Autonomous detection, AI-powered triage, honeypot deception, and active response. Five layers of defense that never sleep. Clone, compose, defend.
Each layer operates independently. Each can block autonomously. Together they form a detection pipeline verified through live pentesting.
Compiled regex pattern matching with double URL-decode. SQLi, XSS, traversal, and command injection detected in 18 microseconds. Auto-blocks after 3 strikes.
Real-time PM2 log tailing with brute-force tracking, port scan detection, and cross-service rate limiting. Seven pattern categories monitored continuously.
122 detection rules with 5 chain rules for multi-event correlation. Campaign tracker links recon, exploit, persistence, and exfiltration across a 10K event window.
13 model routes via OpenRouter including uncensored red-team analysis. Sub-300ms fast path. Full MITRE ATT&CK mapping and audit trail on every decision.
SSH and HTTP honeypots with breadcrumb trap credentials. Attacker steals fake .env, uses creds on real API, gets caught instantly. Full interaction profiling.
Uncensored AI analyzes attacker infrastructure and recommends intelligence gathering, deception campaigns, and abuse reporting. Guardrails enforced on all actions.
Validated against a comprehensive penetration test suite using Kali Linux tooling against live production services. Not simulated. Not staged. Real attacks, real defenses.
Every request inspected. Every attack profiled. Every response logged and auditable.
Layer 1 middleware detection latency. Measured on production hardware under real traffic load.
Open source — verify it yourself. All benchmarks reproducible with the included test suite.
Full detection pipeline is always free. Enterprise unlocks premium modules, unlimited scale, and dedicated support.
AEGIS is an open-source autonomous cybersecurity defense platform that detects, analyzes, and neutralizes threats without human intervention. It features a 5-layer detection pipeline with 18-microsecond response time, 122 Sigma rules, AI-powered triage with MITRE ATT&CK mapping, honeypot deception with breadcrumb traps, and autonomous incident response. Deploy with a single docker compose up command.
AEGIS matches or exceeds both in detection while being fully open source (AGPL-3.0). Unlike Wazuh, AEGIS includes AI-powered honeypot deception and counter-attack analysis. Unlike CrowdStrike, AEGIS is free, self-hosted, and transparent. AEGIS uniquely offers breadcrumb credential traps, shared community threat intelligence, and an 18-microsecond detection pipeline.
Clone the repo, copy .env.example to .env, set your AEGIS_SECRET_KEY, and run docker compose up. Open localhost:3000 — the setup wizard walks you through creating your organization, configuring AI, discovering assets, deploying honeypots, and enabling threat intel sharing. No default credentials — you create your admin account.
Yes. AEGIS is fully open source under AGPL-3.0. The free tier includes the complete 5-layer detection pipeline, SSH and HTTP honeypots with breadcrumb traps, AI triage with MITRE ATT&CK mapping, 122 Sigma rules, counter-attack AI, behavioral ML, shared threat intelligence, dashboard with RBAC, and the Rust endpoint agent — for up to 20 nodes, 100 assets, and 3 users. Enterprise is a custom-priced tier for companies that need smart AI honeypots, quantum analysis, adversarial ML detection, compliance dashboards (ISO 27001, NIS2, SOC 2), SSO, unlimited scale, and dedicated support.
AEGIS has an 11/11 verified detection score: SQL injection, XSS, path traversal, command injection, SSH brute force, port scanning, scanner detection (nmap/sqlmap/nikto), breadcrumb credential theft, lateral movement, C2 beacons (via Renyi entropy analysis), and distributed credential stuffing. Every detection was verified through live penetration testing from Kali Linux.
No. AEGIS works without any AI key using deterministic Sigma rules and playbooks. AI features (triage, classification, counter-attack analysis) activate when you configure an OpenRouter, OpenAI, Anthropic, or Ollama provider. Free AI models are available through OpenRouter. Ollama provides fully local AI with no external API calls.