SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Intelligence · AI Agent · ArgusRoadmap

Meet Argus. Active Generative Deception.

▸ Argus is an Open Systems AI agent. Its job: active generative deception.

Argus turns your network into a minefield. It plants AI-powered decoy services natively at the Internal Network, lures attackers in, wastes their time and compute, and blocks them worldwide the moment they're detected. No appliances, no endpoint agents, no false positives.

01The problem · today's landscape

Static defenses lose.

The economics of attack have flipped. Adversaries strike constantly and cheaply, while defenders stay locked into a reactive, perimeter-first model, forced to be right every time when the attacker only has to be right once.

Defenders are always one step behind

The attacker picks the time, the target and the method. Defenders can only react once the perimeter is already breached, so the initiative sits with the attacker, not with you.

Attacks are cheaper, and massively scalable

Adversaries can scan and exploit thousands of systems at machine speed. What once required expertise now takes a script and a few cents of compute, and leaves defenders little time to react.

Alert fatigue buries the real threat

Traditional detection floods SOC teams with low-fidelity, false-positive-heavy alerts. Analysts tune out, response slows, and the one signal that actually matters gets missed.

02The attempted fix

Deception was supposed to fix this. Legacy honeypots didn't.

Standalone honeypots promised to turn the tables on attackers. In practice they were easy to spot and painful to deploy:

Static scripts

fingerprinted instantly

Legacy honeypots use fixed templates. Automated tools fingerprint them and skip straight past, so the trap never springs.

Deployment friction

new VMs, agents, routing

Standalone vendors like Attivo and Illusive required new VMs, agents and routing changes, months of re-architecture before a single decoy went live.

03What Argus does differently

AI decoys that come alive on contact.

Instead of waiting at the perimeter, Argus seeds the Internal Network with AI decoys tailored to your real environment. Argus watches your traffic, plants the decoys, engages attackers, and closes the loop.

Zero false positives

by design

No legitimate user or app has any reason to touch a decoy, so any connection is inherently suspicious. High-fidelity alerts, no noise. Argus's job isn't detection, that's already solved, it's prolonging engagement and extracting intent.

The generative "Turing test"

a novel response, every time

With an LLM behind the port, the decoy is no longer a static script. Argus hallucinates a plausible environment on demand, different every time, so a novel exploit gets a novel, convincing response. Every minute Argus strings an attacker along burns their time and compute.

Frictionless, passive discovery

not a single probe

No aggressive scanning. Argus passively observes existing edge traffic to fingerprint the real environment, then plants decoys tailored to it, without sending a single probe. It never trips internal IDS, disrupts fragile legacy IoT, or violates compliance rules.

0
legitimate reasons to ever touch a decoy
0
active probes sent during discovery
LLM
behind every port, a new environment each time

▸ The generative decoy engine is Argus. It watches your traffic, plants decoys, engages attackers, and closes the loop.

04How it works

Attacker → edge → cloud → enforcement.

Passive discovery shapes the decoys, Argus brings them to life in the cloud, and enforcement closes the loop, on one platform.

Attacker

Probes a fake service

An adversary scans the edge and connects to a shadow port that looks like a real, exploitable service.

Edge gateway

Shadow ports

The SASE gateway opens decoy ports alongside the real ones and transparently tunnels the attacker's traffic onward.

Argus · cloud LLM decoy

Hallucinated environment

Argus strings the attacker along with a convincing, generated environment, wasting their time and mapping their tools.

Threat Protection

Global blocklist

The moment intent is clear, the block propagates worldwide, the same attacker is stopped in every location at once.

▸ Passive discovery shapes the decoys, Argus brings them to life, and enforcement closes the loop.

05Why only Open Systems

Walls, or a minefield.

Standalone deception vendors can bolt a honeypot onto your network. They can't do it without appliances, at cloud scale, and wired straight into global enforcement. That's the moat.

Deception without appliances

We already own the edge gateways. Argus ships as a software feature overlay, no new hardware, no agents, no re-architecture. It just starts answering traffic on unused ports.

Thin edge, thick cloud

Running capable LLMs on edge hardware is slow and costly. Argus securely tunnels attacker traffic (gRPC / mTLS) to the Open Systems cloud, where the heavy decoy engine lives, cloud-scale compute, cheap edge hardware.

Global enforcement loop

Standalone vendors can only alert. Because Argus sits on the same platform as firewalling and Threat Protection, an attacker probing a fake SSH port in London is blocked across New York and Tokyo instantly.

▸ Because we own the network and the security, we can act where others can only alert.

06It's real

Scoped engineering,
not hand-waving.

Every strong claim is paired with the mechanism that backs it. Here are the constraints we've scoped, honestly.

  • Right protocols first. V1 scopes to text-based application-layer protocols, HTTP/APIs and interactive SSH/Telnet/FTP, where LLMs excel. Binary protocols (RDP, SMB, industrial) fall back to static templates.
  • Latency matters. A fast inference engine with a small, fine-tuned model, plus cached responses to common scanner probes (Nmap, Nuclei), answers inside a scanner's tight timeout.
  • Escalation by intent. A simple ping earns a temporary drop; a reverse-shell attempt earns a permanent global IP block. Severity scales with demonstrated malice.
# attacker scans a shadow port · argus responds nmap > 203.0.113.7:22 open › cached banner served in 4ms SSH-2.0-OpenSSH_8.9 (decoy · hallucinated) attacker > attempts reverse shell argus maps toolset · extracts intent intent: malicious → escalate ✓ global block propagated · all edges
07The architecture

Four components, one platform.

Two live at the Internal Network, one in the Open Systems cloud, one in Threat Protection. Together they discover, deceive and contain, without you deploying anything new.

Passive Discovery

Internal Network

Observes traffic to map real hosts and exposed ports, so decoys blend in. No active pinging.

Honeypot Proxy

Internal Network

Opens shadow ports alongside the real ones and transparently tunnels attacker traffic to the decoy engine.

Argus Decoy Engine

Open Systems cloud

Processes payloads, hallucinates responses and maps attacker tools, cloud-scale compute, cheap edge hardware.

Enforcement

Threat Protection

Propagates firewall blocks back to the edge, globally, so one detection stops the attacker everywhere.

Stop building taller walls.

Let Argus turn the network into a minefield, decoys that trap attackers, and containment that spans the globe the instant intent is clear.

Zero-friction deployment Zero false positives Automated global containment
Already a customerEverything you use today keeps running.