ClearSkies Active Defense

The Building Blocks of Deception

A deception layer is only as effective as the realism and the diversity of what it plants. Active Defense is built from two complementary primitives, deployed across the network segments where high-value assets reside.

Decoy Bundles and Beacon Trap Baits

Decoy bundleEventAttack-vector intelligence captured
ReconnaissancePort scanning, including NMAP NULL, OS, XMAS, FIN and SYN scansSource address, destination address, ports scanned
Web accessAn HTTP GET or a login attemptSource address, path requested, submitted credentials, user agent
Database accessA MySQL or MSSQL authentication attemptSource address, submitted credentials, for both Windows and mixed-mode authentication
Remote accessAn RDP access attemptSource address
File accessAccess to a shared directory or fileUsername and credentials, file name, host name, path, SMB version
File transferAn FTP or TFTP access attemptSource address, submitted credentials, file name, read or write action
Network accessA Telnet, SSH or SNMP access attemptSource address, credentials, SSH client and server strings and keys, SNMP community and OID
Industrial, ModbusA Modbus master or slave requestSource address, protocol, timestamp, Modbus function codes and binary commands
Active Defense deception layer with decoy services, beacon traps, signal bands and the exchange with the TDIR engine.

How an Event Is Banded

Because interaction with a decoy or a trap is inherently anomalous, Active Defense does not face the false-positive problem of probabilistic detection. It still bands events by the strength of the intrusion signal, so the security operation can respond proportionately.

Confirmed intrusion

Authentication or data use against a decoy or a planted credential

A high-confidence alert fires with full attack-vector context and is sent to the engine, and to the customer's own SIEM where one is connected, for immediate response.

Active engagement

An interactive session on a high-interaction decoy, over RDP, SSH or Modbus

The session is engaged and recorded, to gather intelligence on methods and intent while the attacker is delayed.

Reconnaissance

Port scans and probing of decoy services

Logged and alerted with the source and the ports scanned, which places the intruder in the discovery phase.

Traceability

A directory listing, or a benign touch of a bait file

Recorded for forensic reconstruction and for behavioral context around the incident.

Intelligence gathering

Every trap interaction yields attack-vector intelligence: the source, the method, the purpose, and the exact data or service targeted. That supports forensic reconstruction and can help substantiate a legal case, without exposing a single real asset.

Active Defense does not act on what it finds. Every signal routes through the TDIR engine.

How the engine responds

Active Defense gathering attack-vector intelligence from a decoy service and server telemetry.

From Planted credential to contained intrusion

Follow a beacon trap through detection, correlation and response

Planted credentials
Decoy database

02 / BEACON TRAP

The bait becomes a signal.

The attacker uses planted credentials to access a decoy database, triggering the beacon trap.

ILLUSTRATIVE ATTACK SCENARIOActive Defense → Correlation → Playbook

Technical questions

What stops a decoy from generating false alarms like everything else?
A decoy has no legitimate use. No user, process or administrator has a reason to authenticate to it or to open a planted file, so an interaction is not evidence of risk, it is evidence of an intruder.
What does it catch that endpoint or network monitoring does not?
Activity that looks legitimate everywhere else: an attacker using valid stolen credentials, or performing reconnaissance that resembles administrative work. Those are ambiguous on a real asset and unambiguous on a decoy.
How is an attacker prevented from spotting the decoys?
Decoys impersonate genuine operating systems and applications and expose the same protocols and ports real services use, and the Modbus decoy presents a configurable device fingerprint. Realism and placement are reviewed as part of the ongoing optimization service in section 9.

Connect with the team

Book a demo
A ClearSkies analyst reviewing deception-layer activity

Have a question first

Talk to the team
The deception layer across network segments