Detection and monitoring EU-developed

CounterCraft The Platform

Deception platform that deploys realistic decoy assets, records adversary interaction, and enriches resulting alerts with indicators and attack-technique context.

By CounterCraft · Spain

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
CounterCraft
Recorded country
Spain
Product model
Commercial
Deployment
Self-hosted
Software license
Proprietary
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

CounterCraft's founders identify San Sebastián, Spain, as their research-and-development headquarters; group entities also operate in the US and UK.

Reported capabilities

  • Deploys decoy systems that mirror production assets.
  • Records interactions and adds indicator, TTP and MITRE ATT&CK context.
  • Product terms grant a limited license to access, install and deploy where applicable.

Scope and limits

The public product page says cloud and hybrid environments are supported, but it does not establish that the management console is vendor-hosted SaaS. US and UK group entities exist; ultimate control and data residency require review.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    CounterCraft describes decoys/digital twins, real-time interaction data, enriched TTP/IoC context, and on-premises/cloud/hybrid configurations; the page does not establish SaaS tenancy.

    Read source
  2. origin / country

    Founders' signed 23 December 2021 letter locates the company's R&D headquarters in San Sebastián, Spain, and says they built the deception platform.

    Read source
  3. license / deployment

    Sales terms define CounterCraft S.L., Inc. and Ltd. group entities, grant a nonexclusive, nontransferable limited-term license to access/install/deploy, prohibit copying and reverse engineering, and retain product IP.

    Read source
  4. deployment

    Government solution page describes on-premises/air-gapped use of the platform without external connectivity; supports Self-hosted classification.

    Read source
  5. maintenance

    Vendor's 2019 platform article carries an editorial July 2026 update explicitly discussing continued MSSP use. This is active commercial commentary, not a dated code release.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection