Replay the encounter
Inspect captured SSH and Telnet commands, review session timelines, and replay available terminal recordings. Follow the sequence from initial access through reconnaissance and attempted downloads.
Defensive Security · Greek-Fire Corporation
Turn attacker activity into evidence you can use.
Honey Aegis is a self-hosted deception and threat intelligence platform. Dedicated decoy services capture how intruders connect, which credentials they try, and what they do next. Session replay, local AI analysis, and a shared dashboard help your team turn those interactions into an investigation.
A connection attempt is a starting point. Honey Aegis brings the commands, timeline, source context, and observed behavior together, giving analysts the evidence to understand an encounter and explain it to someone else.
Inspect captured SSH and Telnet commands, review session timelines, and replay available terminal recordings. Follow the sequence from initial access through reconnaissance and attempted downloads.
Ollama-powered summaries bring together observed behavior, suggested threat levels, and MITRE ATT&CK technique mappings. Analysts can check that interpretation against the underlying session evidence.
Collect events from multiple sensors in one console. Sensor health, live activity, maps, and trends help teams compare what different locations are seeing.
Export session or aggregate reports as PDF and JSON. Bring the timeline, captured commands, and AI summary into a review, a client conversation, or a training exercise.
Configurable alerts, webhooks, and optional threat intelligence integrations help move findings into your existing security process. Local AI and external enrichment remain distinct configuration choices.
Tenant-scoped access and reporting support managed service workflows. The platform also provides a plugin foundation for extending integrations as requirements grow.
Deploy dedicated decoys on isolated servers, virtual machines, or Raspberry Pi devices. Keep the central analysis hub on a protected management network.
Review an unusual session, inspect its commands, and compare the local AI summary with what was captured. Check related activity across the fleet.
Share a report, refine an alert, or use the replay in a defensive training session. Keep the evidence available for the next investigation.
Use Honey Aegis to observe exposed decoys, investigate recurring behavior, prepare client reports, or teach analysts with captured sessions. Its Docker-based architecture separates sensors from the analysis hub. Multi-tenant access is enforced at the application layer; deployments needing stronger separation use a dedicated hub per tenant.
Greek-Fire Corporation is developing the commercial release. Pricing, packaging, and release availability are still being finalized. Core platform support and community plugin support have separate scopes.
Talk with us about evaluation, deployment needs, and updates on the commercial release.
Book a conversationHoney Aegis brings observed security activity into the wider portfolio. Explore the ecosystem, its shared service infrastructure, and our research platform.
Select a track
Ambient Soundscapes
Premium ambient soundscapes
Voice settings, reading positions, bookmarks — everything stays in sync. No password.
Auto-syncing on every change.
Your email is hashed before it leaves the page. We never store the address.