Strategy
Connect business-relevant attacker paths to feasible warning opportunities, owners, and constraints.
Managed deception and early breach detection
Capture closes the gap between owning deception technology and having a working deception capability. Ghostlight identifies the warning opportunities, implements them with your team, validates the complete alert workflow, documents the operating layer, and keeps it aligned as the environment changes.
The customer engagement
The first call establishes fit without a technical assessment or commitment to buy. After contracting, Ghostlight leads the implementation while customer IT owners provide environment knowledge, access, and approvals.
Use the introductory call to confirm the detection concern, alert owner, and commercial boundary. After a signed agreement and the required pre-discovery payment, map the systems, data, and administrative paths an intruder may pursue. Result: a fit decision followed by clear priorities for design.
Design the customer-specific footprint, define alert routes, and obtain written approval for every placement. Result: an authorized deployment plan with owners and removal instructions.
Configure the decoys and tripwires remotely, integrate alert delivery, safely test every route, and document the deployment. Result: a live, tested deception layer and response runbook.
Stabilize the service, oversee asset health, run scheduled reviews, validate alerting, and adapt approved placements as the environment changes. Result: an operating layer that stays aligned with the agreed scope.
Why managed execution matters
Independent NCSC trials found that cyber deception can provide useful visibility, but is not plug-and-play: effectiveness depends on context and strategy, while safe configuration and ongoing alignment require deliberate work. Read the NCSC findings →
Connect business-relevant attacker paths to feasible warning opportunities, owners, and constraints.
Configure believable assets, coordinate approved placement, avoid normal workflows, and retain removal records.
Safely test the complete alert route, establish the first action, and correct failures before acceptance.
Oversee health, review change, remove stale placements, and keep the approved layer useful over time.
What is deployed
Capture is not a license handoff or a generic consulting engagement. Ghostlight selects, configures, places, validates, documents, and maintains the deception layer.
Example path
Server, management, privileged identity, or administrator paths.
Example path
Cloud runbooks, shared files, collaboration spaces, or high-value knowledge.
Managed by Ghostlight
Configuration, asset health, incident context, alert routing, and placement records are maintained in Ghostlight's MSP console.
Investigates, contains, remediates, and makes incident decisions.
Provides deception context and maintains the service within the agreed support boundary.
Illustrative alert
This synthetic example shows the context a Capture placement is designed to provide. It is not a platform screenshot, measured response time, or service-level promise.
Unexpected interaction
What happens next
Confirm whether the interaction came from an approved test, scanner, or expected activity.
Use the source context to identify the originating system and account.
Escalate through the customer's incident process when the activity is unexplained.
Ghostlight explains the placement and deception context. The customer owns investigation and response.
Included in the annual service
Capture is priced around the approved footprint and operating requirements—not individual tokens, hardware markup, or a block of consulting hours.
Priority paths, design rationale, warning opportunities, owners, constraints, alert routes, and removal instructions.
Believable decoys, tokenized tripwires, breadcrumbs, and integrated alert delivery—not a plan left for the customer to implement.
Safe trigger evidence, route validation, asset register, response runbook, and initial acceptance record.
Health oversight, 30-day stabilization, quarterly decisions, and approved in-scope maintenance or removal.
Operating boundary
Automated alerts can arrive at any time. Ghostlight's copy supports service context; it does not create continuous human monitoring or a guaranteed response time.
Fit and boundaries
Buyer questions
Capture complements identity, endpoint, email, network, and SIEM controls by adding tripwires where normal activity should not go.
The proposal provides a planning target based on the high-level boundary established during the fit call. After a signed agreement and the required pre-discovery payment, detailed discovery confirms the exact design, customer dependencies, change windows, alert integration, and delivery schedule before anything is deployed.
Placements are designed to sit outside normal workflows. Ghostlight uses written placement approval, safe trigger tests, customer-coordinated change windows, and removal instructions. Anything touched by legitimate users or automation is adjusted or moved.
The customer supplies environment context and coordinates deployment access. Ghostlight avoids permanent customer cloud-administration access, uses customer-executed or temporary least-privilege deployment where practical, and removes temporary access after validation.
Capture is designed for very low noise because legitimate users and systems should have no reason to interact with its decoys or tripwires. Ghostlight tests placements, documents possible benign causes, and moves anything normal workflows touch. No security provider should promise literal zero false positives.
Alerts can be routed through agreed supported channels including Splunk or another SIEM, Slack, Microsoft Teams, email, webhook, API, or syslog. The standard scope includes one primary integration, a backup customer route, and a Ghostlight service copy.
Not under the standard service. Ghostlight manages the platform while the customer receives agreed alerts and reporting. A dedicated console is evaluated and priced only when required.
Capture is priced as an annual managed service rather than by individual tokens or consulting hours. Ghostlight uses the fit call to define a bounded commercial scope and investment before commitment. After a signed agreement and the required pre-discovery payment, detailed discovery selects the exact placements within that boundary for customer approval.
Yes. Direct ownership can be the right choice for a team that wants to design, authorize, operate, document, test, and maintain its own deception layer. The platform makes deployment accessible; Capture is for teams that want Ghostlight accountable for the customer-specific strategy, safe execution, alert-workflow assurance, controlled records, and ongoing stewardship around it. The customer retains investigation and incident decisions.
The customer receives the alert directly and follows its incident process. Ghostlight receives a copy and can explain the deception asset, why it was placed, and what the interaction means within the agreed advisory boundary. Containment and full incident response are not included in Capture.
Capture uses established deception technology beneath Ghostlight's managed design and operating process. Relevant provider, security, data-handling, and contractual details are available during qualification and customer diligence.
The annual stewardship plan is reviewed quarterly. A review may result in no change, approved maintenance or removal within the contracted allowance, or a separately quoted expansion. Renewal covers continued platform access, validation, placement maintenance, quarterly reviews, and the agreed adaptation allowance.
Next step
Discuss your environment at a high level, the systems or data that matter most, who owns security alerts, and whether a bounded proposal or one-question validation call is the right next step.
No preparation document is required. A rough picture of your environment and the person responsible for security alerts is enough to begin.
Email to schedule the call Review Trust & Security