Beelzebub
Beelzebub is an Italy-based vendor of an AI-native deception and threat-intelligence platform that uses large language models to power dynamic honeypots, autonomous SOC response, and agentic malware analysis, serving enterprise security teams across cloud, AI, OT, and compliance verticals.
- Company typePrivate
- Founded2024
- HeadquartersMilan, Italy
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Beelzebub does
Beelzebub is an Italy-domiciled, privately held vendor of an AI-native deception and threat-intelligence platform, founded and operated by Mario Candela as a bootstrapped entity with 1-10 employees. The company's product suite comprises the open-source Beelzebub honeypot framework (Apache 2.0, 1,800+ GitHub stars), the Beelzebub Cloud managed enterprise platform, the Arcangelo LLM-honeypot module, the Caronte agentic Cyber Threat Intelligence platform, and the Azazel eBPF-based runtime tracer for AI agent monitoring.
The core technology uses Large Language Models to power dynamic, high-interaction deception environments (SSH terminals, HTTP services, databases, IoT/OT emulators, MCP tools) that engage attackers for extended sessions while keeping real infrastructure insulated. Attackers interact exclusively with the LLM, not with production systems. Sensor footprint is intentionally light (2 CPU cores, 4GB RAM, 20GB storage) and deploys in cloud, on-premises, or air-gapped configurations with local Ollama-model support. Autonomous SOC agents perform end-to-end triage, malware sandboxing, and executive-report generation; Caronte extends the platform into agentic CTI that autonomously delivers malware analysis, infrastructure attribution, YARA rule generation, and threat graph construction from a single sample submission in minutes. The Azazel eBPF runtime tracer provides kernel-level (CO-RE, BTF) observability into AI agent containers with 19 hook points designed to be non-evasible by the agent itself. The platform integrates with hyperscalers (AWS, Azure, GCP), major SIEM/SOAR stacks (Splunk, Elastic, Microsoft Sentinel, Palo Alto, Fortinet, Datadog), and multiple LLM providers.
Commercially, Beelzebub operates a freemium go-to-market: the open-source core is free under Apache 2.0, the managed enterprise platform is quote-based subscription (annual cadence) with a 14-day trial and 30-day PoC, and a professional-services layer provides tiered support, on-site deployment, and training. Demand generation combines community-led adoption (GitHub, Telegram, Discord, a Security Lab research blog) with enterprise field sales (Calendly executive coffee chats, Book-a-Demo CTAs, dedicated CSMs). The stated customer set spans AI services, financial services, government, healthcare, manufacturing, IT providers, and transport/logistics verticals — but no enterprise ARR, customer count, or contracted logos are disclosed. Notable named relationships include Telekom Security (honeypot deployment for lateral movement detection), Tejarat Bank (MCP honeypot for prompt-injection detection), KPMG (cybersecurity practice), St. Bonaventure University, and OSRAM. The firm has not raised institutional capital, and revenue, valuation, and headcount growth metrics are not disclosed in the input.
Beelzebub firmographics
Firmographics- Name
- Beelzebub
- Legal name
- Beelzebub
- Website
- https://beelzebub.ai
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Beelzebub is an Italy-based vendor of an AI-native deception and threat-intelligence platform that uses large language models to power dynamic honeypots, autonomous SOC response, and agentic malware analysis, serving enterprise security teams across cloud, AI, OT, and compliance verticals.
- Ownership category
- akta.pro rank
Beelzebub industry classification
Industry- Product category
- Cybersecurity Deception Platform
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- akta.pro primary industry
- Deception & Honeypot-Based Network Defense (HDADABAN)
- akta.pro secondary industry
- Deception / Honeypot Network Security Appliances (HDAFAFAL)
Keywords
Where Beelzebub is headquartered
LocationHeadquarters
- HQ city
- Milan
- HQ country
- Italy
- HQ region
- Europe
Offices1 record
Markets served
Beelzebub business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Open Source Framework: Core Beelzebub honeypot framework is open source (Apache 2.0), freely available on GitHub with 1,800+ stars. Self-hosted deployment at no cost with core deception and detection functionality.
- Enterprise Managed Platform: Subscription-based managed platform adding AI SOC automation, continuous Red Teaming, centralized management, and 24/7 SLA-backed support. Includes guided PoC deployment, dedicated Customer Success Manager, on-site deployment assistance, and custom training programs.
- Professional Support Services: Tiered support offerings including email support with 24h response, video consultation sessions, configuration assistance, on-site deployment assistance, and custom training programs for enterprise customers.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Open Source - Free tier |
| Subscription | Annual | Managed Platform - Subscription |
| Subscription | Annual | Professional Support |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels9 records
Beelzebub product offering
Product offeringCore offering
Beelzebub is an AI-native security platform that uses Large Language Models to create dynamic, high-interaction deception environments (honeypots) across cloud-native infrastructure, Kubernetes clusters, APIs, IoT/OT devices, and AI agent systems. The platform detects lateral movement with zero false positives, performs autonomous SOC response at machine speed, and includes the Caronte agentic CTI platform for autonomous malware analysis and threat intelligence.
Product overview
Beelzebub is an AI-Native security platform that represents a new category of defensive security designed for the AI era. The platform consists of three core products: Beelzebub Cloud (managed enterprise platform), Arcangelo, and Caronte (agentic CTI platform), alongside an open-source honeypot framework (1,800+ GitHub stars). The platform uses Large Language Models to create dynamic, high-interaction deception sensors that deploy across cloud-native environments, Kubernetes, Docker, APIs, and IoT/OT infrastructure. Key capabilities include zero-false-positive threat detection, autonomous SOC response, continuous AI Red Teaming, and real-time malware analysis. Caronte provides agentic threat intelligence that autonomously analyzes malware samples and attributes infrastructure in minutes. Azazel is an additional open-source eBPF-based runtime tracer for AI agent monitoring.
Differentiator
Problem solved
Functional benefit
Brands
- Beelzebub Cloud: Cloud-native deception runtime platform for deploying AI-powered decoys and sensors across infrastructure.
- Arcangelo
- Caronte
Products and services
- Beelzebub Cloud Managed AI-Native security platform providing enterprise-grade deception runtime with zero false positives, continuous AI Red Teaming validation, real-time malware analysis via CTI Hub, and instant AI SOC-driven threat containment. Targeted at enterprise security teams.
- Arcangelo AI-Native security product module for deception and threat detection within the Beelzebub platform. Functions as an LLM honeypot module for creating dynamic, high-interaction honeypots using Large Language Models.
- Caronte Agentic Cyber Threat Intelligence (CTI) platform that autonomously analyzes malware, attributes infrastructure, generates detection rules, and tracks threat actors. Performs complete analysis from single sample submission in minutes without manual reverse engineering. Capable of binary classification, configuration recovery, infrastructure attribution, YARA rule generation, and threat graph building.
- Beelzebub Open Source Framework Open-source honeypot framework with 1,800+ GitHub stars. AI-Native platform using LLMs to create dynamic, high-interaction decoys across SSH, HTTP, TCP, databases, IoT/OT devices, and MCP protocols. Self-hosted version available free under Apache 2.0 license with core functionality including basic honeypot deployment, SSH/HTTP protocols, and LLM integration via OpenAI/Ollama.
- Azazel eBPF-based (CO-RE, BTF-based) runtime tracer for AI agent monitoring. Captures every syscall, file access, network connection, and security event inside containerized AI agents via 19 hook points across tracepoints and kprobes. Provides kernel-level visibility that agents cannot detect, disable, or evade. Output in NDJSON format for Elasticsearch/Splunk integration. Minimum deployment: 2 cores CPU, 4GB RAM, 20GB storage.
Quantifiable outcome
- 60% reduction in SOC operational costs through autonomous triage
- +6 more outcomes
Companies that use Beelzebub
Customer profileNamed customers18 records
Segments7 records
Ideal customer profiles5 records
Beelzebub technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration6 records
AI capability8 records
Feature8 records
Beelzebub partnerships and signals
Strategic signalPartnerships
19 partnerships are on record, tiered core and minor.
- AWScoreAmazon Web Services is listed as a supported integration and customer of Beelzebub. The platform integrates with AWS cloud environments and supports AWS-specific deployment scenarios.
- Google CloudcoreGoogle Cloud Platform integration support. Listed as customer and integration partner with Google Chronicle SIEM integration available.
- MicrosoftcoreMicrosoft Azure integration and customer. Platform supports Microsoft Defender XDR, Microsoft Sentinel SIEM integration. Azure-specific deployment configurations documented.
- NvidiacoreNvidia is listed as a supported integration partner. The platform supports GPU-accelerated environments and Nvidia-specific security scenarios.
- KubernetescoreKubernetes integration is a core part of Beelzebub's platform. Official Helm chart available for Kubernetes deployment. Security Lab research focused on Kubernetes honeypot deployment and lateral movement prevention.
- SplunkcoreSplunk SIEM and Splunk SOAR integrations documented. Beelzebub events and alerts can be routed to Splunk for security operations workflows.
- ElasticcoreElastic SIEM integration available. Beelzebub generates logs in structured JSON format suitable for Elastic Stack ingestion and analysis.
- Palo Alto NetworkscorePalo Alto Cortex XDR and XSOAR integrations documented. Beelzebub can integrate with Palo Alto security orchestration for automated response workflows.
- FortinetcoreFortinet FortiSIEM integration documented. Beelzebub events can be forwarded to Fortinet security management platforms.
- DockercoreDocker container runtime is a core deployment method for Beelzebub sensors. Minimum 2 cores CPU, 4GB RAM, 20GB storage per instance. Docker API honeypot example documented in official docs.
- KongcoreKong API Gateway integration for defensive deception. Beelzebub can simulate Kong Admin API endpoints as honeypots to attract sophisticated attackers targeting API infrastructure.
- DatadogcoreDatadog Security integration documented. Beelzebub can forward security events and alerts to Datadog for monitoring and incident response.
- OpenAIcoreOpenAI GPT models supported as LLM providers for Beelzebub honeypot responses. gpt-4o and other OpenAI models configurable via API key.
- AnthropiccoreAnthropic Claude models supported as LLM providers for Beelzebub honeypot and deception responses.
- Google (Gemini)coreGoogle Gemini models supported as LLM providers for Beelzebub honeypot responses.
- OllamacoreOllama supported for local/air-gapped deployments with CodeLlama, Llama 3, and other models. Enables fully on-premises LLM honeypot operation with no cloud dependencies.
- xAI (Grok)corexAI Grok models supported as LLM providers for Beelzebub honeypot responses.
- OpenRoutercoreOpenRouter supported as LLM provider aggregation for Beelzebub honeypot responses, enabling access to multiple LLM models through single integration.
- EC-CouncilminorMeisam Eslahi, Executive Director at EC-Council, has provided public endorsement of Beelzebub framework's contribution to proactive threat detection and security community.
Scale indicators9 records
Recent moves6 records
Expansion highlights6 records
Beelzebub competitors and assessment
Company assessmentMarket position
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Beelzebub social profiles
Digital presenceBeelzebub compliance and trust
Trust signalCompliance6 records
Beelzebub financial estimates
Financial estimateRevenue estimate
Valuation estimate
Beelzebub leadership team
Management profileNumber of profiles
Profiles3 records
Beelzebub funding detail
Funding detailFunding overview
Funding rounds2 records
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Beelzebub M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Beelzebub
What does Beelzebub do?
Beelzebub is an AI-native security platform that uses Large Language Models to create dynamic, high-interaction deception environments (honeypots) across cloud-native infrastructure, Kubernetes clusters, APIs, IoT/OT devices, and AI agent systems. The platform detects lateral movement with zero false positives, performs autonomous SOC response at machine speed, and includes the Caronte agentic CTI platform for autonomous malware analysis and threat intelligence.
Is Beelzebub a public or private company?
Beelzebub is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Beelzebub founded?
Beelzebub was founded in 2024. It employs 1 to 10 people.
Where is Beelzebub based?
Beelzebub is headquartered in Milan, Italy, in the Europe region.
How does Beelzebub make money?
Three revenue lines are on record. Open Source Framework is the primary driver. The others are enterprise Managed Platform and professional Support Services.
Does Beelzebub have an API?
Yes. Beelzebub provides a public API (v1) for integration purposes. The API allows developers and security tools to interact with the honeypot platform for automation and extensibility. Documentation available at docs.beelzebub.ai. Developer documentation is at docs.beelzebub.ai.
What industry is Beelzebub in?
Beelzebub's product category is Cybersecurity Deception Platform. Its primary akta.pro industry code is HDADABAN, Deception & Honeypot-Based Network Defense, with a secondary code of HDAFAFAL, Deception / Honeypot Network Security Appliances. Its NAICS code is 561621.