ELLIO Technology
ELLIO Technology operates a global honeypot-driven cyber deception network that delivers first-party threat intelligence and automated blocklist solutions targeting reconnaissance and mass exploitation, serving SOC teams, small IT teams, telcos, and enterprise security organizations.
- Company typePrivate
- Founded2022
- HeadquartersPrague, Czechia
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What ELLIO Technology does
ELLIO Technology s.r.o. is a Prague-based cybersecurity research lab founded in 2022 that operates a global cyber deception network of honeypots and sensors to collect first-party threat intelligence on internet reconnaissance and mass exploitation activity. The company packages this intelligence into the ELLIO Platform, comprising Threat Intelligence feeds, Blocklist Automation, IP Blocklists, Recon IP Lists, an rDNS dataset of approximately 1.25 billion PTR records, and a Fingerprint Firewall that unifies industry-standard JA3/JA4 with ELLIO's proprietary MuonFP fingerprinting. Complementary free tools (IP Lookup, My Fingerprints, research datasets) support a product-led growth motion, while enterprise direct sales and a partner referral program address SOC teams, small IT teams, telcos/ISPs, and large enterprise security buyers.
Revenue is generated through subscription-based platform access, usage-based API licensing, custom enterprise orders, and partner referral fees, with pricing not publicly disclosed. The company is privately held and founder-owned by Vlad Iliushin and Jana Tom, with a team of 1-10 employees and a single disclosed early-stage investment from Presto Ventures (March 2023). ELLIO pursues active ecosystem development through open-source releases such as Recon Shield (an eBPF-based TCP fingerprint firewall), CTF sponsorships, and speaking presence at major industry conferences including Black Hat USA, RSA, BSides events, and it-sa.
ELLIO Technology firmographics
Firmographics- Name
- ELLIO Technology
- Legal name
- ELLIO Technology s.r.o.
- Website
- https://ellio.tech
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- ELLIO Technology operates a global honeypot-driven cyber deception network that delivers first-party threat intelligence and automated blocklist solutions targeting reconnaissance and mass exploitation, serving SOC teams, small IT teams, telcos, and enterprise security organizations.
- Ownership category
- akta.pro rank
ELLIO Technology industry classification
Industry- Product category
- Threat Intelligence Platform
- NAICS
- Computer Systems Design and Related Services (54151)
- akta.pro primary industry
- Deception Technology & Threat Hunting (HDADAGAI)
- akta.pro secondary industries
- Deception & Honeypot-Based Network Defense (HDADABAN), Threat Intelligence Services (BPAEADAC)
Keywords
Where ELLIO Technology is headquartered
LocationHeadquarters
- HQ city
- Prague
- HQ country
- Czechia
- HQ region
- Europe
Offices1 record
Markets served
ELLIO Technology business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Infrastructure, Personnel, Marketing or Sales, Operations
Revenue model
- Threat Intelligence Platform Subscription: Subscription-based access to the ELLIO threat intelligence platform providing real-time threat data, IP blocklists, and automated blocklist management. Subscriptions auto-renew and require 30-day notice for cancellation.
- API License Access: Programmatic access to ELLIO Data via API keys, limited to subscribed API types and credit/usage quotas. API access requires separate licensing from platform access.
- Enterprise Custom Orders: Custom order forms and quotes for enterprise customers with specific scope, term, and fee arrangements. Includes optional SLA and support agreements.
- Partner Lead Fees: ELLIO operates a partner referral program where partners earn fees for validated leads that result in signed contracts. Fee amounts are agreed in writing between ELLIO and the partner.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free trial access to ELLIO Platform |
| Freemium | Pay-as-you-go | Free IP Lookup tool |
| Freemium | Pay-as-you-go | Free Datasets for Research |
| Subscription | Annual | Paid Platform Subscription |
| Usage-based | Monthly | API License |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels8 records
ELLIO Technology product offering
Product offeringCore offering
ELLIO operates a global cyber deception network of honeypots to collect first-party threat intelligence on mass exploitation and network reconnaissance activity, then delivers it through the ELLIO Platform—a unified threat intelligence and blocklist automation SaaS. The platform supplies real-time malicious IP feeds, automated blocklist management, reconnaissance-aware threat data, and an rDNS dataset of approximately 1.25 billion PTR records, with native integrations into Microsoft Sentinel (TAXII 2.1), MISP, and major firewalls (Palo Alto, FortiGate, Cisco ASA). Supporting offerings include a fingerprint firewall combining JA3/JA4/MuonFP signatures, free IP lookup and fingerprinting tools, and the open-source Recon Shield eBPF firewall.
Product overview
ELLIO Technology offers a unified Threat Intelligence and Blocklist Automation platform focused on mass exploitation and reconnaissance threats. The portfolio centers on the ELLIO Platform, which integrates five core products: Threat Intelligence (mass exploitation and recon threat data), Blocklist Automation (centralized IP rule management), IP Blocklists (dynamic malicious IP feeds updated every 5 minutes), Recon IP Lists (scanner and reconnaissance IP feeds), and rDNS Dataset (~1.25 billion PTR records). Supporting products include the Fingerprint Firewall (network fingerprint-based defense) and free tools for IP lookup and fingerprinting. The platform enables real-time threat enrichment for SIEM/SOAR systems and automated blocklist distribution to firewalls.
Differentiator
Problem solved
Functional benefit
Products and services
- ELLIO Platform Unified threat intelligence and blocklist automation platform providing real-time adaptive protection against malicious IP traffic and reconnaissance campaigns for SOC teams, small IT teams, and enterprise security organizations.
- Threat Intelligence Mass exploitation and reconnaissance threat data feed linking exploitation campaigns to IPs and mapping CVEs to vulnerabilities attackers are actively exploiting, for SOC and detection engineering teams.
- Blocklist Automation Centralized IP rule management system that defines allow and block rules with fine granularity and applies them automatically across firewalls, eliminating manual IP blocking workflows for security teams.
- IP Blocklists Curated dynamic malicious IP feeds updated automatically every 5 minutes based on real-time threat detection, for ingestion into firewalls and security infrastructure.
- Recon IP Lists Continuously updated lists of scanner and reconnaissance IPs (covering Censys, Shodan, BinaryEdge, Cortex Xpanse and others) that let organizations define which scanners to block or always allow, improving detection accuracy at the perimeter.
- rDNS Dataset Complete IPv4 reverse DNS dataset of approximately 1.25 billion clean PTR records updated daily, used for brand impersonation detection and infrastructure analysis by security and brand-protection teams.
- Fingerprint Firewall Unified defense layer that combines JA4, JA3, and MuonFP network fingerprints with user-provided signatures and traditional IP blocklists for real-time scanner detection and blocking that survives IP rotation.
- ELLIO Free IP Lookup Free IP checker that provides real-time context on IP traffic including geo data, ports, HTTP activity, CVEs, SSH authentication attempts, and network fingerprints (JA4, JA3, MuonFP), usable without registration.
- My Fingerprints Free tool for generating MuonFP, JA4, and JA3 network fingerprints for a given system, used by security practitioners for system identification and fingerprint analysis.
- Recon Shield (TCP Fingerprint Firewall) Open-source TCP fingerprint firewall built on high-performance eBPF technology that uses MuonFP-based fingerprints to detect and block malicious scanners in real time; launched at Black Hat USA 2025.
Quantifiable outcome
- ELLIO tripled its global sensor coverage in December 2024, significantly expanding its cyber deception network for improved threat detection.
- +2 more outcomes
Companies that use ELLIO Technology
Customer profileNamed customers5 records
Segments5 records
Ideal customer profiles3 records
ELLIO Technology technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
AI capability2 records
Feature9 records
ELLIO Technology partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and minor.
- Microsoft SentinelcoreNative integration with Microsoft Sentinel via TAXII 2.1 protocol. ELLIO provides real-time threat intelligence enrichment for Sentinel workflows, improving signal quality across all Sentinel operations and enabling better threat detection.
- MISP (Malware Information Sharing Platform)coreNative integration with MISP for threat intelligence sharing and SOC/detection engineering workflows. Enables interoperability with the MISP threat sharing ecosystem.
- ELLIO Partner ProgramminorELLIO operates a partner lead registration program where partners submit business leads through an online registration system. Partners can earn margins/fees for validated leads that convert to signed customer contracts. The program has defined terms including 30-day engagement window and 365-day contract window.
Scale indicators5 records
Recent moves7 records
Expansion highlights6 records
ELLIO Technology competitors and assessment
Company assessmentEmerging players
- Cortex Xpanse: Palo Alto Networks' Cortex Xpanse provides attack surface management that continuously discovers exposed assets and recon-exposed infrastructure; it overlaps with ELLIO's attack-surface-reduction solution but is embedded in a much larger security portfolio.
- BinaryEdge: BinaryEdge performs continuous internet-wide scanning and exposes reconnaissance data via API; it overlaps with ELLIO's recon IP intelligence but lacks the deception-network and mass-exploitation correlation layer.
Direct peers
- Acalvio Technologies: Acalvio provides enterprise deception platforms that detect adversaries inside the network; comparable to ELLIO's deception-network heritage and enterprise-focused go-to-market.
- Thinkst Canary: Thinkst Canary deploys honeypots and deception tokens that alert on intrusions; both companies generate threat intelligence from deception assets, though ELLIO adds a global internet-scale reconnaissance layer on top.
- GreyNoise Intelligence: GreyNoise collects, classifies, and labels internet-wide scanner and reconnaissance traffic to help SOCs filter noise - the closest direct analogue to ELLIO's mass-exploitation and recon IP intelligence offering.
- Attivo Networks: Attivo built a leading deception platform for identity and endpoint deception; now part of SentinelOne, it is the most direct large-scale competitor in cyber deception technology.
Others
- Shodan: Shodan is a public internet scanning and reconnaissance data platform frequently referenced in ELLIO's research; it is more of a data/enabling service than a competing security product, but shapes buyer expectations for recon intelligence.
Broad incumbents
- CrowdStrike: CrowdStrike bundles adversary intelligence and threat hunting into its Falcon platform; its intelligence product competes for budget allocated to mass-exploitation and recon use cases that ELLIO targets.
- Recorded Future: Recorded Future is a broad threat intelligence platform covering a much wider range of adversaries, malware, and dark-web data than ELLIO's recon/mass-exploitation focus, but competes for the same threat intelligence budget.
- Mandiant: Mandiant (now part of Google Cloud) provides intelligence-led incident response and threat intel services covering the full attack lifecycle; it offers adjacent recon intelligence at much larger scale and breadth.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
ELLIO Technology financial estimates
Financial estimateRevenue estimate
Valuation estimate
ELLIO Technology leadership team
Management profileNumber of profiles
Profiles2 records
ELLIO Technology funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ELLIO Technology M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ELLIO Technology
What does ELLIO Technology do?
ELLIO operates a global cyber deception network of honeypots to collect first-party threat intelligence on mass exploitation and network reconnaissance activity, then delivers it through the ELLIO Platform—a unified threat intelligence and blocklist automation SaaS. The platform supplies real-time malicious IP feeds, automated blocklist management, reconnaissance-aware threat data, and an rDNS dataset of approximately 1.25 billion PTR records, with native integrations into Microsoft Sentinel (TAXII 2.1), MISP, and major firewalls (Palo Alto, FortiGate, Cisco ASA). Supporting offerings include a fingerprint firewall combining JA3/JA4/MuonFP signatures, free IP lookup and fingerprinting tools, and the open-source Recon Shield eBPF firewall.
Is ELLIO Technology a public or private company?
ELLIO Technology is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was ELLIO Technology founded?
ELLIO Technology was founded in 2022. It employs 1 to 10 people.
Where is ELLIO Technology based?
ELLIO Technology is headquartered in Prague, Czechia, in the Europe region.
How does ELLIO Technology make money?
Four revenue lines are on record. Threat Intelligence Platform Subscription is the primary driver. The others are API License Access, enterprise Custom Orders and partner Lead Fees.
Who are ELLIO Technology's main competitors?
Emerging players on record are Cortex Xpanse and BinaryEdge. Direct peers are Acalvio Technologies, Thinkst Canary, GreyNoise Intelligence and Attivo Networks. Shodan is listed as an others. Broad incumbents are CrowdStrike, Recorded Future and Mandiant.
Does ELLIO Technology have an API?
Yes. ELLIO Technology exposes a public API. Developer documentation is at docs.ellio.tech.
What industry is ELLIO Technology in?
ELLIO Technology's product category is Threat Intelligence Platform. Its primary akta.pro industry code is HDADAGAI, Deception Technology & Threat Hunting, with a secondary code of HDADABAN, Deception & Honeypot-Based Network Defense. Its NAICS code is 54151.