
Security is only as strong as the evidence it relies on.
When decisions are made at machine speed, context matters more than ever. ELLIO provides direct, first-party observation of live reconnaissance, probing, and exploitation activity, delivering the fresh context needed to make the right call at the right time.
We read reconnaissance
as intelligence, not noise.
At Internet scale, patterns of targeting, probing, infrastructure reuse, and changing behavior reveal where adversary attention is moving and when isolated activity starts to form a campaign. That upstream visibility matters because the earlier a threat is understood, the less it costs to contain.
European Threat Intelligence for early-stage attacks.
We are based in Prague, where the word “robot” first entered the world through Karel Čapek’s R.U.R. in 1921. A century later, the Internet is filled with machines probing, scanning, and testing systems at a scale no human could match.
ELLIO is European threat intelligence built around observing that activity directly. Our cyber deception network captures reconnaissance across the Internet, turning individual observations into intelligence on what is being targeted, who is looking, and where activity is starting to converge.
Inspired by the legacy of the first antivirus pioneers.
ELLIO was founded by Vlad Iliushin and Jana Tom, who met at Avast (now Gen Digital Inc.), the company behind the first Windows 95 antivirus. Backed by Presto Ventures, they launched ELLIO to automate, optimize, and uncover emerging threats before they grow into costly incidents.
5 JAN
Pre-Attack Intelligence Research
Started research into the pre-attack threat landscape, focusing on reconnaissance, exploitation, adversary behavior, and early indicators of attack intent.
12 DEC
Venture Backing
Presto Ventures came on board as an investor, supporting ELLIO’s mission to build a new generation of adversary intelligence.
30 JUN
ELLIO Threat List MAX
Released a high-fidelity IP intelligence feed derived from real-time reconnaissance and exploitation activity.
1 OCT
ELLIO Intelligence for NGFW
Extended ELLIO Intelligence into NGFWs for active threat and live scanning detection.
1 APR
ELLIO Recon & Exloitation Atlas
Launched the ELLIO Intelligence Platform, unifying reconnaissance, exploitation, infrastructure, and adversary intelligence into a single intelligence layer.
1 NOV
Multiple Fingerprint Intelligence
Introduced network fingerprint intelligence, expanding ELLIO Adversary Intelligence with behavioral signals from network communication and reconnaissance activity.
15 DEC
Global Intelligence Expansion
Tripled the ELLIO Cyber Deception Network, significantly expanding the volume and geographic coverage of real-time threat observations feeding ELLIO Intelligence.
1 JUN
MITRE ATT&CK® Integration
Integrated MITRE ATT&CK® to map observed reconnaissance and exploitation activity to adversary techniques and enrich behavioral intelligence.
5 AUG
ELLIO NullRecon Technology
Released a pre-attack reconnaissance defense layer for firewalls, WAFs, reverse proxies, and CDN edges, using fingerprint intelligence to identify scanning tools by their connection behavior, not IPs.
15 JAN
Interactive Historical IP Intelligence
Introduced the Historical IP Timeline, enabling analysts to trace IP activity, infrastructure evolution, and observed threat behavior over time.
17 FEB
ELLIO for Microsoft Sentinel
Introduced the ELLIO Threat Intelligence integration for Microsoft Sentinel, delivering reconnaissance and exploitation intelligence through TAXII 2.1 and STIX 2.1.
29 APR
ELLIO Intelligence API
Expanded ELLIO into an agent-ready intelligence layer, delivering real-time threat observations, fingerprints, historical activity, and adversary behavior to automated workflows.
2 AUG
ELLIO for Google SecOps
Released the ELLIO integration for Google SecOps, bringing live reconnaissance and mass-exploitation intelligence into SIEM detection, investigation, and SOAR workflows.
7 SEP
ELLIO MCP Server
Introduced the ELLIO MCP Server, making live adversary intelligence directly accessible to AI agents for querying, reasoning, and autonomous security workflows.
2022
5 JAN
Pre-Attack Intelligence Research
Started research into the pre-attack threat landscape, focusing on reconnaissance, exploitation, adversary behavior, and early indicators of attack intent.
12 DEC
Venture Backing
Presto Ventures came on board as an investor, supporting ELLIO’s mission to build a new generation of adversary intelligence.
2023
30 JUN
ELLIO Threat List MAX
Released a high-fidelity IP intelligence feed derived from real-time reconnaissance and exploitation activity.
1 OCT
ELLIO Intelligence for NGFW
Extended ELLIO Intelligence into NGFWs for active threat and live scanning detection.
2024
1 APR
ELLIO Recon & Exloitation Atlas
Launched the ELLIO Intelligence Platform, unifying reconnaissance, exploitation, infrastructure, and adversary intelligence into a single intelligence layer.
1 NOV
Multiple Fingerprint Intelligence
Introduced network fingerprint intelligence, expanding ELLIO Adversary Intelligence with behavioral signals from network communication and reconnaissance activity.
15 DEC
Global Intelligence Expansion
Tripled the ELLIO Cyber Deception Network, significantly expanding the volume and geographic coverage of real-time threat observations feeding ELLIO Intelligence.
2025
1 JUN
MITRE ATT&CK® Integration
Integrated MITRE ATT&CK® to map observed reconnaissance and exploitation activity to adversary techniques and enrich behavioral intelligence.
5 AUG
ELLIO NullRecon Technology
Released a pre-attack reconnaissance defense layer for firewalls, WAFs, reverse proxies, and CDN edges, using fingerprint intelligence to identify scanning tools by their connection behavior, not IPs.
2026
15 JAN
Interactive Historical IP Intelligence
Introduced the Historical IP Timeline, enabling analysts to trace IP activity, infrastructure evolution, and observed threat behavior over time.
17 FEB
ELLIO for Microsoft Sentinel
Introduced the ELLIO Threat Intelligence integration for Microsoft Sentinel, delivering reconnaissance and exploitation intelligence through TAXII 2.1 and STIX 2.1.
29 APR
ELLIO Intelligence API
Expanded ELLIO into an agent-ready intelligence layer, delivering real-time threat observations, fingerprints, historical activity, and adversary behavior to automated workflows.
2 AUG
ELLIO for Google SecOps
Released the ELLIO integration for Google SecOps, bringing live reconnaissance and mass-exploitation intelligence into SIEM detection, investigation, and SOAR workflows.
7 SEP
ELLIO MCP Server
Introduced the ELLIO MCP Server, making live adversary intelligence directly accessible to AI agents for querying, reasoning, and autonomous security workflows.
ELLIO Gets a Major Upgrade in Its Recon & Mass Exploitation Intelligence
Today, we’re releasing a major set of improvements to ELLIO Reconnaissance and Mass Exploitation Intelligence.
wp2shell in the Wild: From Patch to Mass Exploitation in Under 48 hours
The ELLIO Deception Network recorded more than 11,500 sessions across 700 sensors as traffic moved from probing to attempted database extraction, administrator creation, and a web-shell write. The first probe arrived the morning after WordPress published its fix.
Sanctioned, Seized, Still Scanning: Inside a Russian Bulletproof Hosting Network Targeting the EU
On 18 May 2026, Dutch investigators seized more than 800 servers and broke up a hosting operation that prosecutors say powered Russian cyberattacks across the EU. We had spent the previous year watching the same network from the other side. After the seizure, the scanning did not stop.
Microsoft Security Naming Survival Guide
A quick guide to Microsoft security name changes, helping you make sense of current terms without getting lost in older names.
Why Microsoft Sentinel Feels Noisy: It’s Not Volume, It’s Recon Blindness
Alert fatigue in Microsoft Sentinel is not caused by alert volume alone. It is a context and correlation problem. Read how reconnaissance-aware threat intelligence helps separate internet scanning noise from active exploitation activity to improve signal quality and reduce false-positive incidents.
Threat Intelligence Platforms by Use Case: 2026 Guide
Not all CTI platforms are built for the same purpose. Differences in data sourcing, architecture, and enrichment capabilities mean the “best” platform is defined by its fit for operational use cases, such as reducing SIEM noise, supporting threat hunting, or detecting fraud.