KrKratos
Turns your network into a minefield. AI-powered decoys planted natively at the Internal Network lure attackers in, waste their time and compute, and block them worldwide the moment they are detected. No appliances, no endpoint agents, no false positives.
AI decoys that come alive on contact.
Kratos seeds the Internal Network with AI decoys tailored to your real environment. It watches your traffic, plants the decoys, engages attackers and closes the loop. No legitimate user or app has any reason to touch a decoy, so its job is not detection, that is already solved, it is prolonging engagement and extracting intent.
Kratos is a capability you enable deliberately, not another chat partner: its findings reach you through Lucy, like everything else on the platform.
Zero false positives
No legitimate reason to touch a decoy, so every hit is real.
A minefield
Unused ports turned into AI-generated decoys across the edge.
Global block
One probe, blocked everywhere the moment intent is clear.
Static defenses lose.
The economics of attack have flipped. Adversaries strike constantly and cheaply, while defenders stay locked into a reactive, perimeter-first model, forced to be right every time when the attacker only has to be right once.
- Defenders are always one step behind. The attacker picks the time, target and method; you can only react once the perimeter is already breached.
- Attacks are cheaper and massively scalable. What once needed expertise now takes a script and a few cents of compute, at machine speed.
- Alert fatigue buries the real threat. Low-fidelity, false-positive-heavy alerts flood the SOC, and the one signal that matters gets missed.
Deception was supposed to fix this, but legacy honeypots did not. Static scripts were fingerprinted instantly and skipped, and deployment friction (new VMs, agents and routing) meant months of re-architecture before a single decoy went live.
Not a honeypot. A generative decoy engine.
Zero false positives
No legitimate user or app has any reason to touch a decoy, so any connection is inherently suspicious. High-fidelity alerts, no noise.
The generative "Turing test"
With an LLM behind the port, the decoy is no longer a static script. Kratos hallucinates a plausible environment on demand, different every time, so a novel exploit gets a novel, convincing response. Every minute strung along burns the attacker's time and compute.
Frictionless, passive discovery
No aggressive scanning. Kratos passively observes edge traffic to fingerprint the real environment, then plants decoys tailored to it, without sending a single probe. It never trips internal IDS, disrupts fragile legacy IoT, or violates compliance rules.
Attacker, edge, cloud, enforcement.
Passive discovery shapes the decoys, Kratos brings them to life in the cloud, and enforcement closes the loop, all on one platform.
1 - Attacker probes a fake service
An adversary scans the edge and connects to a shadow port that looks like a real, exploitable service.
2 - Edge opens shadow ports
The SASE gateway opens decoy ports alongside the real ones and transparently tunnels the attacker's traffic onward.
3 - Cloud hallucinates an environment
Kratos strings the attacker along with a convincing, generated environment, wasting their time and mapping their tools.
4 - Global blocklist
The moment intent is clear, the block propagates worldwide; the same attacker is stopped in every location at once.
Walls, or a minefield.
Standalone deception vendors can bolt a honeypot onto your network. They cannot do it without appliances, at cloud scale, and wired straight into global enforcement. That is the moat.
- Deception without appliances. We already own the edge gateways. Kratos ships as a software feature overlay: no new hardware, no agents, no re-architecture.
- Thin edge, thick cloud. Attacker traffic is securely tunneled (gRPC / mTLS) to the Open Systems cloud where the heavy decoy engine lives, cloud-scale compute, cheap edge hardware.
- Global enforcement loop. Because Kratos sits on the same platform as firewalling and Threat Protection, an attacker probing a fake SSH port in London is blocked across New York and Tokyo instantly. Standalone vendors can only alert.
Four components, one platform.
Two live at the Internal Network, one in the Open Systems cloud, one in Threat Protection. Together they discover, deceive and contain, without you deploying anything new.
Passive Discovery - Internal Network
Observes traffic to map real hosts and exposed ports, so decoys blend in. No active pinging.
Honeypot Proxy - Internal Network
Opens shadow ports alongside the real ones and transparently tunnels attacker traffic to the decoy engine.
Kratos Decoy Engine - Open Systems cloud
Processes payloads, hallucinates responses and maps attacker tools, cloud-scale compute, cheap edge hardware.
Enforcement - Threat Protection
Propagates firewall blocks back to the edge, globally, so one detection stops the attacker everywhere.
Go deeper.
Maturity: Coming soon. V1 scopes to text-based application-layer protocols (HTTP/APIs and interactive SSH/Telnet/FTP) where LLMs excel; binary protocols fall back to static templates. Escalation scales with intent: a simple ping earns a temporary drop, a reverse-shell attempt earns a permanent global block.
See the original deep-dive: Active Generative Deception, the v1 concept.
Stop building taller walls.
Let Kratos turn the network into a minefield: decoys that trap attackers, and containment that spans the globe the instant intent is clear.
Book a demo →