BadSIP Fleet Firewall

BadSIP Fleet Firewall

An attack on one is a defense for all

Phone systems are hammered by automated scanners around the clock, hunting for one weak extension. BadSIP is our fleet-wide firewall: every system we run reports the attackers it blocks, and every other system blocks them too — within about a minute.

How it protects you

Collective defense, global intelligence, and enforcement at the edge — the three principles behind BadSIP.

Herd immunity

The moment one system on our fleet blocks an attacker, every other system blocks it too, within about a minute. The more infrastructure we protect, the faster and stronger each customer’s defense becomes — a network that gets safer as it grows.

Fleet + global intelligence

We merge what our own systems see in real time with curated public threat feeds — honeypots and aggregated blocklists — each address scored by how many independent sources flagged it. Tens of thousands of known-bad addresses and malicious networks, refreshed automatically and expired when they go quiet, so the list never goes stale.

Blocked at the edge

Bad addresses are dropped at the network edge, before a packet ever reaches your phone system. Scanners burn against a wall; your PBX never sees them, never wastes a cycle, never logs a failed login. Your own numbers, carriers, offices, and phones are always allow-listed — legitimate traffic is never touched.

🛡  Runs on both our platforms. BadSIP ships as a native module for the FreePBX Integration Suite and is built into the PBXCore RTE — so every system we run, on either platform, defends the whole fleet and is defended by it.

Part of how we run security

BadSIP is one layer of our security & threat detection practice — the same engineers who run your communications watch the infrastructure underneath them, with a human investigating every real alert.