It's interesting. I would have expected them to use rather something low latency/high performance like c++ or erlang given their scale and performance criticality.
This is something that only keeps track of user settings data and consequently configures the endpoints given that data.
It has got nothing to do with packet filtering per se.
Any supplementary thoughts on the fact they are running their attack detection in python? What's the point?