ClearSkies Active Defense
Coverage
Active Defense secures the interior of the network, which is the ground an attacker must cross once prevention has been bypassed.
The same layer extends into operational technology and industrial control environments.
Decoys and beacon traps
Decoys
- Reconnaissance
- Web access
- Database access
- Remote access
- File access
- File transfer
- Network access
- Industrial, Modbus
Beacon traps
- Documents in many formats
- Planted login credentials
- Database credentials
- Shared directories and files
- High-value bait
The defining property of deception. The difference between a decoy or a beacon trap and a real asset is that legitimate users have no reason to access it. Any access is therefore, by itself, an indication of malicious activity.
Two routes into the deception layer
Decoys
High-interaction and medium-interaction decoys look and behave exactly like a real information asset. They impersonate genuine operating systems and business applications, and expose open ports on the same protocols real services use. That makes it close to impossible for a threat actor to tell a decoy from a real asset, which lures the intruder onto the wrong path and reveals both presence and intent.
- TCP
- UDP
- SMB
- HTTP
- HTTPS
- RDP
- FTP
- TFTP
- MySQL
- MSSQL
- Telnet
- Modbus
- SSH
- SNMP
Beacon traps
Beacon traps use fake information and poisoned data as bait, planted strategically among real data to catch unauthorized access early. Any attempt to copy, access, modify or use planted data triggers an alert immediately, whereas the same action against real data would pass unnoticed.
What is planted as bait
More than one trap can be enabled on the same workstation or server. Every alert carries its own context: the trap type, the event triggered, the host address, the username, the service and the timestamp.
- Documents containing fake network designs, systems information, addresses in use and business-application details.
- Planted login credentials for HTTP, FTP, SSH, SNMP, RDP, TFTP and Telnet services.
- Database credentials for MySQL and MSSQL authentication.
- Shared directories and files staged to be discovered and accessed.
- High-value bait such as financial data, personal data and intellectual property.
Contractor, supplier and third-party devices
Internal exposure extends to contractor devices, managed-service systems and third-party software. Because decoys and beacon traps sit on the internal network rather than on managed hosts, they catch a compromised vendor device or an abused supplier account the moment it begins to explore.
Virtualization environments and sizing
| Resource | Active Defense 10 | Active Defense 20 | Active Defense 40 |
|---|---|---|---|
| Supported decoy bundles | Up to 10 | Up to 20 | Up to 40 |
| Hypervisor | VMware or Hyper-V | VMware or Hyper-V | VMware or Hyper-V |
| Supported version | 5.1 and above, or 5.0 and above | 6.0 and above, or 5.0 and above | 6.0 and above, or 5.0 and above |
| Virtual CPUs | 2, with 6 cores | 4, with 6 cores | 4, with 8 cores |
| Management interfaces | 1 | 1 | 1 |
| Virtual memory | 8 GB | 12 GB | 24 GB |
| Virtual storage | 150 GB | 250 GB | 400 GB |
Sizing describes capacity rather than price.
Every finding consolidates into the same record as the rest of the detections, mapped to MITRE ATT&CK and scored the same way, with no separate console to maintain.
What Active Defense does not do
The scope is worth stating plainly, because a deception layer is easy to over-claim.
- Active Defense does not prevent an intrusion: it assumes one and catches it early.
- It does not replace prevention, endpoint or network monitoring, or reduce the need for them.
- It holds no production data and runs no production service, so it protects nothing directly.
- It does not act on other add-ons' findings: every signal routes through the TDIR engine.
Connect with the team
Book a demo
Have a question first
Talk to the team
