ClearSkies Active Defense
The Building Blocks of Deception
A deception layer is only as effective as the realism and the diversity of what it plants. Active Defense is built from two complementary primitives, deployed across the network segments where high-value assets reside.
Decoy Bundles and Beacon Trap Baits
| Decoy bundle | Event | Attack-vector intelligence captured |
|---|---|---|
| Reconnaissance | Port scanning, including NMAP NULL, OS, XMAS, FIN and SYN scans | Source address, destination address, ports scanned |
| Web access | An HTTP GET or a login attempt | Source address, path requested, submitted credentials, user agent |
| Database access | A MySQL or MSSQL authentication attempt | Source address, submitted credentials, for both Windows and mixed-mode authentication |
| Remote access | An RDP access attempt | Source address |
| File access | Access to a shared directory or file | Username and credentials, file name, host name, path, SMB version |
| File transfer | An FTP or TFTP access attempt | Source address, submitted credentials, file name, read or write action |
| Network access | A Telnet, SSH or SNMP access attempt | Source address, credentials, SSH client and server strings and keys, SNMP community and OID |
| Industrial, Modbus | A Modbus master or slave request | Source address, protocol, timestamp, Modbus function codes and binary commands |

How an Event Is Banded
Because interaction with a decoy or a trap is inherently anomalous, Active Defense does not face the false-positive problem of probabilistic detection. It still bands events by the strength of the intrusion signal, so the security operation can respond proportionately.
Confirmed intrusion
Authentication or data use against a decoy or a planted credential
A high-confidence alert fires with full attack-vector context and is sent to the engine, and to the customer's own SIEM where one is connected, for immediate response.
Active engagement
An interactive session on a high-interaction decoy, over RDP, SSH or Modbus
The session is engaged and recorded, to gather intelligence on methods and intent while the attacker is delayed.
Reconnaissance
Port scans and probing of decoy services
Logged and alerted with the source and the ports scanned, which places the intruder in the discovery phase.
Traceability
A directory listing, or a benign touch of a bait file
Recorded for forensic reconstruction and for behavioral context around the incident.
Intelligence gathering
Every trap interaction yields attack-vector intelligence: the source, the method, the purpose, and the exact data or service targeted. That supports forensic reconstruction and can help substantiate a legal case, without exposing a single real asset.
Active Defense does not act on what it finds. Every signal routes through the TDIR engine.

From Planted credential to contained intrusion
Follow a beacon trap through detection, correlation and response
02 / BEACON TRAP
The bait becomes a signal.
The attacker uses planted credentials to access a decoy database, triggering the beacon trap.
Technical questions
What stops a decoy from generating false alarms like everything else?
What does it catch that endpoint or network monitoring does not?
How is an attacker prevented from spotting the decoys?
Connect with the team
Book a demo
Have a question first
Talk to the team
