Tactics

  • Detect (Suricata minimal rulesets, targeted sensors)
  • Deceive (OpenCanary service bouquet: SSH/HTTP/PGSQL as lures)
  • Delay (nftables/iptables, tc shaping: windowed thresholds, unlock timers)
  • Notify (local UI, e-paper, chat hooks; actionable summaries)