Dectrax
CLOUD IAM & AWS

Deception & Telemetry for Cloud Workloads

Deploy honeypot endpoints and deceptive API traps inside cloud environments to detect hostile reconnaissance targeting cloud workloads.

Automated probing against public cloud boundaries

Public cloud deployments face continuous automated probing against exposed public IPs, API gateways, and cloud storage endpoints. Identifying malicious intent among legitimate cloud traffic requires verified interaction traps.

Automated bots scan cloud IP ranges for exposed management ports, unauthenticated storage, and API endpoints.

Security teams require verifiable threat intelligence to update AWS WAF rules and security groups dynamically.

Distinguishing routine cloud scans from targeted reconnaissance requires decoy endpoints isolated from production data.

Deception nodes inside cloud VPCs

DentiGridDeception & Intelligence

DentiGrid enables deployment of lightweight honeypot sensors within AWS VPCs. Interaction with decoy API routes or simulated cloud services produces authenticated telemetry and threat intelligence feeds.

GATEEdge Proxy Enforcement

GATE runs on edge worker networks (such as Cloudflare Workers) to inspect inbound HTTP API requests, validate schemas, and drop malicious traffic targeting cloud applications.

SYSTEM TOPOLOGY & DATA FLOW
                    PUBLIC INTERNET
                           |
                           v
                   GATE Edge Worker Proxy
                           |
            +--------------+--------------+
            |                             |
            v                             v
   Cloud VPC Decoy Node          Cloud Workload / API
   (Mock API / Honeytrap)            (Production)
            |
            v
   DentiGrid Telemetry -> EDL -> AWS WAF / Security Groups

Sanitized Observation Telemetry — AWS API Decoy Probe

Telemetry Observation Record
Sensor: aws-us-east-1-decoy-02
Location: AWS VPC Subnet (Isolated Decoy Tier)
Timestamp: 2026-08-14T23:10:02Z
Source IP: 203.0.113.195
Request: GET /api/v1/aws-config/keys
Response: Served harmless deceptive response
Action: Telemetry signed (HMAC) -> AWS WAF Blocklist Sync

From cloud decoy probe to WAF blocklist update

1

An attacker scans a cloud IP range and sends requests to a DentiGrid decoy API route.

2

The sensor records the interaction, serves a deceptive response, and logs HMAC-signed telemetry.

3

DentiGrid enriches the threat source IP and updates the dynamic blocklist.

4

AWS WAF or GATE edge proxies consume the updated blocklist to drop threat traffic automatically.

What your cloud security team receives

Cloud-native deception node deployment templates for AWS VPCs.
Integration guides for updating AWS WAF, Security Groups, and CloudWatch workflows.
Authenticated threat telemetry feeds for cloud SOC monitoring.
High-confidence threat alert feeds with zero internal false alarms.

Security Stack Integration

Dectrax complements cloud security tools like AWS GuardDuty, Security Hub, and WAF. It does not replace IAM permissions, CSPM tools, or AWS WAF.

COMMERCIAL POSITIONING

Commercial support for cloud deployments

GATE can be deployed as an open-source proxy on edge worker platforms. Commercial Dectrax contracts provide managed DentiGrid deception telemetry, threat intelligence feeds, and enterprise support.

Discuss your environment with our team

Consult directly with Dectrax security engineers to review deception node placement and edge proxy deployment specs for your network.