ClearSkies Active Defense

Coverage

Active Defense secures the interior of the network, which is the ground an attacker must cross once prevention has been bypassed.

The same layer extends into operational technology and industrial control environments.

Decoys and beacon traps

Decoys

  • Reconnaissance
  • Web access
  • Database access
  • Remote access
  • File access
  • File transfer
  • Network access
  • Industrial, Modbus

Beacon traps

  • Documents in many formats
  • Planted login credentials
  • Database credentials
  • Shared directories and files
  • High-value bait

The defining property of deception. The difference between a decoy or a beacon trap and a real asset is that legitimate users have no reason to access it. Any access is therefore, by itself, an indication of malicious activity.

Two routes into the deception layer

Route one

Decoys

High-interaction and medium-interaction decoys look and behave exactly like a real information asset. They impersonate genuine operating systems and business applications, and expose open ports on the same protocols real services use. That makes it close to impossible for a threat actor to tell a decoy from a real asset, which lures the intruder onto the wrong path and reveals both presence and intent.

  • TCP
  • UDP
  • SMB
  • HTTP
  • HTTPS
  • RDP
  • FTP
  • TFTP
  • MySQL
  • MSSQL
  • Telnet
  • Modbus
  • SSH
  • SNMP
Route two

Beacon traps

Beacon traps use fake information and poisoned data as bait, planted strategically among real data to catch unauthorized access early. Any attempt to copy, access, modify or use planted data triggers an alert immediately, whereas the same action against real data would pass unnoticed.

What is planted as bait

More than one trap can be enabled on the same workstation or server. Every alert carries its own context: the trap type, the event triggered, the host address, the username, the service and the timestamp.

  • Documents containing fake network designs, systems information, addresses in use and business-application details.
  • Planted login credentials for HTTP, FTP, SSH, SNMP, RDP, TFTP and Telnet services.
  • Database credentials for MySQL and MSSQL authentication.
  • Shared directories and files staged to be discovered and accessed.
  • High-value bait such as financial data, personal data and intellectual property.

Contractor, supplier and third-party devices

Internal exposure extends to contractor devices, managed-service systems and third-party software. Because decoys and beacon traps sit on the internal network rather than on managed hosts, they catch a compromised vendor device or an abused supplier account the moment it begins to explore.

Virtualization environments and sizing

ResourceActive Defense 10Active Defense 20Active Defense 40
Supported decoy bundlesUp to 10Up to 20Up to 40
HypervisorVMware or Hyper-VVMware or Hyper-VVMware or Hyper-V
Supported version5.1 and above, or 5.0 and above6.0 and above, or 5.0 and above6.0 and above, or 5.0 and above
Virtual CPUs2, with 6 cores4, with 6 cores4, with 8 cores
Management interfaces111
Virtual memory8 GB12 GB24 GB
Virtual storage150 GB250 GB400 GB

Sizing describes capacity rather than price.

Every finding consolidates into the same record as the rest of the detections, mapped to MITRE ATT&CK and scored the same way, with no separate console to maintain.

What Active Defense does not do

The scope is worth stating plainly, because a deception layer is easy to over-claim.

  • Active Defense does not prevent an intrusion: it assumes one and catches it early.
  • It does not replace prevention, endpoint or network monitoring, or reduce the need for them.
  • It holds no production data and runs no production service, so it protects nothing directly.
  • It does not act on other add-ons' findings: every signal routes through the TDIR engine.

How the engine correlates

Connect with the team

Book a demo
A ClearSkies analyst reviewing deception-layer activity

Have a question first

Talk to the team
The deception layer across network segments