Supply Chain & Pipeline Deception Traps
Place decoy secrets and pipeline lures inside build environments to detect supply chain reconnaissance.
Supply chain targets in CI/CD pipelines
CI/CD pipelines are targeted by attackers seeking to harvest repository secrets and inject malicious build dependencies.
Malicious dependencies and compromised build runners scan environment variables for secret keys.
Identifying compromised build steps requires decoy honey-tokens embedded in pipeline configs.
Canary secrets inside build pipelines
DentiGrid generates canary secret tokens. If a compromised build runner attempts to utilize a canary token, DentiGrid receives the interaction and alerts the team.
GATE blocks requests attempting to use flagged canary keys against production API endpoints.
BUILD PIPELINE / SDLC +--------------------------+ | Canary Token Lure Asset | ---> Interaction Attempt ---> DentiGrid Intel ---> GATE Blocklist
From canary token access to pipeline isolation
A build script or malicious dependency accesses a canary secret token.
Token use triggers an immediate DentiGrid telemetry event.
Pipeline is automatically aborted and source IP is blocked at GATE.
What your DevOps team receives
Security Stack Integration
Complements GitHub Actions, GitLab CI, and container build security scanners.
Discuss your environment with our team
Consult directly with Dectrax security engineers to review deception node placement and edge proxy deployment specs for your network.
