GuardPot
GuardPot fills the network with decoys an attacker cannot tell from the real thing, so touching one is itself the alert.
The alternative
Thinkst Canary at one end, small and few. Attivo (now SentinelOne) and Acalvio at the other, full platforms with a deployment project attached.
At a glance
- Delivery
- Decoy systems, services and accounts. Nothing installed on production machines
- Modules
- Decoy management, real-time detection, attacker technique analysis, intelligence output
- Coverage
- Network segments, cloud environments and endpoints
A legitimate user has no reason to open a system that was never in production. When a decoy reports, there is nothing left to judge.
GuardPot carries the platform capabilities, decoy systems, decoy accounts, decoy services, attacker behaviour analysis and intelligence output, in one product rather than across a suite.
The argument that matters most is the one about triage. Every other detection source hands an analyst something to assess. An endpoint agent decides whether a process looks malicious, a network sensor decides whether traffic looks unusual, and a SIEM correlates the two into something that still needs a human. A decoy has no users and no dependencies, so an interaction with it is not a signal about an intrusion. It is the intrusion.
For a team already behind on its queue, that is the difference between adding a source and adding work. It is also one of the few methods available in an OT or production network, where no agent can be installed and no traffic can be mirrored.
How it works
- Decoy systems, services and accounts are placed where an attacker looks
- Every interaction with one is recorded and analysed
- The techniques attempted and the direction of travel become visible
- Captured activity becomes indicators the rest of the stack can use
- Response starts before a production system is reached
Who it is for
- Security teams with a SIEM and alert fatigue
- Organisations that cannot see lateral movement inside the network
- Teams looking for ransomware at the reconnaissance step
- OT and production networks where an agent cannot be deployed
What we can point to
- Presented to regional security leaders at the event ICM led in Dubai, September 2025
Where it sits
Deception. It is the detection layer that sits behind identity security, and a decoy account is one of the few ways to see an attacker already inside the directory.
