Product

How Asteria Deception Cloud works

One Windows agent. Decoy services on the host. A live cloud panel to block and respond — without turning your stack into a SIEM project.

The model in one minute

Local agent runs on the Windows server you authorize. It opens decoy listeners (RDP, SSH, SQL, FTP, …), watches canary/ransomware signals, and can apply firewall rules you request.

Asteria cloud receives heartbeats and attack events, powers the multi-server dashboard, and delivers remote commands (Premium) over authenticated channels.

Your real production services stay yours. Asteria’s job is to make the wrong door loud — then let you shut the attacker out.

Not a replacement for EDR or perimeter firewall. Asteria is a deception + response layer that shortens time-to-detect and time-to-block on exposed Windows hosts.

Install → Attract & capture → Respond

01

Install the agent

Download the Windows installer from asteria.run, run it on the host, and let it register with the cloud. You get a private dashboard path and can link the server to your membership account.

  • Prefer verifying the SHA-256 on the Download page
  • Align decoy ports with change-control before enabling traps in production
  • Create an account first if you manage multiple servers
02

Attract & capture

Enable the bait services you want. Probes, credential stuffing attempts, and ransomware staging signals land in your threat timeline — without opening real databases or domain controllers to the bait ports.

  • Decoy RDP / SSH / MSSQL / MySQL / FTP
  • Canary files and shadow-copy abuse heuristics
  • Source IPs and attempted credentials on decoys only
03

Respond from the cloud

From any browser: review the timeline, auto-block or manually block IPs (AR-BLOCK / AR-INTEL), open remote desktop, kill processes, log off sessions, run Windows Tools & Repair, and clear rules when the investigation is done. Email alerts hit your notify mailbox on high severity (Premium).

What “done” looks like after install

Who it’s for

IT / infra

Windows shops with exposed services

RDP and management ports on the internet, limited SOC bandwidth, need early warning that isn’t “another log silo.”

MSP

Many hosts, one membership

Link agents under one account. Standard for visibility; Premium seats where traps and remote response matter.