Moving-Target Defense
Moving-target defense that starves ransomware of reconnaissance
Attackers succeed by studying a fixed environment until they know it better than its defenders. Immune takes that advantage away. It continuously changes the shape of your environment, so the map an attacker builds is obsolete by the time they try to use it.
Immune's moving-target defense rotates decoys and shifts internal characteristics so that attacker reconnaissance goes stale — turning a static target into a moving one, and often tripping a deception trap in the process.
Why attackers love a target that stays still
Almost every serious cyberattack begins with reconnaissance. Before an attacker strikes, they spend time learning the environment: which systems exist, how they are named and arranged, where the valuable data lives, and where the defenses are. This mapping is what makes a later attack fast and precise. It is also something defenders have traditionally handed to attackers for free, because most environments are static. Once an attacker has mapped a network, that knowledge stays valid for weeks or months, and they can act on it whenever they choose.
Moving target defense inverts this dynamic. Rather than presenting attackers with a fixed landscape to study at their leisure, it keeps the landscape in motion. The decoys that lure attackers change their names and locations. Aspects of the internal layout shift on a schedule and in response to suspicious probing. The result is that reconnaissance decays: what an attacker learned last week no longer describes the environment this week, so a carefully prepared attack plan misfires. It is a fundamentally proactive form of defense — it does not wait for an attack to begin before making the attacker's job harder.
See it in action
The moving-target console logs every morph event, shows environment entropy over time, and visualizes how attacker recon value decays after each rotation.

Features
What moving-target defense provides
Rotating decoys
Canary names, locations, and characteristics change continuously so attackers can't learn them.
Shifting internal layout
Selected environment characteristics vary over time, so a static map loses accuracy.
Probe-triggered morphing
Detected reconnaissance immediately reshapes the affected area, devaluing the scan.
Scheduled reshaping
Regular, automatic morphing keeps reconnaissance perpetually out of date.
Seamless for real users
Authorized access is unaffected; only attackers relying on stale knowledge are tripped.
Deception-coordinated
Works with the deception engine so traps stay unpredictable and unavoidable.
How it works
How moving-target defense works
Establish the moving parts
Immune identifies the decoys, access paths, and internal characteristics that can safely be varied.
Morph on a schedule
These elements are reshaped automatically at intervals, so reconnaissance decays continuously.
React to probing
When scanning or probing is detected, Immune immediately re-morphs the affected area.
Protect legitimate access
Changes are applied so that authorized access through normal channels is never disrupted.
Push attackers into traps
Unpredictability drives attackers into deception, turning their next move into an alarm.
Advantages
The advantages of a moving target
Stale reconnaissance
An attacker's map expires before they can use it.
Higher attacker cost
Planning becomes unreliable and repeated effort is wasted.
More trap encounters
Unpredictability pushes attackers into deception traps.
Proactive protection
Degrades an attack before it begins, not just after.
Zero user friction
Legitimate clinical work is completely untouched.
Compounds the loop
Strengthens deception and detection across the whole platform.
Use cases
Where moving-target defense helps
Defeating reconnaissance
Make the mapping attackers rely on unreliable and short-lived.
Protecting decoys
Keep canary traps unpredictable so attackers can't learn and avoid them.
Slowing targeted attacks
Force attackers to re-map repeatedly, wasting their effort and time.
Raising the cost of intrusion
Make your environment expensive and unreliable to attack.
The final expression of the immune idea
A defense that adapts to make the host harder to infect
In Immune, moving target defense is tightly woven with deception. Deception sets the traps; moving target defense keeps them unpredictable, so an attacker cannot simply learn the layout of decoys and route around them. Together they create an environment that is not just watched but actively hostile to reconnaissance — one where an attacker's natural first steps are the ones most likely to give them away. It is the final expression of the immune-system idea: a defense that does not merely react to infection, but continually adapts to make the host a harder place to infect at all.
Common questions
Moving target defense, answered
+What is moving target defense?
Moving target defense is a proactive strategy that continuously changes aspects of an environment — such as decoy placement and internal layout — so that the reconnaissance an attacker performs becomes outdated. Instead of defending a static target, you keep the target moving, which raises the cost and lowers the reliability of an attack.
+How does moving target defense stop ransomware?
Ransomware operators rely on mapping an environment before they strike. By rotating decoys and shifting internal characteristics, Immune ensures that what an attacker learned yesterday no longer holds today, so their plan misfires — often tripping a deception trap in the process.
+Does morphing disrupt legitimate users?
No. Immune's moving-target changes are applied so that access authorized through normal channels is unaffected. Only an attacker relying on stale reconnaissance is disrupted; clinicians and systems continue to work normally.
+Is this the same as deception?
They are closely related and work together. Deception plants the traps; moving target defense keeps them — and the wider environment — unpredictable, so attackers cannot learn which assets are real and which are decoys.
+Is moving target defense proactive or reactive?
It is one of the few genuinely proactive controls. It degrades an attacker's capability before they act, by making the reconnaissance they depend on unreliable — rather than waiting for an attack to begin before responding.
+Does it react to probing?
Yes. When Immune detects reconnaissance or probing, it can immediately reshape the affected decoys and access paths, so the very act of scanning devalues what the scan finds.
Explore the platform
Related capabilities
Turn your environment into a moving target
Book a demo and see how Immune keeps attackers guessing — and keeps their reconnaissance perpetually out of date.
