v2.04.310 — Community Edition available

Free Intrusion Detection System
for OT, IoT, and ICS Networks

Intrufend, a high-performance OT/ICS intrusion detection system. Deep packet inspection of industrial system protocols with Tbps-scale throughput, 165 protocol parsers, passive asset discovery, and anomaly detection. Visibility of threats in industrial systems. Free Community Edition.

Tbps

Throughput

scale with DPDK

3.1s

Startup

8x faster

165

Protocols

OT/ICS + IT + IoT

49K+

Community Rules

Suricata-compatible

The Gbps era is over

Detect threats in Terabits per second of OT/IoT traffic. For free.

Traditional intrusion detection engines were built for Gigabit IT networks. Intrufend is architected from the ground up for Tbps-scale OT, IoT, and ICS detection — linear multi-core scaling, zero-contention architecture, and DPDK zero-copy capture. No per-core licensing. No traffic caps. Free Community Edition.

Quick start

Install on Ubuntu/Debian

sudo dpkg -i intrufend_2.4.310_amd64.deb
sudo intrufend-update-rules
sudo systemctl start intrufend

Capabilities

Built for OT, IoT, and ICS detection

165 Protocol Parsers

Deep packet inspection across 100+ OT/ICS, 25 IT, 15 network infrastructure, and 6 IoT protocols. Purpose-built for OT, IoT, and ICS visibility.

High-Speed Detection

Advanced multi-pattern matching engine delivering 130K+ packets per second per core. Optimized for large rulesets with minimal latency.

Flexible Rule Format

Native YAML rules with field-level matching for every OT protocol. Also fully compatible with Suricata .rules format and 49K+ community rules.

Unified Pipeline

Single processing path for live capture and replay. Integrated flow tracking, TCP reassembly, protocol parsing, detection, and asset discovery.

Tbps-Scale Capture

Zero-copy DPDK capture with linear multi-core scaling. Architected for Terabit-per-second deployments across clustered nodes. Auto-sized buffers ensure zero packet loss.

File Extraction

Automatic extraction and hashing of files transferred over the network. Forensic-ready filenames with timestamps and source information.

Benchmarks

Performance

Same hardware, same rules, same traffic. Full three-way comparison with Suricata and Snort.

MetricIntrufendSuricata 7.0.3
Detection throughput130K+ PPS~71K PPS
Live capture throughput1.6 Gbps~215 Mbps
Startup time3.1s25.7s
Live capture drops0%52.3%
Rule formatsSuricata + YAMLSuricata only
Protocol parsers165 (Rust plugins)~20 built-in

Full comparison with methodology

Editions

Choose your edition

Community

Free

  • 10 protocol parsers (IT + Modbus/DNP3)
  • 49K+ community detection rules
  • Native YAML rule format
  • DPDK + file extraction
  • Free license (EULA)
Download .deb

OEM

Commercial

  • All 165 protocols (100+ OT/ICS + 25 IT + 15 network + 6 IoT)
  • 100+ OT/ICS + all vendor-specific parsers
  • White-label / appliance / MSSP
  • Redistribution rights + commercial support
  • Custom protocol development
Contact Sales

Architecture

Unified packet pipeline

Every packet flows through a single optimized pipeline — the same code path for live capture and forensic replay. No shortcuts, no blind spots.

Flow Tracking

Bidirectional flow association with stateful session management

TCP Reassembly

Full stream reconstruction for accurate protocol analysis

Protocol Parsing

165 Rust-based parsers with deep field extraction

Detection Engine

Multi-pattern matching across all protocol fields

File Extraction

Automatic file carving with cryptographic hashing

TLS Inspection

Certificate validation, version enforcement, fingerprinting

Asset Discovery

Passive device identification and inventory tracking

Alert Output

Real-time JSON, syslog, and PCAP dump of matching traffic