Skip to content
All ventures

Defensive Security · Greek-Fire Corporation

Honey Aegis

Turn attacker activity into evidence you can use.

Honey Aegis is a self-hosted deception and threat intelligence platform. Dedicated decoy services capture how intruders connect, which credentials they try, and what they do next. Session replay, local AI analysis, and a shared dashboard help your team turn those interactions into an investigation.

Discuss Honey Aegis Commercial release in development

Understand the behavior behind the alert

A connection attempt is a starting point. Honey Aegis brings the commands, timeline, source context, and observed behavior together, giving analysts the evidence to understand an encounter and explain it to someone else.

Replay the encounter

Inspect captured SSH and Telnet commands, review session timelines, and replay available terminal recordings. Follow the sequence from initial access through reconnaissance and attempted downloads.

Add local AI context

Ollama-powered summaries bring together observed behavior, suggested threat levels, and MITRE ATT&CK technique mappings. Analysts can check that interpretation against the underlying session evidence.

See the whole fleet

Collect events from multiple sensors in one console. Sensor health, live activity, maps, and trends help teams compare what different locations are seeing.

Share useful evidence

Export session or aggregate reports as PDF and JSON. Bring the timeline, captured commands, and AI summary into a review, a client conversation, or a training exercise.

Connect your workflow

Configurable alerts, webhooks, and optional threat intelligence integrations help move findings into your existing security process. Local AI and external enrichment remain distinct configuration choices.

Support different teams

Tenant-scoped access and reporting support managed service workflows. The platform also provides a plugin foundation for extending integrations as requirements grow.

From a decoy interaction to a defensible next step

  1. Place the sensors

    Deploy dedicated decoys on isolated servers, virtual machines, or Raspberry Pi devices. Keep the central analysis hub on a protected management network.

  2. Investigate the sequence

    Review an unusual session, inspect its commands, and compare the local AI summary with what was captured. Check related activity across the fleet.

  3. Put the finding to work

    Share a report, refine an alert, or use the replay in a defensive training session. Keep the evidence available for the next investigation.

For security teams, service providers, and serious labs

Use Honey Aegis to observe exposed decoys, investigate recurring behavior, prepare client reports, or teach analysts with captured sessions. Its Docker-based architecture separates sensors from the analysis hub. Multi-tenant access is enforced at the application layer; deployments needing stronger separation use a dedicated hub per tenant.

Greek-Fire Corporation is developing the commercial release. Pricing, packaging, and release availability are still being finalized. Core platform support and community plugin support have separate scopes.

Discuss your security use case.

Talk with us about evaluation, deployment needs, and updates on the commercial release.

Book a conversation

Honey Aegis brings observed security activity into the wider portfolio. Explore the ecosystem, its shared service infrastructure, and our research platform.