Network Deception Vendors: How to Choose
A vendor-neutral set of evaluation criteria, with what each vendor documents publicly.
Last reviewed: October 2026. This guide is vendor-neutral by design: it lists the questions to ask any vendor and summarizes what each vendor documents publicly (sources accessed 2026-10-09). PacketViper is one of the options and is labeled as such. Where a fact is not in public material, this guide says “Not publicly documented”.
What “network deception” covers
Network deception means placing believable decoys, lures or credentials where an attacker will find them, so that any interaction is a high-confidence signal. Products differ in three ways that matter more than the decoy catalogue: where the decoys live, whether the system can act on a touch itself, and whether the product also changes the real network surface.
Three broad models appear in the market. Decoy-first detection places or projects decoys and sends alerts (and, through integrations, containment requests). Endpoint moving target defense changes what an attacker finds inside a host, such as process memory. Network AMTD with inline enforcement changes what an attacker can map on the network and enforces in the packet path. Many environments benefit from more than one.
Seven criteria to evaluate
1. Decoy realism
A decoy that fails a basic fingerprint check teaches the attacker to ignore it.
2. Coverage
Deception only helps where an attacker will actually look.
3. Agent versus agentless
Agents give host-level visibility; agentless approaches protect devices that cannot run software.
4. Inline response versus alert-only
The gap between a touch and a containment action is the window an attacker uses.
5. OT support
OT environments tolerate little active scanning and no unexpected traffic.
6. Operational overhead
A deception program fails if nobody can run it.
7. Integration
Deception output is only useful if it reaches the tools your team already works in.
What each vendor documents publicly
The table summarizes public statements only, as of 2026-10-09. It is a starting point for questions, not a verdict. Each row links to a longer, fully sourced comparison.
| Vendor | Primary model | Agent or agentless | Response at first contact | OT protocols named publicly | Detail |
|---|---|---|---|---|---|
| Acalvio ShadowPlex | Projected, autonomous deception | Agentless (per Acalvio) | Not inline; isolation through integrations | Modbus, BACnet, EtherNet/IP, S7; DNP3 on a separate page | Comparison |
| Fortinet FortiDeceptor | Decoys, lures and honeytokens | Agentless (per Fortinet) | Built-in quarantine plus Security Fabric integrations | BACnet, CAN Bus, DNP3, ENIP, IEC104, Modbus, MOXA, PROFINET, S7COMM, ScadaBR, Triconex, Guardian AST, Kamstrup | Comparison |
| SentinelOne Singularity Hologram | Network decoys; identity deception on the Singularity agent | Decoys: hardware or virtual. Identity: agent | Alerts; containment workflows between identity and endpoint. | ICS-SCADA decoys named; protocols Not publicly documented | Comparison |
| Thinkst Canary | Canary devices and Canarytokens | No endpoint agent described | Alerts | Modbus service; three SCADA personalities | Comparison |
| Morphisec | Endpoint memory moving target defense | Agent | Host-level prevention | Not publicly documented | Comparison |
| PacketViper | Network AMTD with deception and inline enforcement | Agentless network platform; optional endpoint AMTD Agent | Inline, in the packet path | Modbus, DNP3, BACnet, S7COMM | Deception and AMTD |
Vendor statements in this table are drawn from the sources listed at the end of this page[1][2][3][4][5].
Choosing by situation
How to run a fair proof of concept
For the longer, sourced comparisons, see PacketViper vs Acalvio ShadowPlex, PacketViper vs Fortinet FortiDeceptor, PacketViper vs SentinelOne Singularity Hologram, PacketViper vs Thinkst Canary, PacketViper vs Morphisec. For the network versus endpoint question, see AMTD Vendors: Network vs Endpoint Moving Target Defense.
Sources
- Acalvio, ShadowPlex for OT/ICS Security solution brief (PDF, (c) 2024) Accessed 2026-10-09.
- Fortinet, FortiDeceptor data sheet (PDF, FDC-DAT-R23-20260713, dated July 13, 2026) Accessed 2026-10-09.
- SentinelOne, Singularity Hologram data sheet (PDF, code S1-DS_SINGULARITY_HOLOGRAM-05032022) Accessed 2026-10-09.
- Thinkst Canary, “Which personalities and services does my Canary support?” Accessed 2026-10-09.
- Morphisec, Automated Moving Target Defense Accessed 2026-10-09.
It places believable decoys, lures or credentials on a network so that any interaction is a high-confidence signal of reconnaissance or intrusion. Products differ in where decoys live and whether the system can act on a touch itself.
Not always. Detection-first products send alerts and rely on integrations for containment. Inline enforcement shortens the time between a touch and a containment action, and matters most where there is no analyst available at the moment of contact.
For devices that cannot run software, such as PLCs and RTUs, agentless is a requirement. For endpoints, agents can add host-level visibility. Many environments use both.
Define success criteria first, run the same scenarios against each candidate, measure time from first contact to containment, and test failure modes such as loss of management connectivity.
Test inline AMTD against your own criteria
Request a proof of concept and measure time from first contact to containment in your environment.
Explore further
Sourced vendor comparisons and the AMTD primer.