Aegis Cyber Intelligence · Under development

Security tools detect events.
Aegis detects trajectory.

A privacy-preserving cyber precursor intelligence platform designed to identify when users, devices, cloud identities and business workflows begin moving toward breach, ransomware, fraud, insider abuse or AI-enabled attack—before the incident fully materialises.

Precursor-firstDetection model
Private by designClient-controlled data
DynamicEntity-risk graph
ExplainableEvidence chains
Aegis Cyber Intelligence cyber precursor and threat graph visual

Not another SIEM, XDR or UEBA

Built for the stage before
the critical alert.

Conventional security platforms are essential, but most are optimised to identify suspicious or malicious events once enough evidence already exists. Aegis is designed to sit above and beside those controls, correlating smaller changes across systems into an earlier view of emerging threat trajectory.

TRADITIONAL / 01

Event detection

SIEM, XDR and UEBA platforms typically identify rules, anomalies, indicators or suspicious activity within their own telemetry domain.

AEGIS / 02

Precursor convergence

Aegis asks whether individually weak signals across identity, endpoint, cloud, SaaS, network and financial behaviour are beginning to form a credible threat pattern.

AEGIS / 03

Threat progression

The system tracks how risk is changing, which entities are connected, what the likely next attacker action may be and which containment step is justified now.

The intelligence layer

From isolated alerts
to an evolving threat case.

Aegis is intended to convert fragmented telemetry into a living, explainable risk graph connecting users, devices, workloads, cloud roles, SaaS identities, external infrastructure and business workflows.

RISK VELOCITY

Detect acceleration

Measure not only whether risk is high, but whether it is rising abnormally fast across related entities.

ATTACK PATH

Forecast the next move

Map observed precursor chains to likely credential expansion, persistence, staging, exfiltration, fraud or destructive action.

EVIDENCE

Explain every score

Expose the contributing signals, confidence, blast radius, business criticality and recommended action behind each case.

INTEGRATION

Complement existing controls

Deliver risk scores and threat cases into current SIEM, SOAR, XDR, Slack, webhook and analyst workflows rather than forcing replacement.

Aegis Veil · Adaptive containment and deception

Protect the real environment.
Divert the intrusion.

When evidence, customer policy and risk level support it, Aegis Veil is designed to remove a suspicious identity, session, device or workload from authentic systems and route it into an isolated, instrumented environment. Real client data stays protected while the intrusion is presented with believable synthetic services and information.

CONTAIN

Cut off authentic access

Use approved customer controls to reduce privilege, revoke sessions, restrict egress, block sensitive operations and isolate affected workloads.

DIVERT

Present synthetic targets

Route suspicious activity toward decoy repositories, documents, APIs, identities or services containing no real client data, credentials or reusable secrets.

OBSERVE

Capture the attack path

Record requested resources, commands, payload hashes, timing, observed IP addresses, domains and progression into the immutable Aegis evidence chain.

TERMINATE

Safety overrides engagement

Ransomware, active exfiltration, destructive activity or integrity failure triggers immediate isolation and termination rather than extended observation.

Low-observable, not invisible.
Veil is designed to make diversion difficult to recognise, but no responsible system can guarantee that a capable intruder will never detect containment. Decoys have no route back to production, contain no authentic client data, and remain subject to customer approval, audit, rollback and an emergency kill switch.
Evidence and attribution boundary: Aegis can track observed infrastructure and associated behaviour—including IP addresses—but an IP address alone is not proof of a person's identity. Veil does not retaliate, hack back or expose customer systems to prolong an engagement.

Initial product focus

Identity, SaaS and cloud
precursors first.

The first production path is deliberately narrow: identity-driven breach and ransomware precursors across Microsoft 365 or Entra ID, Okta, AWS and Google Workspace, with endpoint, fraud, insider-risk and AI-threat modules added later.

IDENTITY

Account takeover drift

MFA fatigue, rare ASN access, dormant-account reuse, privilege changes and unusual service-account behaviour.

SAAS

Data and persistence signals

Suspicious OAuth grants, forwarding rules, mass downloads, exports and administrative changes.

CLOUD

Control-plane movement

Role assumptions, IAM expansion, new access keys, audit tampering and abnormal data-transfer paths.

AI THREATS

Emerging attack surfaces

Prompt injection, AI-system misuse, sensitive-data leakage, synthetic phishing and malicious automation patterns.

Privacy and deployment

The client sees the threats.
Pythology sees system health.

Aegis is being built so that privacy is enforced by architecture. Customer telemetry, identities, content and threat cases remain isolated from Pythology's operational monitoring.

STANDARD / MANAGED ISOLATION

Aegis Managed

A dedicated encrypted tenant, private API connection and customer-side collector. The collector minimises and pseudonymises telemetry before transmission. Aegis services process only the signals the customer has approved; Pythology personnel do not routinely view customer cases or content.

HIGH-RISK / CUSTOMER CONTROLLED

Aegis Private

Processing, threat graphs, evidence and dashboards remain inside the customer's cloud account, VPC or on-premises environment. The customer controls encryption keys and access. Pythology receives only an outbound health heartbeat and cannot access the security data plane.

PYTHOLOGY CAN SEE

Operational health only

Collector availability, software version, queue depth, processing latency, CPU and memory health, certificate expiry, integrity checks and backup status.

PYTHOLOGY CANNOT SEE

Customer security activity

User identities, email or file content, internal logs, IP evidence, threat cases, alerts, employee activity, dashboard content or incident reports in Aegis Private deployments.

Aegis watches the customer's security environment. A separate Watchtower service watches Aegis itself.
The Watchtower verifies that collectors, scoring services and dashboards are healthy without receiving the client's security evidence.

Protection scope

Outside exposure and
inside behaviour.

External monitoring does not require access to internal content. Internal precursor detection is enabled only through customer-authorised connectors and policies.

EXTERNAL

Attack-surface monitoring

Track DNS and certificate changes, unexpected public services, lookalike domains, exposed applications and changes to the organisation's internet-visible footprint.

INTERNAL

Insider-risk precursors

Detect unusual access to restricted information, mass downloads, role misuse, abnormal repository cloning, file staging and other policy-defined deviations.

EMAIL

Outbound data-risk signals

Receive customer-controlled DLP and mail-security events such as sensitive-data matches, unusual external recipients, forwarding rules and blocked or overridden actions—without sending email bodies to Pythology.

CASE INTELLIGENCE

Threat tags and reports

Link observed IPs, domains, hashes, accounts, devices and techniques into cases. Generate client-controlled evidence packages for insurers, legal teams or authorities while preserving uncertainty and chain of custody.

Attribution boundary: Aegis can track observed infrastructure and related activity, but an IP address alone is not proof of a person's identity. Reports distinguish evidence, inference and confirmed facts.

Enterprise and pilot enquiries

Aegis Cyber Intelligence begins
with a technical conversation.

Deployments require discovery across security architecture, available telemetry, data residency, integration scope, governance and the threat outcomes the organisation needs to improve.

Do not submit credentials, security logs, indicators of compromise or confidential incident details through this form.
Initial contact is used only to establish fit and arrange an appropriate technical discussion. Secure information exchange can be established later where required.
01 · DiscoveryCurrent controls, threat priorities, decision workflows and operational constraints.
02 · Technical scopeData sources, connectors, deployment model, retention and integration boundaries.
03 · Pilot designSuccess criteria, baseline metrics, validation method and responsible stakeholders.
Your enquiry will be reviewed directly by Pythology. No sensitive operational data should be included at this stage.
Aegis is being designed to increase warning time without turning Pythology into a custodian of the client's sensitive security data.