Qyleron builds security technology that helps organizations observe, understand, and respond to adversary behavior.
Meet Echidra
Echidra is an open-source deception platform that captures attacker activity across SSH, HTTP, FTP and Telnet, analyzes behavior, maps activity to MITRE ATT&CK, and surfaces recurring security findings.
Attackers leave behind more than connection logs. Their commands, techniques, credentials, tools and behavior reveal how they operate. But collecting that activity is only the first step. Security teams need to understand what happened, identify recurring behavior, and determine what deserves attention.
Echidra turns interaction into intelligence.
One operating model, from decoy to decision.
Deploy realistic decoy environments across SSH, HTTP, FTP and Telnet. Configure personas and controlled fake environments designed to observe adversary behavior safely.
Record attacker sessions, commands, requests, authentication attempts and relevant metadata for investigation and analysis.
Classify observed behavior, map activity to MITRE ATT&CK, assess risk, and correlate activity into meaningful findings.
Turn repeated attacker behavior into actionable findings, recommended remediation, and alerts.
Not just more logs.
Echidra correlates observed behavior across sessions to surface recurring security issues instead of forcing analysts to manually inspect every interaction.
Deployable deception products for controlled attacker interaction capture and analysis
Ready-to-deploy open-source honeypot software for controlled deception environments. Capture attacker behavior across SSH, HTTP, FTP, and Telnet, then review sessions through dashboards.
Echidra is open source and designed to be deployed locally.