Deutsch

Pervigon Security Suite

Talion

Autonomous security agent, powered by NeoI (neonotu Intelligence).

Doesn't hide. Hunts.

Talion is the autonomous security agent of the Pervigon Security Suite. Unlike classic detection tools, Talion doesn't just report — it acts. Detected activity can be automatically isolated or redirected to honeypots, while the security team is informed and retains control.

Detected, cut off, redirected to the honeypot — the systems behind it stay untouched.

What it changes

01

Response in seconds

Automatic first response within the time windows where human reaction is too slow.

02

Deception, productive

Honeypot redirection becomes part of daily defense, not a research project.

03

Low maintenance overhead

NeoI scoring replaces the extensive playbook maintenance of classic SOAR platforms.

04

Complete audit trail

Every action and override is documented in audit-grade form — ideal for regulated industries.

HOW IT WORKS

The Talion approach

Talion unifies detection, isolation, and active deception in one agent — and places that agent under a clear policy and audit regime.

01

Detect what doesn't fit the norm

Talion learns the normal behavior of an environment — login patterns, data flows, typical application execution, common network paths. Deviations are scored on trained models, not on static thresholds.

02

Isolate before damage spreads

When Talion detects a confirmed anomaly, the affected system can be cut off from critical zones within seconds. Isolation is reversible, fully logged, and overridable.

03

Redirect to honeypots, learn from the attacker

Detected attacker activity can be routed to a controlled honeypot environment. There, attacker behavior, tooling, and objectives are observed — information that flows back into the detection models.

04

Human in the loop, always

Talion acts within a policy defined by the organization. Action classes can be configured from suggestion to confirmation-required to fully automatic — by severity, zone, and risk authorization. Every action is documented traceably.

POLICY

Policy model

The policy engine defines what actions Talion may carry out on its own. An organization can tailor the policy to its maturity, risk appetite, and regulatory pressure.

Action classDescriptionTypical setting
Suggest Talion recommends an action without executing it. Low severity
Confirm Action requires sign-off by a SOC analyst. Medium severity
Auto-execute Action is executed immediately and logged. High severity, clear indicators
Manual override Every action is overridable at any time. Always active

In comparison

Market positioning

Talion addresses a gap that classic EDR tools and SOAR platforms each only partially close.

Aspect EDR alone SOAR platform Talion
Detection Endpoint-centric Source-agnostic Behavioral, multi-source
Response Limited Script-based, high maintenance Policy-based, NeoI-scored
Deception/Honeypot Not in scope Only via integration Native
Maintenance effort Medium High Low
Audit suitability Variable Variable Design principle

In practice

Three examples

How organizations across the European mid-market and the public sector use the module.

01

Lateral movement detected outside business hours

On a Saturday at 03:14, Talion observes login behavior on a server that deviates from the learned normal model. Correlated signals from Strider point to a preceding unusual identity sign-in. Talion isolates the affected server, redirects further connection attempts to a honeypot environment, and informs the on-call engineer through the defined escalation path. The situation is contained before the security team could have responded manually.

02

Honeypot observation of targeted attacks

A mid-sized mechanical engineering firm is repeatedly targeted by clearly intentional attacks on its R&D environment. Talion consistently routes detected attacker activity into honeypot systems modeled after the real R&D zone. Over several weeks, a detailed picture of the tooling and objectives is built up without touching production systems.

03

Reducing mean time to contain

A public administration under high regulatory pressure deploys Talion across its critical zones. Mean time to contain — the time between detection and complete containment — drops from a previous 4 hours to under 90 seconds for the defined action classes. Internal and supervisory reporting benefits measurably.

NEXT STEP

From detection to action

Talion shifts the boundary between detection and response to where, in today's threat landscape, it actually needs to sit: into the seconds, with clearly documented and overridable actions. Human and machine do not work against each other but on a jointly defined policy.

Talion is the part of the Pervigon Security Suite that closes the detect-and-response gap. For organizations under elevated response pressure — regulatory, operational, or insurance-related — it is the logical next step.

More products in the suite

Sightadel

NIS2, DORA, ISO 27001 and GDPR as preconfigured control catalogues, plus a security score from 0 to 100 across six domains. Dat…

View

Strider

Signals from firewall, endpoint, identity and cloud condensed into incidents instead of alert floods. NeoI correlation instead …

View

Valar

Four graded models on cyanbox hardware secure the perimeter and internal zones — from a single practice to a corporate network,…

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.