SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Separate offering · Active generative deception · Coming soon

KrKratos

Turns your network into a minefield. AI-powered decoys planted natively at the Internal Network lure attackers in, waste their time and compute, and block them worldwide the moment they are detected. No appliances, no endpoint agents, no false positives.

Active generative deception

AI decoys that come alive on contact.

Kratos seeds the Internal Network with AI decoys tailored to your real environment. It watches your traffic, plants the decoys, engages attackers and closes the loop. No legitimate user or app has any reason to touch a decoy, so its job is not detection, that is already solved, it is prolonging engagement and extracting intent.

Kratos is a capability you enable deliberately, not another chat partner: its findings reach you through Lucy, like everything else on the platform.

Zero false positives

No legitimate reason to touch a decoy, so every hit is real.

A minefield

Unused ports turned into AI-generated decoys across the edge.

Global block

One probe, blocked everywhere the moment intent is clear.

The problem

Static defenses lose.

The economics of attack have flipped. Adversaries strike constantly and cheaply, while defenders stay locked into a reactive, perimeter-first model, forced to be right every time when the attacker only has to be right once.

  • Defenders are always one step behind. The attacker picks the time, target and method; you can only react once the perimeter is already breached.
  • Attacks are cheaper and massively scalable. What once needed expertise now takes a script and a few cents of compute, at machine speed.
  • Alert fatigue buries the real threat. Low-fidelity, false-positive-heavy alerts flood the SOC, and the one signal that matters gets missed.

Deception was supposed to fix this, but legacy honeypots did not. Static scripts were fingerprinted instantly and skipped, and deployment friction (new VMs, agents and routing) meant months of re-architecture before a single decoy went live.

What Kratos does differently

Not a honeypot. A generative decoy engine.

Zero false positives

No legitimate user or app has any reason to touch a decoy, so any connection is inherently suspicious. High-fidelity alerts, no noise.

The generative "Turing test"

With an LLM behind the port, the decoy is no longer a static script. Kratos hallucinates a plausible environment on demand, different every time, so a novel exploit gets a novel, convincing response. Every minute strung along burns the attacker's time and compute.

Frictionless, passive discovery

No aggressive scanning. Kratos passively observes edge traffic to fingerprint the real environment, then plants decoys tailored to it, without sending a single probe. It never trips internal IDS, disrupts fragile legacy IoT, or violates compliance rules.

How it works

Attacker, edge, cloud, enforcement.

Passive discovery shapes the decoys, Kratos brings them to life in the cloud, and enforcement closes the loop, all on one platform.

1 - Attacker probes a fake service

An adversary scans the edge and connects to a shadow port that looks like a real, exploitable service.

2 - Edge opens shadow ports

The SASE gateway opens decoy ports alongside the real ones and transparently tunnels the attacker's traffic onward.

3 - Cloud hallucinates an environment

Kratos strings the attacker along with a convincing, generated environment, wasting their time and mapping their tools.

4 - Global blocklist

The moment intent is clear, the block propagates worldwide; the same attacker is stopped in every location at once.

Why only Open Systems

Walls, or a minefield.

Standalone deception vendors can bolt a honeypot onto your network. They cannot do it without appliances, at cloud scale, and wired straight into global enforcement. That is the moat.

  • Deception without appliances. We already own the edge gateways. Kratos ships as a software feature overlay: no new hardware, no agents, no re-architecture.
  • Thin edge, thick cloud. Attacker traffic is securely tunneled (gRPC / mTLS) to the Open Systems cloud where the heavy decoy engine lives, cloud-scale compute, cheap edge hardware.
  • Global enforcement loop. Because Kratos sits on the same platform as firewalling and Threat Protection, an attacker probing a fake SSH port in London is blocked across New York and Tokyo instantly. Standalone vendors can only alert.
The architecture

Four components, one platform.

Two live at the Internal Network, one in the Open Systems cloud, one in Threat Protection. Together they discover, deceive and contain, without you deploying anything new.

Passive Discovery - Internal Network

Observes traffic to map real hosts and exposed ports, so decoys blend in. No active pinging.

Honeypot Proxy - Internal Network

Opens shadow ports alongside the real ones and transparently tunnels attacker traffic to the decoy engine.

Kratos Decoy Engine - Open Systems cloud

Processes payloads, hallucinates responses and maps attacker tools, cloud-scale compute, cheap edge hardware.

Enforcement - Threat Protection

Propagates firewall blocks back to the edge, globally, so one detection stops the attacker everywhere.

Maturity & roster

Go deeper.

Maturity: Coming soon. V1 scopes to text-based application-layer protocols (HTTP/APIs and interactive SSH/Telnet/FTP) where LLMs excel; binary protocols fall back to static templates. Escalation scales with intent: a simple ping earns a temporary drop, a reverse-shell attempt earns a permanent global block.

See the original deep-dive: Active Generative Deception, the v1 concept.

Stop building taller walls.

Let Kratos turn the network into a minefield: decoys that trap attackers, and containment that spans the globe the instant intent is clear.

Book a demo
Already a customerEverything you use today keeps running.