Threat Deception & Telemetry for Enterprise Networks
Place deception nodes near DMZ boundaries and internal networks to identify unauthorized scanning and lateral movement.
Exposed perimeters and internal lateral movement
Enterprise networks with hybrid cloud boundaries and exposed management ports face continuous automated scanning. Once perimeter access is gained, intruders attempt stealthy lateral movement across internal subnets.
Exposed management interfaces (SSH, RDP, HTTP) are targeted by automated scanners within minutes of exposure.
Security teams lack early-stage observation capabilities before attackers reach production databases.
Distinguishing background scanning from active lateral movement requires isolated interaction traps.
Deploying traps near exposed enterprise boundaries
DentiGrid places honeypot sensors across DMZ boundaries and internal subnets. Decoy services simulate common enterprise targets (SSH, RDP, HTTP APIs). Interaction with any decoy generates signed telemetry and threat intelligence feeds.
GATE sits at perimeter edge nodes to inspect HTTP/HTTPS traffic, validate request schemas, and enforce real-time IP blocklists generated from DentiGrid telemetry.
ENTERPRISE PERIMETER
|
v
GATE Edge Proxy
|
+--------------+--------------+
| |
v v
DMZ Deception Node Production App Server
(SSH / RDP / HTTP) (Protected)
|
v
DentiGrid Telemetry -> EDL Feed -> Enterprise FirewallSanitized Observation Telemetry — DMZ RDP Probe
Sensor: ent-dmz-node-04 Subnet: 10.20.4.0/24 (DMZ Segment) Timestamp: 2026-08-14T20:05:44Z Source IP: 198.51.100.109 Target: Mock RDP / Port 3389 Interaction: Connection attempt & TLS handshake Action: Telemetry signed (HMAC) -> Firewall EDL Feed Updated
From initial scan to firewall containment
A threat actor scans an enterprise IP range and attempts a connection to a DentiGrid RDP decoy.
The decoy sensor authenticates the event and sends signed telemetry to the processing gateway.
DentiGrid enriches the threat source details and updates the enterprise EDL feed.
Enterprise firewalls ingest the updated EDL to drop subsequent connection attempts from the threat source.
What your security team receives
Security Stack Integration
Dectrax operates alongside existing EDR, firewalls, and network monitoring tools as an active threat deception layer.
Why pay Dectrax if GATE is open source?
Enterprise teams can run GATE independently at network edges. Dectrax provides commercial platform management, DentiGrid deception node telemetry processing, EDL firewall feeds, and technical support SLAs.
Discuss your environment with our team
Consult directly with Dectrax security engineers to review deception node placement and edge proxy deployment specs for your network.
