OT / ICS segment
You can’t install an EDR agent on a PLC. DeceptionGrid is the only way to detect an intrusion into OT.
TrapX DeceptionGrid creates a network of thousands of decoy assets: servers, workstations, IoT devices, PLCs and medical equipment. Your employees don’t see them. An attacker who gets past the perimeter is sure to run into them. Any touch becomes a confirmed alert, with no false positives.
DeceptionGrid turns every network segment into a minefield. Any attacker activity on decoy assets, such as reconnaissance, lateral movement or credential theft, is recorded and escalated to the SOC.
The decoy library covers classic IT, OT/ICS, IoT, medical equipment and ATMs. All traps look and respond like real devices.
Windows 10/11 and Linux desktops with realistic user profiles, history and cookies.
FULL OS · EMULATEDFile server, SQL, Exchange, AD controller: they respond to SMB permission probes, Kerberoasting and LDAP queries.
SERVER · DCSiemens S7, Rockwell ControlLogix, Schneider Modicon; Modbus, S7Comm and DNP3 protocols.
OT · ICSDICOM PACS, infusion pumps, X-ray stations, MRI consoles: critical for hospitals.
MEDICAL · DICOMEmulation of ATMs (NCR, Diebold) and POS terminals for financial networks.
ATM · POSCisco, Juniper, Fortinet: they respond to Telnet, SSH, SNMP and default credentials.
SWITCH · ROUTERXerox / HP MFPs are often the first target of an attack. The traps detect reconnaissance.
IoT · PRINTERIP cameras, thermostats, badge readers, BMS: realistic imitation of web interfaces and protocols.
IoT · CAMERADecoys in AWS / Azure / GCP, S3 buckets, fake access keys in Secrets Manager.
CLOUD · S3Lures are scattered across your real workstations and servers. They look like valuable data but point to a decoy. The attacker “takes the bait” and walks into the trap.
A real scenario: after a successful phishing attack, the attacker began lateral movement. Here is how DeceptionGrid responds.
You can’t install an EDR agent on a PLC. DeceptionGrid is the only way to detect an intrusion into OT.
PACS, MRI machines and infusion pumps can’t be updated or patched. Traps cover what EDR can’t see.
Emulates ATMs and detects jackpotting tools and attacks on ATM subnets.
Ransomware looks for SMB shares, hits a decoy share, and the alert goes out before encryption begins.
Threatwise + Commvault Cloud: fake backup servers are the first line of defense against attacks on recovery.
A curious employee “accidentally” connects to a decoy server with financial data, and an alert goes to HR and Security.
We plan the deception fabric: where to place decoys, how to spread lures and how to connect it all to SIEM and EDR. We then support the traps and update scenarios to match current attack tactics.
We will design a deception fabric for your infrastructure: the number of traps, decoy types, a set of lures and SIEM/EDR integration.