Last updated: 17 April 2026
Defused: see exploits land before the advisory drops
First-party honeypot telemetry, full payloads, real-time API delivery
Defused builds and operates a global network of honeypots that captures exploit campaigns in the wild (full payloads, command sequences and post-exploit indicators), often before the vendor publishes a CVE advisory. No repackaged third-party feeds, no sanitised summaries. Raw attacker data from first-party sensors, ready for your SIEM, SOAR or TIP. Neo Security handles onboarding, tuning and integration into your detection stack.
Real-time
API + webhook delivery
First-party
Own sensors, no aggregation
Full capture
Request bodies, not just IPs
> Quick answer
- What
- Honeypot-driven threat intelligence across four products: TF (Threat Feed) for exploit payloads from a shared sensor network, EX (External) for managed decoys on your perimeter, Builder for self-hosted deception infrastructure, and IB (Internal Breach Detection) for bespoke internal deception deployments.
- Who for
- SOC analysts, detection engineers, threat intelligence teams and MSSPs at Dutch and European organisations under NIS2 article 21, ISO 27001 A.5.7 (threat intelligence), DORA article 6, or running their own SOC/CDC that wants to base detection on exploit behaviour instead of CVE lists.
- Where
- Data delivery via REST API, webhook, syslog, or native SIEM connectors (Splunk, Sentinel, QRadar, Elastic). Decoys are geographically placed, custom-branded, and optionally include PCAP capture. IB deployments run on-premise or in your own cloud tenant.
- When
- After a zero-day you had no detection for, ahead of a NIS2 or DORA audit where you must demonstrate structured threat intelligence, when standing up or expanding an MSSP offering, or when your current feed only reports after the vendor advisory lands.
- Cost indication
- TF Research from $50/month (10 streams, research license). TF Pro $299/month (full API, SIEM integration, Radar anomaly detection). TF Enterprise on quote (unlimited streams + commercial redistribution). EX from $599/month (10 always-on decoys). IB: scoped per engagement. Final pricing including Dutch implementation, tuning and support is issued by Neo Security.
- Lead time
- TF API onboarding within one business day of contracting. EX deployment: 5 to 10 business days for scoping, decoy branding and geo placement. IB: 4 to 8 weeks scoping, then phased rollout of 2 to 4 months. SIEM detection content by Neo Security: within 10 business days of go-live.
> What is Defused?
Defused is a deception and threat-intelligence platform that runs on a global network of first-party honeypots. Sensors are built, distributed and operated by Defused itself. Every hit on a sensor (port scan, exploit attempt, credential stuffing, C2 callback) is captured with full request body, timing, IP metadata and autonomous-system context. The raw data is enriched by a Radar anomaly index that separates background noise (mass scanners, commodity botnets) from targeted activity (campaigns, pre-disclosure exploitation).
The product comes in four lines. TF (Threat Feed) gives access to the shared sensor output: a real-time stream of payloads and post-exploit indicators every customer uses for detection engineering, hunt prioritization and TI enrichment. EX (External) places dedicated managed decoys on your own perimeter, branded and geolocated to look like your real infrastructure, with cross-referencing against TF to filter scanner noise. Builder (currently in limited release) lets you run Defused decoys on your own infrastructure with full data sovereignty. IB (Internal Breach Detection) is a professional-services engagement for bespoke internal deception: IT, OT and identity decoys inside your network for detection of lateral movement, credential theft and insider threats.
Defused delivers three things commodity threat feeds do not. First, first-party collection: every data point comes from sensors Defused owns and operates, no aggregation of other people's feeds and no sanitised summaries. Second, full payload capture: you see exactly what the attacker sent, not just an IP and a port. Third, speed: sensors pick up exploitation the moment it happens, often days before the vendor publishes an advisory. Coverage in Forbes, Security Week, The Hacker News and SCWorld cites Defused telemetry for CVE-2026-35616 (FortiClient EMS), CVE-2026-3055 (Citrix NetScaler), CVE-2025-55182 (React2Shell) and Ivanti EPMM sleeper shells.
Defused is not a SIEM, not an EDR and not an IDS/IPS. It deploys no agents on your endpoints and blocks nothing in your network. It produces high-value intelligence that you feed into your existing detection stack. That makes Defused the source-data supplier in a chain that continues with your SIEM for correlation, your SOAR for response automation, your TIP for enrichment, and your EDR for endpoint blocking.
What Defused explicitly is not
- ›Not an EDR/XDR: Defused deploys no endpoint agents and blocks no processes.
- ›Not a replacement for your SIEM: Defused feeds your SIEM, it does not replace your correlation and logging platform.
- ›Not an aggregator of third-party feeds: all telemetry comes from first-party sensors.
- ›Not a managed SOC: detection, triage and response remain with you or your MSSP (optionally Neo Security).
> Who is Defused for?
Primary audience
SOC leads, detection engineers and threat intelligence analysts at Dutch and European organisations running their own CDC/SOC with a mature detection pipeline. These teams have a SIEM (Splunk, Sentinel, QRadar or Elastic) in production, write their own detection content, and want to stop waiting for vendor advisories before they can build detections. For them, TF Pro or Enterprise is the logical starting point, optionally complemented with EX decoys to tell whether a campaign is specifically targeting their infrastructure.
Secondary audience
MSSPs and managed-SOC providers who want to enrich their own customer offering with exploit intelligence they cannot generate themselves. Defused offers multi-tenant deployments, white-label decoy branding and commercial redistribution rights under the OEM/MSSP programme. For Benelux MSSPs this is a way to add a tangible differentiator to customer reporting without building honeypot infrastructure in-house.
Tertiary audience
Threat intelligence teams at larger enterprises, compliance owners under NIS2 or DORA who must demonstrably stand up external threat intelligence, and researchers or red teamers tracking exploit trends. TF Research ($50/month) is deliberately priced low for research and education use.
Who Defused fits less well
Organisations without a SIEM or detection-engineering capacity
Without a team or tooling to turn signals into detections, Defused remains a data source without operational impact. Stand up a SIEM and a SOC process first, then turn TF on.
Small SMEs under 50 FTE
The cost/benefit rarely works out: small organisations usually have no dedicated detection engineers and cannot operationalise the feed. Coverage via an MSSP that consumes Defused itself is a more logical route.
Organisations that want a turn-key managed SOC
Defused is a data platform, not MDR. If the need is 'someone to monitor our alerts', a managed-SOC service (optionally fed by Defused) is the right fit, not a direct TF subscription.
Sectors where Defused delivers the biggest impact
> Where does Defused fit?
Architecture in brief
The Defused sensor network consists of honeypots across multiple geographic and cloud regions, equipped with exploit stubs for popular edge devices (FortiGate, FortiClient EMS, Citrix NetScaler, Ivanti EPMM, Pulse Secure, Cisco ASA, VMware vCenter/ESXi, Microsoft Exchange) and generic application honeypots (web, RDP, SSH, SMB, databases). When an attacker hits a sensor, the full request body, timing, source metadata, and any post-exploit actions (wget/curl, shell commands, uploaded binaries) are captured.
Raw data flows through Radar, Defused's anomaly engine, which classifies signals by noise index, interest level and campaign cluster. Enriched data is available via REST API (JSON), webhook push, syslog, and native integrations with Splunk, Microsoft Sentinel, IBM QRadar and Elastic. For EX customers the decoys are placed on the customer perimeter, optionally with custom branding (hostnames, TLS certificates, HTTP responses that look like the customer's infrastructure) and geographic placement (Amsterdam, Frankfurt, Dublin, or other regions).
Integration points Neo Security configures most often
SIEM
- Splunk (TA + dashboards)
- Microsoft Sentinel (DCR + workbook)
- IBM QRadar (DSM)
- Elastic Security (ingest pipeline)
SOAR
- Palo Alto Cortex XSOAR
- Tines
- Swimlane
- Splunk SOAR (Phantom)
TIP
- MISP (feed module)
- OpenCTI (connector)
- ThreatConnect
- Anomali ThreatStream
Ticketing & communication
- JIRA Service Management
- ServiceNow SIR
- Slack
- Microsoft Teams
Firewall & EDR (indirect IOC push)
- Palo Alto Networks
- Fortinet FortiGate
- CrowdStrike Falcon
- Microsoft Defender for Endpoint
Data format and delivery
Telemetry is delivered as structured JSON with fields for alert_sensor_type, alert_info (for example "Associated with CVE-2025-55182"), alert_IP, port, rawdata (full request body), noise_index, rating (Low/Notable/High Interest), label, and post_exploit_actions (array of action, command and method). That format plugs directly into the ingest pipelines of all listed SIEMs and is compatible with the MISP event structure for TIP import. Webhook delivery gives sub-minute latency between sensor hit and arrival in your stack.
> When should you pick Defused?
Regulatory triggers
NIS2 article 21 requires demonstrable risk management measures including threat-intelligence processes. ISO 27001:2022 Annex A 5.7 lists threat intelligence as an explicit control. DORA article 6 mandates threat-led testing and continuous threat monitoring for financial entities, effective 17 January 2025. In all three frameworks you must show that you procure threat intelligence in a structured, timely manner from a reliable source. Defused supplies the source component, your SIEM/SOC handles the processing layer, and Neo Security (if engaged) produces the audit documentation.
Organic triggers beyond regulation
- $You were just hit by a zero-day that was visible in honeypots three days earlier, but your commercial feed only reported after the vendor advisory.
- $Your SOC writes detections reactively from CVE lists; Defused supplies the pre-disclosure payloads you can build proactive content against.
- $You are standing up an MSSP offering and need an exploit-intel differentiator you cannot produce in-house.
- $Your edge devices (FortiGate, Citrix NetScaler, Ivanti, Pulse Secure) form a persistent attack surface and you want signal days earlier than your current feed gives you.
- $You want to know whether a new campaign is generic scanner activity or specifically aimed at your infrastructure. That is the exact question EX decoys with TF cross-referencing answer.
Authorities and advisories
The Dutch National Cyber Security Centre (NCSC-NL) and the Digital Trust Center (DTC) name threat intelligence as part of baseline hygiene in their NIS2 guidance. ENISA describes threat intelligence as one of seven foundations of mature NIS2 implementation. MITRE ATT&CK and NIST SP 800-160 recognise deception as an explicit cyber-resilience control. Defused fits those recommendations as both an intelligence source (TF) and a deception layer (EX, IB).
> Why Defused over GreyNoise, Shadowserver or a commercial feed?
Honest answer first: there are several good sources for internet-scan and exploit telemetry. GreyNoise is strong at generic internet-noise classification. Shadowserver publishes valuable public reports. Mandiant, Recorded Future and Intel 471 deliver broad commercial feeds with extensive analyst content. We are not going to make the difference look rosier than it is. For some use cases one of those is the right call. Even so, customers we support pick Defused in specific scenarios. Four reasons recur.
Full payload capture instead of IP + classification
GreyNoise excels at 'is this IP noise or targeted', but does not deliver the raw exploit payload. Defused gives the full request body including post-exploit commands. For detection engineering that is the difference between 'we know 1.2.3.4 is attacking' and 'we have the exact payload and can write a detection on it'.
Pre-advisory visibility
Commercial aggregator feeds usually publish only after the vendor releases an advisory, because their analyst teams have to make the link. Defused sensors pick up exploitation the moment it happens. For CVE-2026-35616 (FortiClient EMS) and CVE-2026-3055 (Citrix NetScaler) Defused observations were cited in mainstream press days before the vendor patch was available.
First-party collection, no aggregation
Many feeds are repackaged derivatives of AbuseIPDB, open MISP communities or each other's data. That produces duplicate signals and unclear provenance. Defused owns and operates every sensor itself; every signal has a traceable sensor origin. For auditors and for due diligence in TI procurement that is a measurable advantage.
Decoys that look like your infrastructure (EX)
GreyNoise, Shadowserver and most commercial feeds measure generic internet activity. EX places decoys branded as your organisation, with TLS certs on your subdomains, at geographic locations next to your real infrastructure. A hit on EX is by definition someone who was looking specifically for you. That signal cannot be distilled from generic feeds.
Alternatives that also come up
GreyNoise, Shadowserver Foundation, abuse.ch (Feodo Tracker, URLhaus), CrowdStrike Falcon Intelligence, Recorded Future, Intel 471, Mandiant Advantage Threat Intelligence. Each has strengths Defused does not claim to replace, especially for broad analyst-written reports, brand monitoring, dark-web signals or nation-state attribution. Defused competes on exploit-payload depth and pre-advisory visibility, not on strategic reports. Many SOC teams run Defused alongside GreyNoise and a commercial feed, not instead of.
> Defused in practice
A Dutch customer with 5,000 FTE and an in-house SOC onboards TF Pro in two weeks. Week one: Defused delivers API credentials and Neo Security configures the Splunk integration via the TA, including a workbook showing noise_index, CVE association and post_exploit_actions. Week two: detection engineers use historical TF data to write detections for edge-device exploits that are relevant to the organisation (FortiGate, Citrix, Ivanti). In parallel, a webhook route to Tines is set up that pushes high-interest alerts straight to a Slack channel for the SOC lead.
EX onboarding takes 5 to 10 business days. Scoping decides which decoy archetypes are valuable (for example a FortiGate look-alike, a VPN portal and a Microsoft Exchange look-alike), which regions (Amsterdam and Frankfurt for a Dutch customer), and which TLS hostnames get branded. Defused provisions the decoys, Neo Security wires alerts to SIEM and SOAR and writes the initial detection content. After go-live the noise is monitored for four weeks; around week five high-interest triggers are wired to automated firewall blocks and ticketing.
IB engagements are different. Network topology and threat model are mapped first, then decoy servers, honeytokens and optionally Windows agents for identity decoys are placed in specific segments. Scoping: 4 to 8 weeks. Rollout: 2 to 4 months, depending on segments, compliance requirements and whether OT decoys are in scope. IB is a joint engagement between Defused engineers and Neo Security consultants.
Failure modes we see in practice
!Feed arrives, nothing is done with it
TF is procured without detection-engineering capacity to build content. Result: a dashboard nobody looks at. Remedy: ship at least three production detections based on TF data in the first sprint and deploy them to the SOC floor.
!EX decoys without discipline on whitelisting scans
Internal vulnerability scanners and asset-inventory tools trigger EX decoys constantly, creating noise. Remedy: whitelist your own scanner egress IPs on EX before you enable alert ingestion.
!SIEM ingest without a parser
Pulling in webhook data without field mapping makes SIEM queries slow and brittle. Remedy: at go-live, register the Defused ingest as a dedicated source type and lock down the field mapping (noise_index, rating, cve) before dashboarding starts.
!IB deployment without OT scoping
Internal decoys in IT segments while OT networks stay out of scope, when OT carries the highest business risk. Remedy: include OT scope explicitly in the IB scoping phase, with ICS-specific decoy archetypes.
Timeline of a typical rollout
Week 1
Contracting, API credentials, SIEM integration (Splunk TA / Sentinel DCR / Elastic ingest pipeline), first dashboard live.
Week 2-4
Write detection content on TF payloads, webhook-to-SOAR, SOC runbook update, EX whitelist.
Month 2
EX decoys in production, TI enrichment of incidents with TF context, MISP/OpenCTI sync (optional).
Month 3 and beyond
Monthly threat report based on TF/EX data, quarterly dashboard to CISO/Board, optional extension to IB for internal deception.
> Defused in the press
A selection of recent mainstream media references to Defused telemetry, often days before the vendor published an advisory.
Forbes
New Fortinet Zero-Day Warning: Update Now, Attacks Underway
CVE-2026-35616
SecurityWeek
Exploitation of Critical Fortinet FortiClient EMS Flaw Begins
CVE-2026-35616
The Hacker News
Fortinet fixes critical FortiSIEM flaw
FortiSIEM
Yahoo News
Critical flaw in Citrix NetScaler raises fears of new exploitation wave
CVE-2026-3055
SCWorld
Clandestine IP behind attacks exploiting Ivanti EPMM bugs
Ivanti EPMM
> What Neo Security adds to Defused
Onboarding and SIEM integration
We deliver production-ready Splunk, Sentinel, QRadar or Elastic integrations within ten business days, including field mapping, dashboards and an initial set of detection content.
Detection engineering on TF payloads
We write the first generation of detection rules and sigma conversions from TF data and hand them over to your detection-engineering team with tests and documentation.
EX scoping and decoy branding
We scope which decoy archetypes, hostnames and geographic placements make sense for your specific infrastructure and coordinate branding with Defused.
Optional managed
Not every organisation has a SOC that can process Defused data daily. We offer a managed variant where our analysts handle triage and reporting and only pass validated alerts to your team.
> Frequently asked questions about Defused
Regulatory sources
- NIS2 Directive (EU) 2022/2555, article 21 risk management measures
- DORA Regulation (EU) 2022/2554, article 6 threat intelligence and classification
- ISO/IEC 27001:2022, Annex A.5.7 threat intelligence
- NIST SP 800-160, cyber resilience and deception
- MITRE ATT&CK, deception and early-detection patterns
- ENISA threat landscape reports, NIS2 implementation guidance
See the signal before the advisory
A technical intake starts with your stack, your edge devices, and your current detection gap. No sales pitch. Within two business days an integration sketch, within ten business days production-ready TF detection content in your SIEM.
Call directly
020-716 5487Email us
[email protected]Defused partner. Dutch engineering team. Implementation, tuning and optional managed triage.