Marketplace / Blueprint 12
LIVE FOUNDATIONSecurity / security

Threat Detection & Runtime Security

Detect abusive behavior at the edge, visualize it, scan the software supply chain and optionally enforce runtime policy in the kernel.

Review my build
CrowdSec, the Traefik bouncer, the honeypot and the threat map are live. Trivy runs as a scheduled scan, not a resident service. Tetragon runtime enforcement is optional and currently disabled pending an observe/enforce redesign; it is never marketed as active.

Interactive platform map

Architecture in context

The focused blueprint, its required foundation, and declared recommendations.

Core Selected Automatic Required path
Blueprint 12 / Security

Threat Detection & Runtime Security

Detect abusive behavior at the edge, visualize it, scan the software supply chain and optionally enforce runtime policy in the kernel.

2 vCPU4 GB RAM7 services
01 / Problem

What this replaces

A private AI stack can still be scanned, attacked, misconfigured or compromised through vulnerable images and runtime behavior.

02 / Outcome

What your team gains

Layered security using behavioral detection, application remediation, deception, vulnerability scanning and optional eBPF runtime observability/enforcement.

03 / Capability

What is inside the blueprint

CrowdSec Security Engine decisions
Layer 3/4 and Layer 7 remediation options
Traefik/WAF-capable remediation patterns
Virtual patching/application-layer protections where configured
Honeypot/deception endpoints
GeoIP threat visualization
Scheduled Trivy vulnerability scanning
Trivy secret scanning
Trivy IaC/misconfiguration scanning
Trivy license scanning
SBOM input scanning
Tetragon eBPF process/file/network/security observation
TracingPolicy hooks including kprobes, tracepoints, uprobes, LSM and USDT
In-kernel filtering
Runtime actions such as signals/return-value override where supported and intentionally enabled
04 / Architecture

How it fits the platform

Traffic/code/runtime -> Traefik/CrowdSec + Trivy scheduled scans + optional Tetragon -> decisions/findings/events -> threat map, alerts and operations workflows.

Included services

CrowdSec, Traefik bouncer, honeypot, threat-map, Trivy, Tetragon (optional/disabled today), telegram-gateway

Platform requirements
05 / Delivery

From prerequisites to operation

Prerequisites
  1. Ingress logs
  2. Security policy
  3. Scan targets
  4. Kernel/eBPF compatibility for Tetragon
Deployment
  1. Enable CrowdSec collections and remediation
  2. Connect Traefik logs/bouncer
  3. Deploy honeypot/threat map
  4. Schedule Trivy scans
  5. Introduce Tetragon first in observe mode before enforcement
Configuration
  1. Detection/remediation rules
  2. WAF/AppSec options
  3. Scan severities/scanners
  4. Custom secret rules
  5. Tetragon tracing policies/actions
  6. Alert routing
Operations
  1. False-positive review
  2. Bouncer availability
  3. Vulnerability triage
  4. Rule updates
  5. Kernel-policy safety testing
  6. Threat retention
06 / Combinations

What this unlocks with other layers

Zero-Trust Edge & Identity + Threat Detection & Runtime Security

Zero-Trust AI Service

Remote AI access without exposing origin service ports, with centralized authentication and behavioral remediation.

Threat Detection & Runtime Security + AI Operations Center

Security Operations Story

Edge attacks, software vulnerabilities and runtime behavior feed one alert and response narrative.

07 / Technology

Technology behind this capability

TraefikRUNNING - only ingress pathCrowdSecRUNNINGTrivySCHEDULED - not residentTetragonDISABLED BY CHOICEtelegram-gatewayAICORTEX nativehoneypotAICORTEX nativethreat-mapAICORTEX native