← All services
Add-on

Endpoint Forensics & Deception Hunting

Trap sneaky attackers early — collect proof when needed.

What this service offers

This service combines deception tripwires with deep post-incident forensic collection for high-assurance investigation.

It covers advanced response and proactive deception.

  • Low-noise deception tripwires (decoy credentials / shares style traps)
  • Kevantic ThreatLens (AI-Assisted IOC Extraction & Advisory Analysis)
  • Rapid isolation when a trap is touched (policy permitting)
  • Remote triage collection packages for deep investigation
  • Secure download paths for forensic evidence packages (SOC-controlled)

Limitations (honest scope)

Clear boundaries help you buy the right module — not oversell.

  • Deception is not a replacement for patching and Core monitoring.
  • Forensic packages are sensitive — customer portal stays summary-safe; full evidence is SOC-handled.
  • Requires endpoint coverage where traps/collections run.
  • Legal hold / chain-of-custody needs may require extra process with your counsel.

Who should go for it

  • Higher-maturity teams hunting stealthy intruders.
  • Incidents that need deeper proof than standard alert detail.

Usually not the best fit if…

  • Organizations that cannot approve any deception or forensic collection tooling on endpoints.