Intelligent Securityfor a Changing World

Qyleron builds security technology that helps organizations observe, understand, and respond to adversary behavior.

Meet Echidra

Turn attacker interactions into security intelligence.

Echidra is an open-source deception platform that captures attacker activity across SSH, HTTP, FTP and Telnet, analyzes behavior, maps activity to MITRE ATT&CK, and surfaces recurring security findings.

Echidra Issue Intelligence dashboard showing a detected event, its severity, MITRE ATT&CK technique, session count, and recommended fix

The Problem

Attackers leave behind more than connection logs. Their commands, techniques, credentials, tools and behavior reveal how they operate. But collecting that activity is only the first step. Security teams need to understand what happened, identify recurring behavior, and determine what deserves attention.

Echidra Session Inspector showing a captured attacker session's command timeline, classification, and behavioral evidence
Raw attacker interaction Behavior
Echidra Issue Intelligence dashboard grouping recurring attacker behavior into a severity-ranked issue with a recommended fix
Patterns Security intelligence

Echidra turns interaction into intelligence.

How Echidra Works

One operating model, from decoy to decision.

01
Echidra Personas page listing configured decoy environments across preset device and service types

Deception

Deploy realistic decoy environments across SSH, HTTP, FTP and Telnet. Configure personas and controlled fake environments designed to observe adversary behavior safely.

02
Echidra Sessions page recording captured attacker sessions with source IP, protocol, and actor classification

Capture

Record attacker sessions, commands, requests, authentication attempts and relevant metadata for investigation and analysis.

03
Echidra Intelligence page mapping recurring attacker behavior to MITRE ATT&CK techniques with a severity rating

Intelligence

Classify observed behavior, map activity to MITRE ATT&CK, assess risk, and correlate activity into meaningful findings.

04
Echidra Alert History page showing delivered alert notifications for detected attacker activity

Action

Turn repeated attacker behavior into actionable findings, recommended remediation, and alerts.

Not just more logs.

Find the patterns behind the activity.

Echidra correlates observed behavior across sessions to surface recurring security issues instead of forcing analysts to manually inspect every interaction.

Traditional honeypot Attacker Logs Analyst manually investigates
Echidra Attacker Interaction Analysis Correlation Recurring Issue Recommended Action

Products

Deployable deception products for controlled attacker interaction capture and analysis

Open Source

Echidra OSS

Ready-to-deploy open-source honeypot software for controlled deception environments. Capture attacker behavior across SSH, HTTP, FTP, and Telnet, then review sessions through dashboards.

  • Multi-protocol deception
  • Session capture & behavior analysis
  • MITRE ATT&CK mapping
  • Recurring security findings & recommended actions
Coming next

Echidra X

A future enterprise layer for organizations operating Echidra across larger environments.

  • Centralized deployment
  • Cross-node correlation
  • SIEM/SOAR integrations
  • Operational reporting
  • Enterprise workflows
Roadmap direction — not part of Echidra OSS today.
Request Early Access

Run Echidra yourself.

Echidra is open source and designed to be deployed locally.