Threat Detection & Runtime Security
Detect abusive behavior at the edge, visualize it, scan the software supply chain and optionally enforce runtime policy in the kernel.
Interactive platform map
Architecture in context
The focused blueprint, its required foundation, and declared recommendations.
Threat Detection & Runtime Security
Detect abusive behavior at the edge, visualize it, scan the software supply chain and optionally enforce runtime policy in the kernel.
What this replaces
A private AI stack can still be scanned, attacked, misconfigured or compromised through vulnerable images and runtime behavior.
What your team gains
Layered security using behavioral detection, application remediation, deception, vulnerability scanning and optional eBPF runtime observability/enforcement.
What is inside the blueprint
How it fits the platform
Traffic/code/runtime -> Traefik/CrowdSec + Trivy scheduled scans + optional Tetragon -> decisions/findings/events -> threat map, alerts and operations workflows.
CrowdSec, Traefik bouncer, honeypot, threat-map, Trivy, Tetragon (optional/disabled today), telegram-gateway
- AICORTEX Core PlatformDetection and deception services are Core-managed containers.
- Zero-Trust Edge & IdentityThe CrowdSec bouncer and deception routes attach to the zero-trust edge.
From prerequisites to operation
- Ingress logs
- Security policy
- Scan targets
- Kernel/eBPF compatibility for Tetragon
- Enable CrowdSec collections and remediation
- Connect Traefik logs/bouncer
- Deploy honeypot/threat map
- Schedule Trivy scans
- Introduce Tetragon first in observe mode before enforcement
- Detection/remediation rules
- WAF/AppSec options
- Scan severities/scanners
- Custom secret rules
- Tetragon tracing policies/actions
- Alert routing
- False-positive review
- Bouncer availability
- Vulnerability triage
- Rule updates
- Kernel-policy safety testing
- Threat retention
What this unlocks with other layers
Zero-Trust AI Service
Remote AI access without exposing origin service ports, with centralized authentication and behavioral remediation.
Security Operations Story
Edge attacks, software vulnerabilities and runtime behavior feed one alert and response narrative.