Deception Signals
Live

Low-noise decoy signals for fast review.

Decoys are a tripwire for attacker activity. When something touches one, you get a scoped signal with the context needed to review and route the incident.

Low-noiseWorkspace-scopedReview-ready
Product preview

Deception activity

See Dralvia in action.

See workspace-scoped decoy interactions and move meaningful signals into an investigation.

  • Deploy supported deception controls
  • Observe interaction signals
  • Escalate evidence into investigation

This preview shows the Dralvia workspace. Sign in to see your own scans, alerts, and activity.

Dralvia Deception Signals workspace preview
Product preview · Deception Signals
Why deception

Catch what prevention misses.

Deception fires after suspicious movement reaches a decoy, with a focused signal that broad telemetry can miss.

Decoy touched

Any interaction with a decoy is a signal worth acting on.

Interaction detail

Event type, request method and path, hashed source, and risk tags.

Low-noise source

Decoys are not normal user destinations, so each signal deserves review.

How it works

Register, wait, respond.

1

Register decoys

Enroll decoys for your workspace through the agent API.

2

Get signals

Any interaction with your decoys shows up as a scoped alert.

3

Respond

Triage the interaction and route it to your incident workflow.

What you get

Low-noise, scoped, automatable.

Workspace-scoped

You only ever see interactions with your own decoys.

Review-ready signal

A signal means something touched a decoy, which should not happen in normal use.

API + SIEM

Pull signals via GET /api/deception/signals into a SIEM or TicketBridge.

Who it is for

Security and response teams.

Responders

A low-noise tripwire that flags attacker activity worth investigating.

Security engineers

Place decoys near sensitive assets to widen coverage.

FAQ

Honest answers.

No. The signals feed is strictly scoped to your workspace's decoys.

Add a low-noise tripwire.

Turn decoys into low-noise alerts scoped to your workspace.