Deception & Telemetry for Cloud Workloads
Deploy honeypot endpoints and deceptive API traps inside cloud environments to detect hostile reconnaissance targeting cloud workloads.
Automated probing against public cloud boundaries
Public cloud deployments face continuous automated probing against exposed public IPs, API gateways, and cloud storage endpoints. Identifying malicious intent among legitimate cloud traffic requires verified interaction traps.
Automated bots scan cloud IP ranges for exposed management ports, unauthenticated storage, and API endpoints.
Security teams require verifiable threat intelligence to update AWS WAF rules and security groups dynamically.
Distinguishing routine cloud scans from targeted reconnaissance requires decoy endpoints isolated from production data.
Deception nodes inside cloud VPCs
DentiGrid enables deployment of lightweight honeypot sensors within AWS VPCs. Interaction with decoy API routes or simulated cloud services produces authenticated telemetry and threat intelligence feeds.
GATE runs on edge worker networks (such as Cloudflare Workers) to inspect inbound HTTP API requests, validate schemas, and drop malicious traffic targeting cloud applications.
PUBLIC INTERNET
|
v
GATE Edge Worker Proxy
|
+--------------+--------------+
| |
v v
Cloud VPC Decoy Node Cloud Workload / API
(Mock API / Honeytrap) (Production)
|
v
DentiGrid Telemetry -> EDL -> AWS WAF / Security GroupsSanitized Observation Telemetry — AWS API Decoy Probe
Sensor: aws-us-east-1-decoy-02 Location: AWS VPC Subnet (Isolated Decoy Tier) Timestamp: 2026-08-14T23:10:02Z Source IP: 203.0.113.195 Request: GET /api/v1/aws-config/keys Response: Served harmless deceptive response Action: Telemetry signed (HMAC) -> AWS WAF Blocklist Sync
From cloud decoy probe to WAF blocklist update
An attacker scans a cloud IP range and sends requests to a DentiGrid decoy API route.
The sensor records the interaction, serves a deceptive response, and logs HMAC-signed telemetry.
DentiGrid enriches the threat source IP and updates the dynamic blocklist.
AWS WAF or GATE edge proxies consume the updated blocklist to drop threat traffic automatically.
What your cloud security team receives
Security Stack Integration
Dectrax complements cloud security tools like AWS GuardDuty, Security Hub, and WAF. It does not replace IAM permissions, CSPM tools, or AWS WAF.
Commercial support for cloud deployments
GATE can be deployed as an open-source proxy on edge worker platforms. Commercial Dectrax contracts provide managed DentiGrid deception telemetry, threat intelligence feeds, and enterprise support.
Discuss your environment with our team
Consult directly with Dectrax security engineers to review deception node placement and edge proxy deployment specs for your network.
