How you run it
Three deployment usages
Same sensor fabric and fail-closed rules. Pick the posture that matches the job —
internal defense, open-internet CTI collection, or an isolated cyber range lab.
Inside the network
Decoys beside real assets
Plant forbidden scenarios next to production identity, OT, and AI surfaces.
When an adversary — human or AI — touches a decoy, you get graded campaign evidence
and a human Propose→Approve→Execute path to Soft/Hard — not another SIEM flood.
- Enterprise internal planting
- Detection off until you enable observe
- Loopback / private bind by default
On the internet
Public decoys → intel
Opt-in internet-facing research decoys collect scanner, bot, and operator activity.
Graded evidence exports to SIEM and CTI feeds under operator-controlled admission —
not an always-on Internet claim by default.
- CTI collection posture
- Fleet / sticky per-source admission
- SIEM & CTI export sinks
Cloud cyber range
AI-automated explosion lab
Spin up an isolated cloud range of decoys for purple-team and malware behaviour runs.
Ack-gated disposable guests record every move, block attacker egress, and send
behaviour evidence to Ops — no production path, no phone-home entitlement check.
- Isolated range boundary
- Ack-gated Live guests
- Egress denied · guests recycled