BaitHive Decoy
Clone traps that intercept attackers before production is touched
BaitHive Decoy deploys realistic clone traps — mimicking enterprise portals, VPN gateways, device interfaces, and internal applications — to identify attackers before they reach production systems, without the false-positive burden that conventional detection tools impose on security teams.
Every interaction with our decoy is hostile by architectural definition: legitimate users and systems have no reason to interact with resources outside the production environment. The decoy intercepts the attacker at the earliest possible stage — during reconnaissance or initial access — and every interaction simultaneously generates the TTP intelligence that feeds CATIS. Deception is the first of the five capability areas behind preemptive cybersecurity.
Capabilities
| Capability | Why it matters |
|---|---|
| Zero false positives by architecture | Every interaction with our decoy is adversarial by definition, so every alert warrants investigation. There is no tuning burden. |
| JA4H fingerprinting | Identifies the specific toolchain behind an attack, enabling attribution and campaign correlation across events even when infrastructure rotates. |
| Active response shaping | Dynamically probes attacker behaviour to extract toolchain capability and operator intent. |
| Engineered to evade AI-assisted scanning | Built so that automated scanning tools and AI-driven reconnaissance cannot reliably distinguish a clone trap from a genuine production asset — not merely legacy honeypot-detection heuristics. |
| AI agent-aware deception | Extends clone-trap coverage from human and tool-driven reconnaissance to autonomous AI agents that inspect, reason about and act on what they find without human control. |
| Rapid deployment | Pre-built clone packs live within 1 business day; custom clones for bespoke internal applications within 3–7 business days. |
Patent-protected: US 12,284,211 B2
BaitHive Decoy and TCP Mirage are both protected under United States Patent 12,284,211 B2, “Cyber clone of a computing entity”, granted 22 April 2025 to Advanced Security Technologies Asia Pte Ltd. It covers the core cyber-clone deception methodology shared by both products.
The patented technique is engineered so that automated scanning tools and AI-driven reconnaissance cannot reliably distinguish an AST clone trap from a genuine production asset. That indistinguishability — verified against contemporary AI-assisted scanning, not just legacy honeypot-detection heuristics — is the foundation of the zero-false-positive model: if an interaction reaches the trap at all, it is adversarial.
Live in days, not quarters
1 business day
Pre-built clone packs replicating common enterprise portals, VPN gateways, and device interfaces are deployed and generating telemetry within one business day.
3–7 business days
Custom clones, built to mirror bespoke internal applications in your own inventory, are live within three to seven business days.
How it works
Personalised decoy deployment
Decoys replicate the vendor devices, administrative portals, and web services actually present in your inventory. This personalisation matters: generic decoys are more easily identified by attackers, while decoys mirroring your real environment elicit deeper engagement and yield more relevant intelligence. Deployment includes synthetic vulnerability surfaces — controlled, inert points designed to attract exploit tools relevant to your real exposure profile — and optional deployment inside edge routers to shift detection to the network boundary.
Attacker interception and profiling
Every interaction is fingerprinted at the transport and application layers, identifying scanning tools, exploit frameworks, and AI-driven attack agents independent of source IP. Complete payload data, request sequences, and TTP patterns are captured in real time, and decoy behaviour adapts dynamically to extend engagement.
Intelligence generation
All collected TTP data is forwarded automatically to CATIS, correlated against telemetry from your wider network, analysed for novel attack patterns, and transformed into IOFA distributed to your security controls in real time. Documented cases exist of zero-day detection and prevention 30 to 45 days ahead of official vulnerability confirmation.
Monitoring and management
The managed service includes continuous monitoring of all decoys and interactions with them, tuning and expansion of the deception surface as your environment changes, status and availability tracking, and escalation whenever indicators of active infiltration into production systems are detected.
Complete coverage across the network stack
BaitHive Decoy is one of two complementary Advanced Cyber Deception sensors. Together they cover the full network stack.
| Sensor | Layer | Role |
|---|---|---|
| BaitHive Decoy | Application / HTTP | Engages attackers on realistic clone traps of portals, gateways, and internal applications |
| TCP Mirage | Transport | Intercepts reconnaissance at the first packet of a connection, on any TCP service and any port, producing telemetry even when application payloads are fully encrypted |
AI Agent-Aware Deception
Reconnaissance is increasingly carried out by autonomous AI agents rather than by people at keyboards. An agent reads what it finds, reasons about it, and decides what to do next without waiting for instructions — which changes what a decoy has to withstand. BaitHive Decoy extends the same patented clone-trap methodology to that adversary; the full picture is on autonomous AI agent security.
AI Agent Tripwires
Suspicious autonomous interaction with deceptive machine-readable assets is detected and recorded. Those assets are placed where an agent performing reconnaissance will encounter them and ordinary work will not take a person, so the interaction itself is the signal.
Deception that survives automated evaluation
Deception built for adversaries that inspect, reason about and act on information automatically, rather than for adversaries that browse. The design question changes: not whether an asset looks convincing on a screen, but whether it holds up when it is parsed and evaluated by something that decides its next move without asking anyone.
AI Agent TTP Intelligence
The sequence of actions an autonomous attacker performs is observed and analysed to establish its objective, its reconnaissance process and its likely next actions. As with every other decoy interaction, that analysis feeds CATIS and becomes IOFA.
Autonomous Containment
Detection on the deception surface creates a defensive opportunity to interrupt autonomous attack progression before real high-value assets are reached — while there is still distance between the adversary and anything that matters.
Placement, construction, and the techniques that make an asset resistant to automated classification are deliberately not described here. Architecture and demonstrations are available under NDA.
Field-proven on embedded hardware
AST’s patented clone-trap technology has been embedded and field-validated directly within third-party network hardware, extending deception coverage to the edge without a separate appliance.
- Teltonika industrial cellular routers
- Cisco IR series industrial routers
- MikroTik routers
- Quectel SC200 4G IoT module
What you receive
- A summary of detected attacks and attacker profiles for the period
- Identified TTP patterns and changes in attack technique relevant to your environment
- Autonomous AI agent interaction observed against the deception surface, and what it indicates about objective and likely next actions
- Deception surface status, with recommendations for expansion or adjustment