top of page

LABYRINTH in the CyberHive Matrix 2026: What the Evaluation Actually Shows

Aug 26
3 min read

The 2026 CyberHive Matrix places LABYRINTH in the European Leaders Area for Detection and Response (Products).

The Matrix evaluates cybersecurity solutions across two dimensions: User Experience and European Readiness. The 2026 edition also introduces the ECSO Cybersecurity Taxonomy and separates cybersecurity products from services, providing a more specific basis for comparing solutions.

LABYRINTH received a final score of 4.50/5, placing it among the European Leaders in the Detection and Response product category.



Advanced Deception Turns Attacker Interaction Into a Detection Signal


LABYRINTH uses simulated infrastructure to create targets that appear relevant to an attacker.

Its Points reproduce services, content, routers, devices and other elements of a real network environment. They are deployed as decoys across the infrastructure and can be adapted to the services and devices present in the environment.


The goal of Advanced Deception is to draw attackers toward controlled targets and expose their activity.


When an attacker interacts with a LABYRINTH decoy, the system captures details of that activity. The report highlights information such as the source of the threat, tools used, vulnerabilities exploited and attacker behaviour.

This creates a high-confidence signal based on attacker interaction rather than ordinary network activity.



How LABYRINTH Works Across the Environment


The LABYRINTH solution consists of four core components: Admin, Worker, Points and Seeder.

Admin provides centralized management, analysis and integration with third-party security systems. Workers provide the infrastructure for deploying Points across network segments and VLANs. Points are the deception units that reproduce services, devices, content and other elements of the environment. Seeder extends the detection surface by placing attractive artifacts across servers and workstations, creating additional paths toward LABYRINTH decoys.


Together, these components allow the Advanced Deception environment to reflect the structure of the network rather than relying on a single isolated decoy.



Built for Deployment and Scale


The CyberHive Matrix evaluation records strong results for LABYRINTH across deployment and scalability:

The report also describes LABYRINTH as available for on-premise Windows and Linux environments, with support for VMware, Hyper-V, Proxmox, Microsoft Azure, AWS and bare-metal deployments.


LABYRINTH supports deployment across IT, OT, Active Directory, and cloud environments, allowing Advanced Deception to be adapted to the infrastructure it is designed to protect..


For security teams, this provides flexibility when extending Advanced Deception across different parts of the infrastructure rather than limiting deployment to a single network segment.



European Readiness Is Part of the Evaluation


The CyberHive Matrix evaluates European Readiness alongside User Experience.


For LABYRINTH, the report records GDPR compliance, European headquarters, support for English, Polish and Ukrainian, and on-premise deployment options.


These characteristics are relevant for organizations evaluating cybersecurity technologies within European regulatory, procurement and operational environments. The report also identifies a subscription model based on the number of deployed Points, connecting the licensing model directly to the scale of the deception environment.



Where LABYRINTH Fits


LABYRINTH approaches detection from a different point in the attack.


Instead of relying only on activity against production assets, Advanced Deception introduces controlled targets into the environment and monitors interaction with them.


Because these interactions are designed to expose unauthorized activity, they can provide high-confidence signals and contextual evidence for investigation. LABYRINTH can also send this information to existing security systems, allowing deception-derived detections to become part of established detection and response workflows.


Advanced Deception therefore works as an additional detection layer alongside the security controls already in place.



What the Recognition Means


The CyberHive Matrix 2026 recognition reflects more than LABYRINTH's detection capabilities. It also recognizes the practical aspects of deploying and operating the solution, including user experience, scalability, documentation and European readiness.

We are proud to be recognised in the European Leaders Area for Detection and Response for the second consecutive year.


Thank you to the European Cyber Security Organisation and The Cyberhive EUROPE by ECSO for the work behind the 2026 Matrix, and to our customers and partners whose requirements continue to shape LABYRINTH.


The matrix gives us a point of reference. The real measure is what LABYRINTH helps security teams see, investigate and act on.


bottom of page