Hexalon Technologies Pvt. Ltd.

Enterprise Kubernetes & Cybersecurity Software for Regulated Infrastructure

Hexalon Technologies builds enterprise infrastructure software for Kubernetes management and virtualization, GPU workloads, and automated DDoS protection — across on-premises, edge and cloud environments.

Multi-cluster Kubernetes control plane 24/7 automated DDoS protection On-prem · Edge · Cloud
2Flagship products
28eHAWK DDoS capabilities
24/7Automated defence & monitoring
50K+Known-bad IPs checked live
Our Products

Two platforms. One standard of engineering.

AetherVirt is a Kubernetes management platform that gives platform teams a single control plane for containers, virtual machines and GPU workloads. eHAWK DDoS is a DDoS protection platform that gives network operators automated, network-level defence against attacks. Both are built for auditability, scale, and day-one operational clarity.

AetherVirt Kubernetes platform details →

AetherVirt is a Kubernetes management platform that unifies day-2 operations for platform teams — cluster health, KubeVirt virtualization, GPU workloads, storage, networking, and security — into a single, auditable console built for regulated, enterprise-scale environments.

Multi-cluster Containers + KubeVirt VMs GPU-aware RBAC & audit-ready On-prem · Edge · Cloud
12+Platform capability areas
1Console for containers & VMs
3Deployment targets

Unify operations

Manage Deployments, Pods, Jobs, StatefulSets, and KubeVirt VMs from one console — no tool-switching.

See everything, instantly

Cluster health, topology, capacity, and security posture are visible the moment you log in.

Operate with confidence

RBAC-backed, audited actions across GPUs, storage, and networking reduce operational risk.

  • Multi-cluster inventory — health, capacity, node roles
  • Virtualization — KubeVirt VMs, images, flavors, migrations
  • GPU & AI — MIG-aware allocation, AI workload templates
  • Storage insight — CSI capacity, PVC/PV, IOPS charts
  • Networking — Services, Gateway API, MetalLB, firewall policy
  • Security — RBAC, admission policy, vulnerability scanning
  • Runtime security — eBPF policies, alerts, investigations
  • Governance — full audit logging, permission-aware UI
Explore the AetherVirt Kubernetes management platform →
Kubernetes virtualization

Run virtual machines the same way you run containers

Most teams end up maintaining two stacks: one for cloud-native workloads, another for the VMs the business still depends on — each with its own console, its own access model, and its own blind spots. AetherVirt collapses that divide by treating KubeVirt virtual machines as first-class Kubernetes objects: same namespaces, same RBAC, same observability, same audit trail. See when to choose a VM over a container for the full comparison.

Full VM lifecycle, orchestrated

Every VM operation is a permission-checked, tracked action in the control plane — not an SSH session on a hypervisor.

  • Create, clone, snapshot, migrate and restore, with built-in progress tracking
  • Golden images and flavors, so every new VM starts from an approved baseline
  • Templates, SSH key management and in-browser console access
  • Backup and restore policies applied per VM, not per hypervisor
  • Migrations handled as a tracked, first-class operation
Cluster Dashboard

Containers and VMs sharing one inventory

Clusters4
Nodes ready3/3
Namespaces49
Pods459
CPU avail5.72c
Memory avail57.3 GiB

Scheduling and placement

VMs are scheduled by Kubernetes itself, so node roles, capacity and readiness govern placement exactly as they do for pods — with HPA/VPA workflows available for the services around them.

GPU-aware orchestration

Node-level GPU visibility and MIG-aware allocation let accelerated workloads and AI workload templates land on the right hardware, instead of being hand-placed by an operator.

Storage that follows the VM

CSI-backed PVC/PV management with real capacity, IOPS and utilization data — so storage pressure shows up as a trend long before it becomes an incident.

One access model

RBAC with SSO or local authentication governs container and VM actions alike. A permission-aware UI hides what an operator cannot do, and every action lands in the audit log.

Networking as policy

Services, networks, firewall policies, Gateway API and MetalLB are configured from the same console, so VM connectivity stops being a separate change request.

Observability across both

Topology graphs, timeline, events and metrics-backed alerting cover containers and VMs together, with per-namespace usage and quota context for every team sharing the cluster.

Orchestration layerWhat AetherVirt manages
ComputeDeployments, Pods, StatefulSets, DaemonSets, Jobs and KubeVirt virtual machines
VM day-2Console access, snapshots, clone, migrations, backup and restore policies
ImagesGolden images, flavors, templates and SSH key management
AcceleratorsNode GPU views, MIG-aware allocation, AI workload templates
StorageCSI capacity, PVC/PV management, IOPS and utilization charts
NetworkServices, networks, firewall policies, Gateway API, MetalLB
GovernanceRBAC with SSO or local auth, admission policy, full audit logging
FootprintOn-premises data centers, edge sites and cloud-hosted Kubernetes
Explore all platform capabilities →
eHAWK DDoS protection details →

eHAWK DDoS is an automated DDoS protection platform that protects your network from attacks. Think of it as a smart security guard that watches all traffic coming into your network, automatically blocks threats, and gives you a clear dashboard to see what's happening in real time.

28 capabilities 24/7 automated defence AI anomaly detection BGP RTBH black-hole
30–120sPre-attack warning window
50K+Known-bad IPs monitored
14Report types with PDF/CSV export

Automatic Detection & Blocking

Watches traffic 24/7 and blocks attacking IPs at the network level — no human required.

Early Warning Radar

A 30–120 second head-start before an attack saturates your links, with CRITICAL/HIGH/MEDIUM risk levels.

Live Traffic Dashboard

Real-time Gbps & pps, top attackers, attack-type breakdown, and country-level views.

AI Anomaly Detection

Learns your normal traffic, flags statistical anomalies, and classifies the attack type automatically.

BGP / RTBH Black-Hole

Advertises a black-hole route to your router automatically, stopping volumetric attacks before they arrive.

Threat Intelligence Feeds

Cross-checked against AbuseIPDB, VirusTotal, Shodan & GreyNoise, refreshed every 6 hours.

SLA Compliance Tracking

Time-to-Mitigation with average, P50, P95 & P99 response-time reporting.

Customer Portal

Scoped logins let you resell DDoS protection to your own clients with per-customer reporting.

See all 28 eHAWK DDoS capabilities →
DDoS protection for ISPs & network operators

Built for the operator whose customers are the ones under attack

An ISP has a harder problem than a single enterprise: the attack rarely targets you, it targets a prefix you announce — and it saturates your transit on the way there. eHAWK DDoS is built around that reality, with prefix-level ownership, upstream BGP mitigation, and per-customer reporting you can hand straight to the affected client. New to the concepts? Start with what DDoS protection actually involves.

Mitigation posture

Detection to black-hole, measured end to end

Warning window30–120s
Radar scan12s
Known-bad IPs50K+
Intel refresh6h
SLA targets1–15m
Report types14

Stop it upstream, not at your edge

Filtering a volumetric flood after it has already crossed your transit link solves the wrong half of the problem. eHAWK DDoS advertises a black-hole route to your upstream router the moment an IP is blocked.

  • BGP RTBH announced automatically on block, with one-click manual announce and withdraw
  • Configurable AS number, peer AS, neighbor IP, next-hop and community string
  • Route table view with automatic resync after a restart
  • Effectiveness reporting: attacks stopped at the router versus at your server
  • Bandwidth offloaded in Gbps — the number that justifies the RTBH build-out

Protected prefix management

Register the CIDRs you announce so the platform knows which prefixes belong to which customer. Any attack inside a registered prefix is linked to that customer automatically, with name, contact, SLA commitment and plan tier attached.

Multi-tenant customer portal

Each customer gets a scoped login showing only their own prefix, SLA uptime and recent incidents — no access to your internals, your other customers, or system configuration. Resell protection as a service without building the portal yourself.

SLA you can evidence

Time-to-Mitigation is recorded per event, with average, P50, P95 and P99 response times, a daily trend chart, and a breach table for anything that missed target. Configurable to 1, 2, 5, 10 or 15 minutes.

ASN campaign detection

Attackers are grouped by originating provider to expose shared infrastructure, flagging coordinated campaigns that span many IPs from one network — with a cross-matrix of attack types by provider.

Geo and threat intelligence

Feeds from Emerging Threats, Feodo Tracker, Blocklist.de, Spamhaus, CINS Score and TOR exit nodes, cross-checked against AbuseIPDB, VirusTotal, Shodan and GreyNoise. Smart GeoFence ranks which countries are worth blocking from your own last 30 days of attacks.

Fits your existing NOC

Email over your own SMTP with deduplication, webhooks to Slack, Microsoft Teams or PagerDuty, SIEM forwarding to Splunk, QRadar, Elastic or Graylog in CEF syslog, and Prometheus metrics for your Grafana dashboards.

Operator concernHow eHAWK DDoS handles it
Transit saturationBGP RTBH black-hole announced upstream automatically, before traffic reaches your edge
Prefix ownershipRegistered CIDRs map every attack to the owning customer, with SLA tier and contact
Early warningRadar scans every 12 seconds below block threshold, giving a 30–120 second head-start
False positivesAuto-threshold tuner analyses up to 90 days of your own traffic to recommend the right pps setting
Trusted peersIP whitelist immune to all three block triggers — threshold, AI and threat intelligence
Repeat offendersIPs blocked three or more times flagged as persistent threats, with ISP and country attribution
Customer reportingPer-prefix 30-day attack reports, 14 report types, CSV and PDF, scheduled daily and weekly
Regional contextLive attack map plus 15+ South-East Asia and Indo-Pacific submarine cable systems with status
See all 28 eHAWK DDoS capabilities →
Get started

Ready to put Hexalon software behind your infrastructure?

Talk to our team about a live walkthrough of AetherVirt or eHAWK DDoS on your own environment.