Enterprise Kubernetes & Cybersecurity Software for Regulated Infrastructure
Hexalon Technologies builds enterprise infrastructure software for Kubernetes management and virtualization, GPU workloads, and automated DDoS protection — across on-premises, edge and cloud environments.
Two platforms. One standard of engineering.
AetherVirt is a Kubernetes management platform that gives platform teams a single control plane for containers, virtual machines and GPU workloads. eHAWK DDoS is a DDoS protection platform that gives network operators automated, network-level defence against attacks. Both are built for auditability, scale, and day-one operational clarity.
AetherVirt is a Kubernetes management platform that unifies day-2 operations for platform teams — cluster health, KubeVirt virtualization, GPU workloads, storage, networking, and security — into a single, auditable console built for regulated, enterprise-scale environments.
Unify operations
Manage Deployments, Pods, Jobs, StatefulSets, and KubeVirt VMs from one console — no tool-switching.
See everything, instantly
Cluster health, topology, capacity, and security posture are visible the moment you log in.
Operate with confidence
RBAC-backed, audited actions across GPUs, storage, and networking reduce operational risk.
- Multi-cluster inventory — health, capacity, node roles
- Virtualization — KubeVirt VMs, images, flavors, migrations
- GPU & AI — MIG-aware allocation, AI workload templates
- Storage insight — CSI capacity, PVC/PV, IOPS charts
- Networking — Services, Gateway API, MetalLB, firewall policy
- Security — RBAC, admission policy, vulnerability scanning
- Runtime security — eBPF policies, alerts, investigations
- Governance — full audit logging, permission-aware UI
Run virtual machines the same way you run containers
Most teams end up maintaining two stacks: one for cloud-native workloads, another for the VMs the business still depends on — each with its own console, its own access model, and its own blind spots. AetherVirt collapses that divide by treating KubeVirt virtual machines as first-class Kubernetes objects: same namespaces, same RBAC, same observability, same audit trail. See when to choose a VM over a container for the full comparison.
Full VM lifecycle, orchestrated
Every VM operation is a permission-checked, tracked action in the control plane — not an SSH session on a hypervisor.
- Create, clone, snapshot, migrate and restore, with built-in progress tracking
- Golden images and flavors, so every new VM starts from an approved baseline
- Templates, SSH key management and in-browser console access
- Backup and restore policies applied per VM, not per hypervisor
- Migrations handled as a tracked, first-class operation
Containers and VMs sharing one inventory
Scheduling and placement
VMs are scheduled by Kubernetes itself, so node roles, capacity and readiness govern placement exactly as they do for pods — with HPA/VPA workflows available for the services around them.
GPU-aware orchestration
Node-level GPU visibility and MIG-aware allocation let accelerated workloads and AI workload templates land on the right hardware, instead of being hand-placed by an operator.
Storage that follows the VM
CSI-backed PVC/PV management with real capacity, IOPS and utilization data — so storage pressure shows up as a trend long before it becomes an incident.
One access model
RBAC with SSO or local authentication governs container and VM actions alike. A permission-aware UI hides what an operator cannot do, and every action lands in the audit log.
Networking as policy
Services, networks, firewall policies, Gateway API and MetalLB are configured from the same console, so VM connectivity stops being a separate change request.
Observability across both
Topology graphs, timeline, events and metrics-backed alerting cover containers and VMs together, with per-namespace usage and quota context for every team sharing the cluster.
| Orchestration layer | What AetherVirt manages |
|---|---|
| Compute | Deployments, Pods, StatefulSets, DaemonSets, Jobs and KubeVirt virtual machines |
| VM day-2 | Console access, snapshots, clone, migrations, backup and restore policies |
| Images | Golden images, flavors, templates and SSH key management |
| Accelerators | Node GPU views, MIG-aware allocation, AI workload templates |
| Storage | CSI capacity, PVC/PV management, IOPS and utilization charts |
| Network | Services, networks, firewall policies, Gateway API, MetalLB |
| Governance | RBAC with SSO or local auth, admission policy, full audit logging |
| Footprint | On-premises data centers, edge sites and cloud-hosted Kubernetes |
eHAWK DDoS is an automated DDoS protection platform that protects your network from attacks. Think of it as a smart security guard that watches all traffic coming into your network, automatically blocks threats, and gives you a clear dashboard to see what's happening in real time.
Automatic Detection & Blocking
Watches traffic 24/7 and blocks attacking IPs at the network level — no human required.
Early Warning Radar
A 30–120 second head-start before an attack saturates your links, with CRITICAL/HIGH/MEDIUM risk levels.
Live Traffic Dashboard
Real-time Gbps & pps, top attackers, attack-type breakdown, and country-level views.
AI Anomaly Detection
Learns your normal traffic, flags statistical anomalies, and classifies the attack type automatically.
BGP / RTBH Black-Hole
Advertises a black-hole route to your router automatically, stopping volumetric attacks before they arrive.
Threat Intelligence Feeds
Cross-checked against AbuseIPDB, VirusTotal, Shodan & GreyNoise, refreshed every 6 hours.
SLA Compliance Tracking
Time-to-Mitigation with average, P50, P95 & P99 response-time reporting.
Customer Portal
Scoped logins let you resell DDoS protection to your own clients with per-customer reporting.
Built for the operator whose customers are the ones under attack
An ISP has a harder problem than a single enterprise: the attack rarely targets you, it targets a prefix you announce — and it saturates your transit on the way there. eHAWK DDoS is built around that reality, with prefix-level ownership, upstream BGP mitigation, and per-customer reporting you can hand straight to the affected client. New to the concepts? Start with what DDoS protection actually involves.
Detection to black-hole, measured end to end
Stop it upstream, not at your edge
Filtering a volumetric flood after it has already crossed your transit link solves the wrong half of the problem. eHAWK DDoS advertises a black-hole route to your upstream router the moment an IP is blocked.
- BGP RTBH announced automatically on block, with one-click manual announce and withdraw
- Configurable AS number, peer AS, neighbor IP, next-hop and community string
- Route table view with automatic resync after a restart
- Effectiveness reporting: attacks stopped at the router versus at your server
- Bandwidth offloaded in Gbps — the number that justifies the RTBH build-out
Protected prefix management
Register the CIDRs you announce so the platform knows which prefixes belong to which customer. Any attack inside a registered prefix is linked to that customer automatically, with name, contact, SLA commitment and plan tier attached.
Multi-tenant customer portal
Each customer gets a scoped login showing only their own prefix, SLA uptime and recent incidents — no access to your internals, your other customers, or system configuration. Resell protection as a service without building the portal yourself.
SLA you can evidence
Time-to-Mitigation is recorded per event, with average, P50, P95 and P99 response times, a daily trend chart, and a breach table for anything that missed target. Configurable to 1, 2, 5, 10 or 15 minutes.
ASN campaign detection
Attackers are grouped by originating provider to expose shared infrastructure, flagging coordinated campaigns that span many IPs from one network — with a cross-matrix of attack types by provider.
Geo and threat intelligence
Feeds from Emerging Threats, Feodo Tracker, Blocklist.de, Spamhaus, CINS Score and TOR exit nodes, cross-checked against AbuseIPDB, VirusTotal, Shodan and GreyNoise. Smart GeoFence ranks which countries are worth blocking from your own last 30 days of attacks.
Fits your existing NOC
Email over your own SMTP with deduplication, webhooks to Slack, Microsoft Teams or PagerDuty, SIEM forwarding to Splunk, QRadar, Elastic or Graylog in CEF syslog, and Prometheus metrics for your Grafana dashboards.
| Operator concern | How eHAWK DDoS handles it |
|---|---|
| Transit saturation | BGP RTBH black-hole announced upstream automatically, before traffic reaches your edge |
| Prefix ownership | Registered CIDRs map every attack to the owning customer, with SLA tier and contact |
| Early warning | Radar scans every 12 seconds below block threshold, giving a 30–120 second head-start |
| False positives | Auto-threshold tuner analyses up to 90 days of your own traffic to recommend the right pps setting |
| Trusted peers | IP whitelist immune to all three block triggers — threshold, AI and threat intelligence |
| Repeat offenders | IPs blocked three or more times flagged as persistent threats, with ISP and country attribution |
| Customer reporting | Per-prefix 30-day attack reports, 14 report types, CSV and PDF, scheduled daily and weekly |
| Regional context | Live attack map plus 15+ South-East Asia and Indo-Pacific submarine cable systems with status |
Ready to put Hexalon software behind your infrastructure?
Talk to our team about a live walkthrough of AetherVirt or eHAWK DDoS on your own environment.