Platform capability

Operational

Deception and internal early warning

Decoy systems placed inside your network that no legitimate process should ever touch, producing near-zero false positives.

Overview

Every detection method has a false positive rate. Deception has close to none, because the systems it monitors have no legitimate purpose. Nothing in your business needs to connect to them, so anything that does is either misconfigured or hostile - and both are worth knowing about immediately.

Vanguard places decoy services on your internal network that present as ordinary infrastructure: a file share, a database port, an administrative interface. An attacker performing reconnaissance after gaining an initial foothold finds them precisely because they are looking for exactly that kind of target.

The result is a high-confidence signal at the stage of an intrusion where response is still cheap: after initial access, before lateral movement succeeds.

What this identifies

  • Internal network reconnaissance and service enumeration
  • Lateral movement following an initial compromise
  • Use of credentials harvested from a compromised host
  • Insider access to systems outside a legitimate role
  • Automated worm and ransomware propagation behaviour

Delivery status: Operational - deployed and in production service.

Capabilities

What deception does

  • Decoy services

    Convincing decoy services placed at plausible points in your internal address space.

  • High-confidence alerting

    Interaction with a decoy escalates immediately, because the false positive rate is close to zero by construction.

  • Lateral movement detection

    Catches internal reconnaissance that perimeter controls never see.

  • Credential canaries

    Planted credentials that trigger an alert if they are ever used.

Under the hood

The engineering underneath

How this capability is actually engineered and operated. The specific detection tooling behind the security operations centre is shared with customers under agreement rather than published, for the same reason you would not publish yours.

  • Decoy services run on dedicated internal addresses, chosen to sit where an intruder would look.
  • Interactions feed the central pipeline and escalate through the standard severity ladder.
  • The platform is aware of its own scheduled self-tests, so a routine verification scan is never reported as an intrusion.

The full platform architecture is documented on the architecture page.

Related

  • In deployment

    Network Detection

    Signature-based intrusion detection combined with protocol metadata, giving visibility into traffic that never touches a monitored endpoint.

    Explore
  • In deployment

    Threat Hunting

    Analyst-led search for activity that did not trigger an alert, supported by fleet-wide query and remote forensic collection.

    Explore
  • Operational

    Incident Response

    A defined path from alert to containment to closure, with analysts who investigate before they escalate.

    Explore

Get started

Find out what is actually happening on your network

A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.