Introduction

Platform Overview

Module map for Dashboard, Lure Center, Automation, Research, Integrations, and administration.

Last updated May 2026

Product modules

ModulePurposePrimary users
DashboardReal-time KPIs, Deception Surface Map, recent threatsSOC, managers
Lure CenterCreate, start, stop, and configure decoysDeception engineers
AutomationAutonomous Deception Engine—intel-driven deploymentsDetection engineering
ResearchAnalytics, trends, IP investigation profilesThreat hunters
IntegrationsDNS, WAF, Slack, KE-LA, Hidden HandPlatform / SecOps
AdminTeams, users, scanner groups, detection rulesPlatform owners

Workspaces and teams

H1VE scopes lures, statistics, and integrations to workspaces. Enterprise deployments typically map a workspace per business unit or customer (MSSP model). Users switch workspaces from the profile menu; API tokens inherit workspace context.

Data flow at a glance

Attacker → DNS/edge → Traefik → lure container → batch telemetry export → H1VE backend queue → classification & storage → Dashboard / Research / exports. Internal telemetry (process, file, outbound) follows a parallel ingest path documented under Logs & Telemetry.