Dectrax
KUBERNETES & CONTAINERS

Container Deception & Pod Traps

Deploy decoy pods and container traps inside Kubernetes clusters to catch intra-cluster scanning.

Unseen intra-cluster scanning in container environments

Compromised container pods are used by adversaries to perform cluster-wide port scanning and service account token harvesting.

Intra-cluster traffic in default Kubernetes configurations often lacks granular visibility.

Compromised pods scan adjacent ServiceIPs to identify vulnerable microservices.

Decoy pods inside Kubernetes namespaces

DentiGridDeception & Intelligence

DentiGrid allows running decoy container pods within Kubernetes namespaces. Scans against decoy pod ports generate instant telemetry.

GATEEdge Proxy Enforcement

GATE acts as an edge ingress controller proxy, validating request schemas before microservice routing.

SYSTEM TOPOLOGY & DATA FLOW
  KUBERNETES CLUSTER
  +--------------------------+
  |  DentiGrid Decoy Pod     | ---> Intra-Cluster Scan ---> DentiGrid Intel ---> Cluster Firewall

From pod trap scan to cluster containment

1

A compromised container scans cluster network and connects to a DentiGrid decoy pod.

2

The sensor authenticates telemetry and alerts cluster security operators.

3

Adversary IP/pod is flagged for containment.

What your cloud-native team receives

Kubernetes manifest templates for deploying decoy pod sensors.
Centralized telemetry logging for container security operations.

Security Stack Integration

Complements container security tools like Falco and Kubernetes network policies.

Discuss your environment with our team

Consult directly with Dectrax security engineers to review deception node placement and edge proxy deployment specs for your network.