Home Solutions TrapX
Deception · Active Defense · OT & IoT
TrapX logo

Let attackers
give themselves away.

TrapX DeceptionGrid creates a network of thousands of decoy assets: servers, workstations, IoT devices, PLCs and medical equipment. Your employees don’t see them. An attacker who gets past the perimeter is sure to run into them. Any touch becomes a confirmed alert, with no false positives.

How deception works

Three steps.
The attacker gets in and gets caught.

DeceptionGrid turns every network segment into a minefield. Any attacker activity on decoy assets, such as reconnaissance, lateral movement or credential theft, is recorded and escalated to the SOC.

01
Deploying decoys and lures
Several thousand decoy assets are placed in each VLAN. “Lures” are scattered across real hosts: fake accounts, SMB shares, RDP session histories, browser passwords.
02
Contact with a trap
After initial access, the attacker starts reconnaissance, sees the lures and follows the “trail” to the decoys. Every touch (network scan, login, exec) is recorded with full context.
03
Intelligence gathering
DeceptionGrid collects the payload, TTPs, tools and C2 addresses in a safe environment. The alert goes to SIEM/SOAR, and EDR isolates the source host.
Classic defense
Catch the attack on real assets
  • Fine-tune rules to avoid false alarms
  • Real alerts get lost in the noise of normal activity
  • The attacker keeps trying techniques until one gets past the detector
  • Industry average MTTD (time to detect): weeks or months
Deception (TrapX)
Catch the attack on decoy assets
  • Any interaction with a decoy is a confirmed attack
  • Zero false positives → the SOC doesn’t burn out on “noise”
  • The attacker doesn’t know which asset is fake
  • MTTD in seconds, not days
Trap types

Decoys that look like servers
or any other asset on the network.

The decoy library covers classic IT, OT/ICS, IoT, medical equipment and ATMs. All traps look and respond like real devices.

Workstations

Windows 10/11 and Linux desktops with realistic user profiles, history and cookies.

FULL OS · EMULATED
Servers and AD

File server, SQL, Exchange, AD controller: they respond to SMB permission probes, Kerberoasting and LDAP queries.

SERVER · DC
PLCs and SCADA

Siemens S7, Rockwell ControlLogix, Schneider Modicon; Modbus, S7Comm and DNP3 protocols.

OT · ICS
Medical devices

DICOM PACS, infusion pumps, X-ray stations, MRI consoles: critical for hospitals.

MEDICAL · DICOM
ATMs and POS

Emulation of ATMs (NCR, Diebold) and POS terminals for financial networks.

ATM · POS
Network equipment

Cisco, Juniper, Fortinet: they respond to Telnet, SSH, SNMP and default credentials.

SWITCH · ROUTER
Printers and MFPs

Xerox / HP MFPs are often the first target of an attack. The traps detect reconnaissance.

IoT · PRINTER
IoT devices

IP cameras, thermostats, badge readers, BMS: realistic imitation of web interfaces and protocols.

IoT · CAMERA
Cloud workloads

Decoys in AWS / Azure / GCP, S3 buckets, fake access keys in Secrets Manager.

CLOUD · S3
Lures & Honeytokens

Lures on real hosts
lead attackers into the trap.

Lures are scattered across your real workstations and servers. They look like valuable data but point to a decoy. The attacker “takes the bait” and walks into the trap.

  • Fake admin credentials in LSASS, Credential Manager, browser passwords.
  • RDP & SMB history - traces of “recent connections” to a decoy server.
  • Fake mapped drives and shortcuts to “Accounting” / “Contracts”.
  • Honeydocs - Excel/Word files with a tracking marker: opening one raises an alert.
  • AWS access keys in .aws/credentials, GitHub tokens in .env.
  • Kerberos tickets and AD objects that attract Kerberoasting.
Mimikatz dump · WS-FIN-014
What the attacker sees after dumping LSASS
# Logon Session 0:
Username : a.karimov
Domain : CORP
NTLM : 7c4f…d3 (real)
# Logon Session 1:
Username : backup_svc ← honeytoken
Domain : CORP
NTLM : f1aa…91 (lure)
// any use of this hash triggers a high-severity alert
# Recent RDP:
10.2.14.71 // decoy WS-ARCHIVE-DB
The attacker runs Mimikatz and sees an “attractive” `backup_svc` account with access to `WS-ARCHIVE-DB`. They go there and end up in DeceptionGrid. Any use of the honeytoken hash is confirmed proof of compromise.
Incident timeline

From first reconnaissance
to isolation in 7 minutes.

A real scenario: after a successful phishing attack, the attacker began lateral movement. Here is how DeceptionGrid responds.

T0
Phishing payload executed on WS-MKT-007
EDR didn’t react to the fileless C# loader.
↗
+00:42
Network scan of 10.0.0.0/16: decoys found
DeceptionGrid records ARP/ICMP traffic to the traps.
⚠
+01:18
SMB authentication on a decoy server
The attacker uses the hash of the honey account `backup_svc`.
🔴 HIGH
+02:09
SIEM alert + SOAR playbook
Splunk/Sentinel receives the event, and a ticket opens in ServiceNow.
↘
+03:30
EDR isolates the source host
CrowdStrike Falcon disconnects WS-MKT-007 from the network.
🛡
+07:00
Investigation closed
DeceptionGrid passed the payload, TTPs and C2 address to Threat Intel.
✓
Where deception is critical

Environments where EDR can’t cope on its own.

OT / ICS segment

You can’t install an EDR agent on a PLC. DeceptionGrid is the only way to detect an intrusion into OT.

Healthcare and IoMT

PACS, MRI machines and infusion pumps can’t be updated or patched. Traps cover what EDR can’t see.

ATM networks

Emulates ATMs and detects jackpotting tools and attacks on ATM subnets.

Ransomware protection

Ransomware looks for SMB shares, hits a decoy share, and the alert goes out before encryption begins.

Backup protection

Threatwise + Commvault Cloud: fake backup servers are the first line of defense against attacks on recovery.

Insider threats

A curious employee “accidentally” connects to a decoy server with financial data, and an alert goes to HR and Security.

CYBER BOOST × TrapX

We deploy deception from start to finish.

We plan the deception fabric: where to place decoys, how to spread lures and how to connect it all to SIEM and EDR. We then support the traps and update scenarios to match current attack tactics.

14 days
typical DeceptionGrid deployment on a corporate segment of 5,000 hosts.
OT-ready
certified engineers for deployment in OT/ICS environments.
SIEM
ready-made playbook exports for Splunk, Sentinel, QRadar and KUMA.
RU/UZ
runbooks in Russian and Uzbek, plus SOC training.
FAQ

Frequently asked questions about TrapX.

Are TrapX and Commvault Threatwise the same thing?
Yes. In 2022, Commvault acquired TrapX Security. DeceptionGrid was integrated and renamed Commvault Threatwise. The deception technology stayed, and Commvault Cloud integration was added to protect backups.
How is deception different from EDR or SIEM?
EDR looks for attacks on real hosts by signatures and behavior. This is noisy and needs fine-tuning. Deception instead creates decoy assets that employees never touch. Any interaction with a decoy is a confirmed attack, with zero false positives.
Can an attacker tell a real host from a trap?
No. DeceptionGrid uses “emulated assets” (thousands of lightweight traps with a real TCP/IP stack) and complete “full-OS decoys” (virtual machines with a real OS, services and data). An attacker would have to take dozens of actions to figure it out, and every one of them would be recorded.
Does TrapX support OT/ICS and medical devices?
Yes, this is one of the platform’s strengths. The decoy library includes PLCs (Siemens, Rockwell, Schneider), SCADA, medical devices (PACS, infusion pumps, MRI consoles), ATMs, IoT and printers. They are deployed in the OT segment without agents.
How many traps do you need for it to work?
The ratio of real assets to traps is usually 5:1 to 10:1. For a network of 5,000 hosts, that is 500-1,000 decoys. They create no load: emulated traps run as hundreds of instances on a single “host” virtual machine.
What SIEM and SOAR integrations are available?
Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, Elastic, Kaspersky KUMA. SOAR outputs: Cortex XSOAR, Splunk SOAR, Tines. Any event is sent to syslog/CEF, and there is a REST API for your own integrations.
Request · TrapX / Threatwise

We’ll place your first decoys in 2 weeks.

We will design a deception fabric for your infrastructure: the number of traps, decoy types, a set of lures and SIEM/EDR integration.