How an Open Source Side Project Called Beelzebub Turned Big Tech Adoption Into a 3 Million Euro Seed Round
Editorial Team

Beelzebub, an open‑source honeypot framework originally built as a side project by a solo researcher in Milan back in 2021, has raised a 3 million euro seed round led exclusively by United Ventures, after quietly being adopted by engineers at Microsoft, Google, Cisco, AWS and other major technology companies over the course of more than three years of open development.
The round follows an earlier 300,000 euro pre‑seed raise backed by strategic investors and advisors, bringing Beelzebub's total funding to 3.3 million euros. Founded by Mario Candela, the company has grown from a single open‑source repository into a ten‑person team building a full commercial platform designed to defend organizations against increasingly AI‑driven cyberattacks.
From GitHub Side Project to Enterprise Trust
Beelzebub's technology began as an open‑source deception runtime, a system that deploys adaptive, AI‑powered decoy services across common attack surfaces including SSH, HTTP, TCP, TELNET and, more recently, the Model Context Protocol used by AI agents. Rather than passively logging attack attempts the way traditional honeypots do, Beelzebub's decoys actively engage attackers in realistic interactions, using large language model integrations to generate contextually accurate responses in real time, keeping attackers engaged long enough for the system to collect detailed information about their tools, techniques and objectives.
Over more than 36 months of open development, the project accumulated more than 2,000 GitHub stars and over 450 weekly installations across more than 45 countries, gradually earning the trust of security engineers at Fortune 500 companies including Microsoft, Google, Cisco and Red Hat, largely through organic, developer‑led adoption rather than any formal enterprise sales process. That kind of grassroots technical credibility, built entirely through open‑source usage before a company is formally commercialized, has become an increasingly recognized path to fundraising for infrastructure and security startups, since it gives investors concrete evidence of product‑market fit well before a single sales conversation takes place.
Built for a World Where Attackers Also Use AI
Beelzebub's commercial pitch centers on a threat category its founder argues traditional cybersecurity tooling was never designed to handle: AI‑powered cyberattacks capable of automating vulnerability discovery, generating custom malware, and launching large‑scale attacks at machine speed rather than the slower pace of human‑driven intrusion attempts. As AI tools make it easier for attackers to scale and personalize their techniques, Beelzebub is positioning its deception‑based approach as a way to generate high‑confidence threat intelligence, since every interaction with one of its decoy systems is, by definition, illegitimate activity rather than a false positive requiring manual triage.
The company's platform has since expanded well beyond its original honeypot concept into three integrated products. Its cloud‑based deception and containment layer deploys AI‑powered decoy sensors across infrastructure, Kubernetes clusters, APIs, IoT devices and cloud‑native environments, alongside honeypot tools built specifically to detect prompt injection attacks against AI agents. A separate autonomous red‑team capability, described internally as Arcangelo, continuously runs adversarial simulations around the clock across both conventional IT infrastructure and AI models, including jailbreak attempts, semantic attacks and prompt injections against enterprise large language models, generating audit‑ready evidence of resilience that companies increasingly need to satisfy requirements under the EU AI Act and the Digital Operational Resilience Act.
Riding the Momentum of Formal Cloud Provider Recognition
Beelzebub's growth has been reinforced by its acceptance into the Nvidia Inception Program and support from the startup programs run by AWS, Google and Microsoft, formal recognition from major cloud providers that typically signals a level of technical validation few early‑stage security startups achieve this quickly. That backing, combined with the platform's single‑click deployment availability on the AWS Marketplace, positions Beelzebub to scale distribution through existing cloud provider relationships rather than needing to build enterprise sales infrastructure entirely from scratch.
What the New Capital Will Support
Beelzebub plans to use its new funding to expand its research team, open commercial offices in Rome and San Francisco by the end of the year, and accelerate customer acquisition across Europe, with particular attention to organizations facing new regulatory obligations under the EU's NIS2 Directive and Cyber Resilience Act. The company has also said it will continue developing technology specifically aimed at protecting AI agents directly, extending its deception‑based approach into a category of AI security that remains largely undefined as autonomous agents become more common inside enterprise environments.
A Model for How Open Source Security Tools Can Become Startups
Beelzebub's path from a single developer's open‑source project to a funded, ten‑person cybersecurity company illustrates a recurring pattern in the security industry, where tools built to solve a specific technical problem gain enough organic adoption among engineers at major companies that a formal commercial business becomes a natural next step rather than a speculative bet. For Candela, the challenge ahead lies in translating years of grassroots technical trust into a repeatable enterprise sales motion, a transition that has proven difficult for other open‑source‑turned‑commercial security companies even when the underlying technology has already won over engineers at some of the world's largest technology firms.





