Overview

Product video
Acalvio ShadowPlex Cloud Security delivers AI-powered deception and honeytokens to IAM and cloud-native services, providing fast and accurate threat detection across public clouds with minimal overhead.
It offers deception-based capabilities to detect a wide range of cloud-based threats effectively. Through the strategic deployment of honeytokens - carefully crafted deceptions designed to lure attackers within AWS cloud infrastructure - Acalvio SCS provides visibility into malicious activity in the cloud.
Honeytokens are deployed across both IAM directories and cloud workloads, covering key areas that are commonly targeted. Acalvio SCS deploys honeytokens that represent deceptive IAM users, IAM user groups, IAM roles, SSM parameters, SM secrets, EKS, and deceptive profiles on cloud workloads such as S3 buckets and EC2 instances.
Honeytokens operate outside the boundaries of legitimate business or IT workflows, making any interaction with them a clear and direct signal of malicious activity. Attempts to access or manipulate honeytokens serve as high-fidelity alerts, indicating a potential security threat with minimal false positives.
Acalvio SCS is optimized for seamless and efficient deployment in AWS, offering all the essential deployment artifacts to simplify and accelerate the setup process.
Highlights
- Agentless Solution: Acalvio SCS is an agentless solution. No Acalvio software is deployed in the customer's cloud. It only needs Read access to one storage bucket that stores the cloud logs for detecting Honeytoken access. Deployment and management of Honeytokens are performed using a configurable, dynamically generated script, which greatly simplifies adoption across complex environments, including AWS deployments with hundreds of accounts.
- AI-Powered Recommendations & Comprehensive Palette: Acalvio SCS uses AI to recommend highly realistic IAM and workload Honeytokens, luring attackers early in the kill chain. It deploys a wide array of IAM and workload Honeytokens to deliver coverage across cloud assets and workloads, including virtual machines, containers, and serverless functions, among other resources.
- Actionable Alerts Mapped to MITRE ATT&CK Framework: Acalvio SCS alerts are actionable and mapped to the MITRE ATT&CK framework to provide a standardized taxonomy for SOC teams, improving threat intelligence and incident response workflows.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.