---
title: Voidhawk | Turn the Attack Around | ZioSec
description: Packet-level visibility, campaign detection, and response for adaptive attacks on apps and APIs. Block threats or send actionable evidence to your SOC.
url: https://ziosec.com/voidhawk
---

# Voidhawk: Turn the attack around.

Visibility, detection, and response for adaptive attacks. Voidhawk inspects traffic between your applications and APIs, connecting signals across IPs, sessions, and time. Detect campaigns that isolated requests conceal, then block malicious traffic or investigate with evidence in your SOC.

Voidhawk is in active development. ZioSec is selecting a small number of design partners.

[Discuss a design partnership](/contact?intent=voidhawk) | [Explore deployment](/voidhawk/deployment)

## See the whole flow. Expose the campaign.

Voidhawk follows how an attack unfolds, even when attackers rotate infrastructure, change tactics, or make each request look harmless in isolation.

1. **Packet-level evidence.** Packet-level visibility between your apps and APIs exposes request and response payloads, protocol behavior, and interactions across entire flows. This exposes attack signals conventional logs often omit, giving defenders evidence they would not otherwise have.
2. **Campaign context.** Correlate signals across IP addresses, sessions, and time to identify coordinated campaigns, including activity that looks harmless when each request or IP is examined alone.
3. **Line-speed detection.** The detection engine is designed for line-speed analysis, using specialized analyzers, heuristics, and lightweight models to flag suspicious activity. Complex patterns receive deeper AI investigation while fast-path inspection continues.
4. **Response on your terms.** Findings can drive real-time blocking or feed actionable signals and supporting evidence into existing SOC workflows, including AI SOC platforms. Visibility and investigation value do not depend on blocking traffic.

### Choose your inspection mode

Visibility and blocking depend on how Voidhawk connects.

- **Mirror mode:** observes request copies only. Cannot block traffic.
- **Full visibility without blocking:** inspect requests and responses with ext_proc and every rule in dry-run.

[Compare deployment modes](/voidhawk/deployment#attachment-modes)

### Traffic and attack coverage

Web applications, APIs, and networked AI agents. Protocols include gRPC, WebSocket, MCP, and JSON-RPC.

Coverage also includes conventional Layer 7 attacks, such as injection and cross-site scripting. Available inspection depends on the deployment mode.

## Let traffic flow. Make attackers wait.

**99.9% passes in under 5ms.** Clear traffic continues to your applications.

**0.1% escalates for analysis and triage.** Suspicious traffic is analyzed for intent across applications, APIs, and infrastructure. Complex patterns receive deeper AI investigation while fast-path inspection continues. Cleared traffic is allowed through.

**Malicious intent triggers disruption.** Only traffic deemed malicious brings in ZioSec attack models to disrupt the attack.

This is an inline response example. Findings can also support investigation in existing SOC workflows without blocking. Mirror mode observes request copies only.

## Evidence your SOC can act on.

Send actionable findings and supporting evidence into existing SOC workflows, including AI SOC platforms. Voidhawk provides visibility and investigation value even when you choose not to block traffic.

Structured verdicts explain decisions in words. Activity can be grouped by endpoint, field, identity, and cohort. Development previews show a statement of record and an entities-by-intent investigation view.

- [Statement of record interface example](/images/voidhawk/statement-of-record.png)
- [Entities by intent interface example](/images/voidhawk/entities-by-intent.png)
- JSON verdicts flow into the existing log pipeline.
- A query API supports investigation and dry-run review.
- Optional PostgreSQL supports durable history.

## The attacker is an agent, too.

ZioSec builds agents that uncover how AI systems fail. Voidhawk puts that knowledge to work against the agents attacking your systems.

1. **Train:** offensive agents challenge Voidhawk with adversarial strategies, training and validating its defenses.
2. **Reason:** offensive models help reason about attacker objectives, action sequences, and weaknesses.
3. **Disrupt:** apply that understanding to malicious agentic traffic interacting with your defended systems.

[Explore AI Red Teaming Platform](/ai-red-teaming) | [The ZioSec approach](/approach)

## Your cluster or our hosted edge

### Self-hosted Kubernetes

A Helm chart installs Voidhawk into one namespace. Request data and per-endpoint calibration stay in your infrastructure. Requires Kubernetes 1.27+ and GPU inference nodes. Attach through ext_proc, mirrored requests, or TLS passthrough. Pull signed detection updates on your schedule.

### Hosted edge

Point your CDN's origin to the Voidhawk edge. ZioSec inspects and forwards traffic to your origin. Request data is processed in ZioSec infrastructure. Nothing installs in your cluster. Forward the client address and a JA4 fingerprint header; configure your origin to accept only Voidhawk egress ranges. The edge has full request and response signal and can refuse requests.

### Observation is not the same as full signal

Mirror mode observes request copies without enforcing. It cannot see responses, refuse requests, or run response-based credential-stuffing, enumeration, reflection, or leak detection. For full request and response signal without blocking, use ext_proc with every rule in dry-run. TLS passthrough provides full signal and enforcement but moves Layer 7 responsibility to Voidhawk for the delegated hostnames.

[Compare deployment modes](/voidhawk/deployment#attachment-modes)

## Practical questions

### What does Voidhawk protect?

Connected applications, APIs, and AI agents against adaptive attackers. Defensive action happens in traffic interacting with your protected environment.

### Does every request need AI inference?

No. The detection engine is designed for line-speed analysis with specialized analyzers, heuristics, and lightweight models. Complex patterns escalate for deeper AI investigation while fast-path inspection continues.

### Can we use Voidhawk without blocking traffic?

Yes. Use findings and supporting evidence for investigation in your existing SOC, including AI SOC platforms. Mirroring scores request copies without enforcing, but does not receive responses. For full request and response signal without blocking, use ext_proc with every rule in dry-run.

### Where is our traffic processed?

In a self-hosted deployment, request data and application calibration stay in your infrastructure. With the hosted edge, traffic is processed in ZioSec's infrastructure before it is forwarded to your origin.

### How can we try Voidhawk?

Voidhawk is in active development and ZioSec is selecting a small group of design partners. Scope a real environment, run authorized adversarial challenges, and review the results together.

## What a design partnership looks like

1. Scope a real environment and choose mirror mode or an appropriate dry-run path.
2. ZioSec brings offensive agents to test the agreed environment and evaluate the signals Voidhawk sees.
3. Review the evidence together. Use findings in your SOC, then choose whether to enable enforcement through an agreed rollout.

[Discuss a design partnership](/contact?intent=voidhawk)
