlow provide insight into user-application interactions.
FLOWCUTTER allows both external and internal attacks detection - incoming volumetric DDoS attack, network scanning, brute force attacks, or outgoing reflexive attack, when a host joins a botnet.
In combination with additional data sources (SNMP, synthetic scans, syslogs, IP reputation, and threat intel) it can help reveal root cause of many anomalies, attack, misconfiguration.

Automated anomaly detection
FLOWCUTTER provides pre-defined templates for flow-based detection of network anomalies, for example:
- incoming volumetric DDoS attacks (SYN, SYN ACK, iCMP, DNS, NTP, ICMP floods etc.)
- outgoing reflexive attacks, e.g. via open DNS ports
- volumetric change of intra-network behaviour such as scanning, brute force attacks and anomalies on service ports (telnet, ssh, snmp, smtp, etc.)

Vulnerability scan
FLOWCUTTER enables continuous validation of network configuration and security exposure across defined IP ranges.
- Open Ports Scan (v1.0) identifies exposed services, applications, and newly appearing devices.
- Vulnerability Scan (v1.1) detects service versions and associated CVEs with automatic severity classification.
- Extended scanning (v1.5) supports multiple scan instances and configurable scan depth and aggressiveness.
All findings are presented in a clear, auditable overview for prioritization, remediation, and compliance.

Multi-tenant
Multitenant nature of Collector allows root organisation to provide for their selected customers:
Network Visibility & Security as a service. Enables MSSP (Managed Security Service Providers) to offer most of what FC offers to their customers in a read-only user-friendly interactive and safe environment to their key customers as a service. It is created and orchestrated automatically with a few clicks.

Key front-end components
- Data Sources: Grafana integrates with multiple monitoring systems.
- Query Engine: Allows users to write and customize queries to filter and manipulate data for precise insights to match their specific needs.
- Visualization & Dashboards: Supports various visualization types like graphs, tables, heatmaps, and alerts for real-time monitoring.
- Alerting System: Users can set up alerts with custom thresholds, sending notifications via email, Slack, Webhook, and other integrations.

Fastest backend
FLOWCUTTER’s Data Source is proprietary backend that allows fast adhoc queries on large flow dataset.
Why fast ad-hoc queries?
No one can predict tomorrow’s network issues. Technicians and administrators never know in advance what problems they’ll need to investigate or where they’ll arise. That’s why fast ad-hoc query response is crucial for any analyst.

FLOWCUTTER Probe
- Captures and pre-filters raw network traffic, reducing noise by focusing on key indicators, and optimizing storage efficiency (in comparison to pcap-based solutions).
○ Supports flow export in IPFIX format.
○ Supports both TCP and UDP
- Operates passively via SPAN, TAP without affecting network traffic.
○ Transparent at L2/L3 layers with zero impact on infrastructure.
- L2-L4: Captures standard NetFlow/IPFIX fields (IP, port, protocol) along with other optional identifiers for mac addresses, VLAN visibility, and ASN analysis.
○ v2.5: Optionally decapsulates VxLAN and MPLS to expose real user interactions.
○ Note: Probe does not support L7 visibility or Deep Packet Inspection (DPI).
Get in touch
Try FLOWCUTTER in your own network
Engineering team responds within 24 hours. NDA available on request | Direct technical contact: info@flowcutter.net




