Dectrax
FINANCIAL SERVICES & FINTECH

Threat Deception & Telemetry for Financial Platforms

Deploy decoy endpoints across financial subnets to capture early-stage scanning, SSH brute-forcing, and credential probing before core payment systems are targeted.

Where financial infrastructure is targeted

Financial systems, payment gateways, and banking APIs operate under continuous automated reconnaissance. Threat actors scan perimeter boundaries daily to identify exposed management ports, unpatched microservices, or misconfigured API endpoints.

Automated bot networks probe public IP ranges for exposed SSH, RDP, and HTTP administration portals.

High background internet noise makes it difficult for security teams to distinguish routine port scans from targeted reconnaissance.

Traditional security tools trigger thousands of unverified alerts, straining SOC analysts during active incident response.

How DentiGrid observes probing in payment networks

DentiGridDeception & Intelligence

DentiGrid places decoy honeypot nodes near financial DMZ boundaries. When an attacker probes a decoy endpoint, DentiGrid authenticates the interaction using HMAC-SHA256 timestamping, records the source telemetry, and exports an External Dynamic List (EDL) feed.

GATEEdge Proxy Enforcement

GATE operates as an edge reverse proxy in front of web APIs. It inspects inbound requests, validates JSON schemas against defined specifications, and blocks malicious traffic patterns before requests reach payment microservices.

SYSTEM TOPOLOGY & DATA FLOW
                 INTERNET / EXTERNAL TRAFFIC
                            |
                            v
                  GATE Edge Proxy (WAF / Schema Rules)
                            |
             +--------------+--------------+
             |                             |
             v                             v
     DentiGrid Decoy Node          Production Payment API
     (Mock Management Trap)           (Protected Origin)
             |
             v
   Authenticated Telemetry (HMAC-SHA256)
             |
             v
   DentiGrid Threat Intelligence Feed -> Perimeter Firewall Blocklist (EDL)

Sanitized Observation Telemetry — DMZ SSH Probe

Telemetry Observation Record
Sensor: dmz-fin-node-east-01
Timestamp: 2026-08-14T21:40:12Z
Source IP: 198.51.100.44 [AS393577]
Protocol: SSH / OpenSSH 8.9p1
Interaction: Password spraying against decoy user 'admin_fin'
Telemetry Status: HMAC-SHA256 Verified
Action: Source IP exported to DentiGrid EDL Feed

From detection to perimeter enforcement

1

An attacker scans an enterprise IP range and probes a DentiGrid SSH decoy node.

2

The decoy node authenticates the interaction and sends signed HMAC telemetry to the ingestion gateway.

3

DentiGrid enriches the threat telemetry and updates the exportable External Dynamic List (EDL).

4

Perimeter firewalls and GATE edge proxies consume the EDL to drop subsequent connection attempts from the threat source.

What your engineering team receives

Pre-configured decoy node deployment templates for Linux and cloud subnets.
Exportable External Dynamic Lists (EDL) for Palo Alto, Fortinet, and Cisco firewalls.
Centralized telemetry audit logs with HMAC-SHA256 replay verification.
Direct architecture reviews with Dectrax security engineers.

Security Stack Integration

Dectrax complements your existing SIEM, EDR, WAF, and identity controls. It does not replace core banking engines, perimeter firewalls, or identity providers.

COMMERCIAL POSITIONING

Why pay Dectrax if GATE is open source?

GATE is an open-source edge proxy that can be deployed independently. Dectrax provides commercial value through DentiGrid deception node deployment, managed telemetry enrichment pipelines, multi-tenant portal workflows, EDL firewall feeds, and operational support.

Discuss your environment with our team

Consult directly with Dectrax security engineers to review deception node placement and edge proxy deployment specs for your network.