Skip to main content

Real-Time Security Event Processing and Detection

Purpose-Built for Streaming Security Data

PADAS is a high-performance streaming platform designed to transform, filter, and detect threats in real time — from any source to any destination. With a schema-on-read approach and a powerful domain-specific language (PDL), PADAS helps security teams normalize events to any target format, run detections directly on the stream, and reduce SIEM overhead before data hits storage.

Any Source, Any Destination

Ingest from various sources (syslog, HTTP, Kafka, files, etc) and fan-out to desired destinations (Splunk, S3, Kafka, syslog, etc.). No single broker required.

SyslogKafkaHTTPS3Splunk
Learn More

Inline Detection and Normalization

Run PDL-based detection and transformation directly on the stream — filter noise, normalize events to any target schema (OCSF, OpenTelemetry, or your own), and emit alerts before data reaches your SIEM or data lake.

PDLSchema-on-ReadMITRE ATT&CK
Learn More

Built for High-Throughput Workloads

PADAS is designed for the sustained event rates common in security telemetry. Throughput scales with pipeline complexity and hardware — from simple routing to windowed aggregation over high-cardinality fields.

Stream ProcessingWALREST API
Learn More

See PADAS in Action

Get a quick overview of how PADAS transforms security event data and detects threats in real-time.

HowPADASWorks

Connectors, streams, and PDL tasks compose pipelines

from any source to any destination.


  1. Core Capabilities

    1. Key Features & Benefits
      1. Stream-Native Processing

        Filter, transform, enrich, and aggregate every event inline, with no separate query engine.

      2. Inline Detection

        Run PDL detection on the normalized stream and alert before data reaches storage.

      3. Schema-on-Read Normalization

        Map vendor fields to OCSF, OpenTelemetry, or your own schema, with no rigid ingest contract.

      4. Reduced SIEM Load

        Dedupe and route only what matters, cutting SIEM ingest, storage, and analyst noise.

    2. Integration & Flexibility
      1. Broad Connector Coverage

        Sources and sinks for Syslog, Kafka, HTTP, files, Splunk HEC, and S3-compatible storage.

      2. Multi-Sink Fan-Out

        One stream, many sinks: alert your SIEM and archive raw events in parallel.

      3. Vendor-Agnostic Delivery

        Ship to Splunk, Elastic, Kafka, S3, or any HTTP target via open formats.

    3. Future-Proofing & Adaptability
      1. Purpose-Built PDL

        Filtering, regex/grok, lookups, windowed aggregation, and routing, versioned independently.

      2. REST API Control Plane

        Manage streams, tasks, and connectors with Prometheus metrics for full operational visibility.

      3. Extensible Context & Search

        Optional lookup service today; entity, threat-intel, and search services on the roadmap.

    4. Professional Support & Services
      1. Technical Support

        Production support for PADAS Core and UI, covering tuning, PDL debugging, and upgrade advisories.

      2. Professional Services

        Architecture, deployment, and operations consulting for production-ready clusters.

Built for Security Practitioners, by Security Engineers

Our Vision

To redefine how security teams work with data—making real-time, intelligent analytics accessible across any streaming platform. We envision a future where AI-enhanced detection transforms security from reactive defense to proactive insight, with simplicity and performance at its core.

Real-Time Processing
Advanced Analytics

Frequently Asked Questions