Dectrax
ENTERPRISE INFRASTRUCTURE

Threat Deception & Telemetry for Enterprise Networks

Place deception nodes near DMZ boundaries and internal networks to identify unauthorized scanning and lateral movement.

Exposed perimeters and internal lateral movement

Enterprise networks with hybrid cloud boundaries and exposed management ports face continuous automated scanning. Once perimeter access is gained, intruders attempt stealthy lateral movement across internal subnets.

Exposed management interfaces (SSH, RDP, HTTP) are targeted by automated scanners within minutes of exposure.

Security teams lack early-stage observation capabilities before attackers reach production databases.

Distinguishing background scanning from active lateral movement requires isolated interaction traps.

Deploying traps near exposed enterprise boundaries

DentiGridDeception & Intelligence

DentiGrid places honeypot sensors across DMZ boundaries and internal subnets. Decoy services simulate common enterprise targets (SSH, RDP, HTTP APIs). Interaction with any decoy generates signed telemetry and threat intelligence feeds.

GATEEdge Proxy Enforcement

GATE sits at perimeter edge nodes to inspect HTTP/HTTPS traffic, validate request schemas, and enforce real-time IP blocklists generated from DentiGrid telemetry.

SYSTEM TOPOLOGY & DATA FLOW
                  ENTERPRISE PERIMETER
                            |
                            v
                    GATE Edge Proxy
                            |
             +--------------+--------------+
             |                             |
             v                             v
     DMZ Deception Node           Production App Server
     (SSH / RDP / HTTP)                (Protected)
             |
             v
   DentiGrid Telemetry -> EDL Feed -> Enterprise Firewall

Sanitized Observation Telemetry — DMZ RDP Probe

Telemetry Observation Record
Sensor: ent-dmz-node-04
Subnet: 10.20.4.0/24 (DMZ Segment)
Timestamp: 2026-08-14T20:05:44Z
Source IP: 198.51.100.109
Target: Mock RDP / Port 3389
Interaction: Connection attempt & TLS handshake
Action: Telemetry signed (HMAC) -> Firewall EDL Feed Updated

From initial scan to firewall containment

1

A threat actor scans an enterprise IP range and attempts a connection to a DentiGrid RDP decoy.

2

The decoy sensor authenticates the event and sends signed telemetry to the processing gateway.

3

DentiGrid enriches the threat source details and updates the enterprise EDL feed.

4

Enterprise firewalls ingest the updated EDL to drop subsequent connection attempts from the threat source.

What your security team receives

Deception sensor deployment models for Linux, Docker, and cloud subnets.
Exportable EDL feeds compatible with Palo Alto, Fortinet, and Cisco firewalls.
Centralized telemetry logging with HMAC replay protection.
Dedicated architecture reviews with Dectrax security engineers.

Security Stack Integration

Dectrax operates alongside existing EDR, firewalls, and network monitoring tools as an active threat deception layer.

COMMERCIAL POSITIONING

Why pay Dectrax if GATE is open source?

Enterprise teams can run GATE independently at network edges. Dectrax provides commercial platform management, DentiGrid deception node telemetry processing, EDL firewall feeds, and technical support SLAs.

Discuss your environment with our team

Consult directly with Dectrax security engineers to review deception node placement and edge proxy deployment specs for your network.