PADAS is a high-performance streaming platform designed to transform, filter, and detect threats in real time — from any source to any destination. With a schema-on-read approach and a powerful domain-specific language (PDL), PADAS helps security teams normalize events to any target format, run detections directly on the stream, and reduce SIEM overhead before data hits storage.
Ingest from various sources (syslog, HTTP, Kafka, files, etc) and fan-out to desired destinations (Splunk, S3, Kafka, syslog, etc.). No single broker required.
Run PDL-based detection and transformation directly on the stream — filter noise, normalize events to any target schema (OCSF, OpenTelemetry, or your own), and emit alerts before data reaches your SIEM or data lake.
PADAS is designed for the sustained event rates common in security telemetry. Throughput scales with pipeline complexity and hardware — from simple routing to windowed aggregation over high-cardinality fields.
Get a quick overview of how PADAS transforms security event data and detects threats in real-time.
Connectors, streams, and PDL tasks compose pipelines
from any source to any destination.
Filter, transform, enrich, and aggregate every event inline, with no separate query engine.
Run PDL detection on the normalized stream and alert before data reaches storage.
Map vendor fields to OCSF, OpenTelemetry, or your own schema, with no rigid ingest contract.
Dedupe and route only what matters, cutting SIEM ingest, storage, and analyst noise.
Sources and sinks for Syslog, Kafka, HTTP, files, Splunk HEC, and S3-compatible storage.
One stream, many sinks: alert your SIEM and archive raw events in parallel.
Ship to Splunk, Elastic, Kafka, S3, or any HTTP target via open formats.
Filtering, regex/grok, lookups, windowed aggregation, and routing, versioned independently.
Manage streams, tasks, and connectors with Prometheus metrics for full operational visibility.
Optional lookup service today; entity, threat-intel, and search services on the roadmap.
Production support for PADAS Core and UI, covering tuning, PDL debugging, and upgrade advisories.
Architecture, deployment, and operations consulting for production-ready clusters.
To redefine how security teams work with data—making real-time, intelligent analytics accessible across any streaming platform. We envision a future where AI-enhanced detection transforms security from reactive defense to proactive insight, with simplicity and performance at its core.