Stop Malware —
before it calls home.
Detect silent, periodic check-ins signalling a compromised device. The threats your antivirus never sees.
Your Antivirus Won't Catch This
Modern malware rarely announces itself. Instead, it installs silently, then reaches out to its operator via short, regular, encrypted messages — beacons. Once a live command channel is confirmed, attackers push further: lateral movement, data exfiltration, ransomware deployment.
Traditional defences inspect files and signatures. Beacons don't look like malware. They look like background traffic — which is exactly the point.
Behavioural Network Monitoring
Beacon Butty sits between your LAN and the internet, tracking and scoring every connection — without any packets being blocked or delayed. Zero impact on your network performance.
Rather than matching against known-bad signatures, it measures behaviour: connection regularity, consistent payload sizes, unusual destination profiles. These statistical patterns survive encryption and obfuscation.
Inside Beacon Butty
Real-time visibility across every layer of detection — from beacon scores to asset inventory to IDS alerts.
A Five-Layer Detection Pipeline
Best-in-class open source components, orchestrated into a single appliance.
Zeek monitors all LAN traffic on the internal interface — passively, with zero impact on throughput. Every TCP/UDP connection is logged with full metadata: timestamps, bytes transferred, connection state, and duration.
Hourly, RITA imports Zeek connection data and runs statistical analysis per source/destination pair, scoring each on four axes: connection periodicity, inter-arrival jitter, consistent byte size, and connection duration.
Beacon scores, connection records, and alert history are stored in a columnar time-series database on NVMe SSD. Sub-millisecond queries across weeks of data allow the dashboard to serve results instantly, even on constrained hardware.
Suricata runs concurrently, applying thousands of community and commercial ruleset signatures against live traffic. Alerts are correlated back to the asset inventory via MAC address and IP — so you always know which device triggered which rule.
A Flask web application provides real-time visibility across all detection layers. A daily 07:00 report summarises top beaconing hosts. Alerts fire within minutes of a high-confidence detection to your chosen channel (Slack, email, SMS etc.), with configurable thresholds and suppression windows.
What Beacon Butty Catches
Six categories of threat, detected continuously — 24 hours a day, 7 days a week.
Prioritised, Intelligent Alerting
Not every event is equally urgent. Beacon Butty grades alerts so you know what to act on immediately.
- Beacon score ≥ 0.95
- Persistent strobe traffic
- Threat intel match
- Tor exit node contact
- Suricata P1 rule
- Service down (Zeek / ClickHouse / Suricata)
- WAN unreachable
- Disk > 90% full
- New device on LAN
- Health check failure
- Beacon score 0.80–0.94
- High DNS volume host
- Suricata P2/P3 alerts
- Firewall policy change
- Daily summary digest
Built for Small Business and Home Networks
Beacon Butty is designed for networks that matter but don't have a full security operations team behind them — small businesses, professional home offices, and anyone who handles sensitive data and wants to know if something is quietly phoning home.
It is a combined hardware and software solution. The appliance must be physically placed on your network and configured to match your specific environment — this is not software you download and install yourself.
Enterprise-grade threat detection technology, sized and priced for organisations without enterprise budgets.
How it works
- 1 We scope your networkA short discovery call to understand your setup — number of devices, internet connection, and physical access for installation.
- 2 On-site installationA Mustard Research consultant visits to install and configure the appliance. Beacon Butty requires physical placement between your router and LAN — not something that can be done remotely.
- 3 Monitoring beginsFrom the moment it's live, Beacon Butty is watching. Alerts land in your Slack workspace. A daily digest arrives each morning.
- 4 Ongoing supportWe handle ruleset updates and are on hand if an alert needs expert interpretation.
Ready to see what's on your network?
Get in touch to discuss your setup. We'll let you know if Beacon Butty is a good fit and talk through the installation process.