Container Deception & Pod Traps
Deploy decoy pods and container traps inside Kubernetes clusters to catch intra-cluster scanning.
Unseen intra-cluster scanning in container environments
Compromised container pods are used by adversaries to perform cluster-wide port scanning and service account token harvesting.
Intra-cluster traffic in default Kubernetes configurations often lacks granular visibility.
Compromised pods scan adjacent ServiceIPs to identify vulnerable microservices.
Decoy pods inside Kubernetes namespaces
DentiGrid allows running decoy container pods within Kubernetes namespaces. Scans against decoy pod ports generate instant telemetry.
GATE acts as an edge ingress controller proxy, validating request schemas before microservice routing.
KUBERNETES CLUSTER +--------------------------+ | DentiGrid Decoy Pod | ---> Intra-Cluster Scan ---> DentiGrid Intel ---> Cluster Firewall
From pod trap scan to cluster containment
A compromised container scans cluster network and connects to a DentiGrid decoy pod.
The sensor authenticates telemetry and alerts cluster security operators.
Adversary IP/pod is flagged for containment.
What your cloud-native team receives
Security Stack Integration
Complements container security tools like Falco and Kubernetes network policies.
Discuss your environment with our team
Consult directly with Dectrax security engineers to review deception node placement and edge proxy deployment specs for your network.
