The Core Hadron Firehose contract.
Every record arrives with the same field set. Names are stable. Types are stable. Build matchers and projections against this list — not against vendor-specific log shapes.
Identity & Probe Context
Where the signal originated.
Transport & Flow Metrics
Layer-3/4 counters and flow state.
Addressing & Assets
IPs, CIDRs, and asset names.
Geographic Enrichment
Country, city, and lat/lon for both ends.
Protocol, Risk & Classification
nDPI categories and normalized risk.
Domain & Host
Raw and normalized hostnames.
HTTP
Observed application-layer detail.
TLS
Versions, ciphers, certs, and JA fingerprints.
DNS
Query and response detail.
Cumulative Counters & Pair Metrics
Running totals per side and pair.
Global TIP Summary
Threat-intel match summary across enrichers.
Source IP TIP Enrichment
Per-source threat enrichment.
Destination IP TIP Enrichment
Per-destination threat enrichment.
Domain TIP Enrichment
Domain-level threat enrichment.
JA4 TIP Enrichment
JA4 fingerprint threat enrichment.
Analytic Flags & ASN
Heuristic flags, ASN, ISP context.
UI Counters & Rendering
Counters useful for live dashboards.
Built a useful projection?
Most teams use 30–60 fields per app. Send us yours — we publish notable projections in the showcase.