Project Overview
A cybersecurity deception platform for generating realistic decoy assets, deploying sensors, observing attacker activity, and supporting incident response.
Problem Addressed
Security teams need early visibility into attacker behavior before it reaches real assets.
My Role
I designed and built the deception sensors and the event-correlation and behavior-analysis engine.
How It Works
Setup begins by defining a company profile and its related data, then realistic decoy assets such as fake files and folders are generated, and a sensor is deployed (such as an SSH tarpit, an SMB sensor, or a web SQL-injection sensor). Threat events are collected and correlated into sessions and campaigns, the resulting behavior is analyzed, and alerts and incident reports are generated to support the response team.
What I Implemented
- Fake documents, folders, and shares
- Sensor deployments (SSH tarpit, SMB, web SQL injection)
- Threat event ingestion and session correlation
- Campaign analysis and behavior profiles
- MITRE ATT&CK mapping
- Alerts and incident reports
Technologies Used
Current Status
Active development