Beelzebub Secures $3.4 Million to Scale AI-Native Deception Platform
- CVE ID
- N/A
- Affected Products / Orgs
- N/A
Milan-based cybersecurity startup Beelzebub has closed a €3 million (~$3.4 million) seed funding round led by venture capital firm United Ventures, bringing its total funding to $3.8 million. The company plans to use the capital to expand its core research division, establish operational presences in Rome and San Francisco, and accelerate commercial adoption of its automated hacker-trapping platform across Europe, with an immediate focus on organizations navigating strict compliance frameworks like NIS2.
Founded in 2025 by CEO Mario Candela, Beelzebub is targeting the growing imbalance between AI-assisted cyber operations and traditional, manual SOC defense mechanisms. By integrating continuous adversary emulation with LLM-powered deception environments, the company’s platform aims to catch post-exploitation threat activity in real time while insulating host environments from live impact.
Continuous Adversary Emulation Meets Dynamic Runtime Deception
Traditional defense-in-depth relies heavily on static rules, perimeter defenses, and reactive endpoint detection. However, modern intrusion sets increasingly leverage living-off-the-land (LotL) techniques, credential theft, and automated vulnerability exploitation scripts that slide past standard behavioral baselines. Beelzebub’s architecture operates under a explicit “assume breach” methodology, acting under the premise that adversary entry into internal networks is inevitable.
The platform addresses this paradigm through two complementary operational loops:
- Continuous Adversary Emulation (Red Teaming): The platform autonomously maps attack surface telemetry and simulates emerging tradecraft against internal assets. Rather than relying on periodic penetration testing or manual red team engagements, the automated emulation agent identifies potential escalation paths, privilege vectors, and lateral movement channels before an active adversary can discover them.
- LLM-Powered Deception Traps (Blue Teaming): When an attacker breaches the outer perimeter, the platform diverts their activity into isolated, dynamic honeynets. Rather than using static traps or simple fake services (like open SSH or HTTP banners), Beelzebub utilizes large language models (LLMs) to dynamically generate realistic file systems, active sessions, dynamic API endpoints, and system responses. This interactive feedback loop traps attackers in closed-loop simulations, exhausting their operational resources while capturing real-time telemetry on their tools, techniques, and procedures (TTPs).
Once an intrusion is contained within the dynamic trap, the platform’s AI analyst isolates impacted endpoints, initiates local incident response workflows, and dissects incoming malware payloads. Telemetry captured during the interaction is transformed into actionable threat intelligence, automatically generating localized detection engineering rules to protect the broader production network.
The Operational Advantage of Low-Noise Deception
For enterprise Security Operations Centers (SOCs), one of the persistent challenges with modern SIEM and XDR tooling is alert fatigue. Security analysts are frequently flooded with low-fidelity telemetry, false positives, and benign system anomalies.
Deception technology fundamentally flips the signal-to-noise ratio: because legitimate users and legitimate service accounts have no operational business interacting with decoy tokens, dynamic honeypots, or fake Active Directory objects, any interaction with a deception asset constitutes a high-confidence indicator of compromise (IoC) or unauthorized internal discovery.
By combining LLMs with dynamic deception environments, modern trapping platforms address the classic limitation of legacy honeypots: predictability. Sophisticated threat actors regularly run anti-analysis checks, honeypot detection scripts, or environmental checks (such as inspecting system uptime, loaded drivers, hardware parameters, or interactive shell behaviors) to detect whether they are inside a sandbox. Dynamic, LLM-backed responses allow decoys to maintain operational realism during interactive attacker sessions, increasing attacker dwell time inside the trap while security teams gather threat intelligence.
On-Premises Capability and NIS2 Compliance
A critical component of Beelzebub’s positioning is its deployment flexibility. While available as a Software-as-a-Service (SaaS) model, the platform can also be deployed completely on-premises within air-gapped or heavily regulated enterprise networks.
This architectural choice directly addresses the stringent data sovereignty, privacy, and incident notification mandates imposed by European regulatory frameworks, most notably the Network and Information Security 2 (NIS2) Directive. Under NIS2, essential and important entities across critical infrastructure, healthcare, energy, and digital services face strict 24-hour initial notification timelines for significant incidents, alongside severe penalties for failure to manage supply chain and operational risks.
Deploying AI analysis engines and threat intelligence tools locally ensures that sensitive internal network logs, host telemetry, and proprietary asset mappings do not leave the organizational security boundary or violate strict data-handling policies. Additionally, the platform integrates live threat intelligence feeds sourced from over 60 independent global researchers, ensuring that localized defense engines remain updated against zero-day exploits and novel adversary tradecraft without compromising internal operational security.
Related content
Adobe Patches Maximum-Severity CVSS 10.0 Zero-Click Flaw in Campaign Classic
Security NewsCritical Adobe ColdFusion Vulnerability (CVE-2026-48282) Actively Exploited In The Wild
Security NewsAnthropic Claude Attacks Driven by System Over-Permissioning, Not Model Vulnerabilities
Security NewsApple Patches CVE-2026-43810 and Hundreds of Flaws Across iOS and macOS
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call