Nythrix โ€” Active Defense Platform

Loading...
Value Delivered (Last 30 Days)
Show framework metrics ▼

Priority Threats

All Observations →

Highest-risk adversary interactions with your deception assets. Click any row to investigate โ€” see the source IP, MITRE technique, risk score, and recommended response.

Loading...

Adversary Sessions

SSH Sessions →

Tracked adversary behavior across your honeypots. Each session groups detections from the same source IP โ€” showing which decoys they touched and how persistent they are.

Loading...

Deception Posture

View Map →

Your deception coverage across the AAA framework. Annoy = waste attacker time, Attribute = identify who's attacking, Act = collect intelligence. Higher bars = more coverage in that pillar.

Loading...

Active Assets by Category

Full Catalog →

Deployed deception assets grouped by type. Click "Full Catalog" to deploy new decoys from 30 templates covering SSH, RDP, SMB, Web, Database, ICS, and more.

Loading...

Deception Sensors

Lightweight detection sensors: honeyports catch port scans, canary files detect document exfiltration, honey credentials detect credential theft.

Loading...

Pre-Auth Connects (24h)

Full View →

TCP-connect scanner traffic captured before any login attempt reaches the honeypot protocol log. The majority of pre-login activity lives here.

Loading...

Infrastructure Mesh

Manage Collectors →

Tailscale mesh health across ADE collector nodes. Green = heartbeat within 2 min, yellow = within 5 min, red = offline.

Loading...
๐ŸŒ
Common Operating Picture
Geographic threat map with real-time attack origins, collectors, and deception assets
โ–ถ
SSH Session Recordings
Watch attacker terminal sessions replayed โ€” see commands, credentials, and files downloaded
๐Ÿ”
Threat Intelligence
APT groups, campaign tracking, IOC enrichment, daily intel digest from 10+ feeds
โšก
SOAR Playbooks
Automated response workflows โ€” block IPs, send alerts, enrich indicators on trigger
๐ŸŽฏ
Hunt Leads
IOCs and IOAs extracted from detections with ready-to-run Splunk and Sigma queries
๐Ÿ“ก
Deploy Collector
Add a new sensor in 60 seconds โ€” one-liner deploys on any Ubuntu VM