Acalvio’s Deception Technology Triumphs at Navy Cyber Challenge
Acalvio’s deception technology delivered 100% true positives and denied 80% of attacker objectives at the U.S. Navy NIWC Pacific ANTX Cyber Challenge, taking first prize for usability, technical performance, and assessors’ recommendations against four other shortlisted vendors. The result lands at a moment when the Navy itself is on record that “standard cybersecurity practices are not enough to fully protect Department of Navy networks from current threat vectors, and that we are now in a post-security environment.” That shift toward an assumed-breach posture is exactly the case Gartner has been making for preemptive cybersecurity, and it’s the case this result validates.
Answer capsule At the U.S. Navy NIWC Pacific ANTX Cyber Challenge, Acalvio’s deception technology achieved 100% true positives (every alert was a confirmed malicious interaction) and denied 80% of attacker objectives against a sophisticated red team. Acalvio was one of five vendors shortlisted from 14 proposals, and won first prize for usability, technical performance, and assessors’ recommendations.
At a glance
- Acalvio won first prize at the U.S. Navy NIWC Pacific ANTX Cyber Challenge, evaluated against four other shortlisted vendors on usability, technical performance, and assessor recommendations.
- Every alert ShadowPlex generated was a confirmed malicious interaction: 100% true positives, with zero analyst time lost to noise.
- ShadowPlex didn’t just detect the red team; it denied 80% of their objectives, actively degrading their ability to complete their mission.
- Detections spanned the full kill chain: initial enumeration, credential access, lateral movement, privilege escalation, and data exfiltration.
- The Navy’s own framing makes the underlying case: standard practices aren’t enough, and assuming compromise is now the operating standard.
The ANTX challenge: what was being tested and why it matters
The Naval Information Warfare Center (NIWC) Pacific hosted its Cyber Resilient Systems (CRS) Advanced Naval Technology Exercise (ANTX) in mid-2025 to identify technologies capable of holding up under this new, assumed-breach standard. From 14 initial proposals, the government down-selected five commercial and non-traditional companies to compete in Charleston.
Each team faced a sophisticated red team, a live adversarial simulation rather than a vendor-run benchmark, and was scored on its ability to detect, divert, and degrade that red team’s progress toward its objectives. That structure matters for two reasons: the field was competitive (five finalists out of 14 proposals), and the test conditions were adversarial rather than self-reported. The ANTX challenge served as a live testbed for assessing deception technology under those conditions.
Acalvio's dominant performance: the headline metrics
Acalvio’s deception strategy didn’t just detect the red team; it degraded their performance and denied their objectives. That result validates deception as a proactive layer for defending high-value assets against advanced, persistent threats across both IT and operational technology (OT) environments. Technical performance broke down as follows:
- 100% true positives: every alert generated was a confirmed malicious interaction, with no false alarms and no analyst time spent triaging noise.
- 80% denial of attacker objectives: Acalvio’s deception layer actively thwarted the red team’s ability to complete its mission, not just flagged its presence.
Those detections covered the full kill chain the red team attempted to move through: initial enumeration, credential access, lateral movement, privilege escalation, and data exfiltration. Catching a red team at enumeration is a different achievement than catching it at exfiltration; covering all five stages is what the 80% denial figure actually reflects.
Technical differentiators: what makes Acalvio ShadowPlex different
Acalvio’s ANTX performance traces back to five technical differentiators, each of which did specific work during the exercise:
- Comprehensive deception as strategy: coverage spans from slowing and detecting attackers to actively disrupting and denying their progress, rather than alerting alone.
- Multi-strategy support: running several deception strategies at once made the environment harder for the red team to map and predict.
- Auto-triaged incidents: correlating related events into a single high-fidelity alert meant the reviewing team worked from one confirmed signal per attack chain instead of dozens of raw events.
- Hyper-realistic deception artifacts: decoys blended into the environment closely enough that the red team could not reliably distinguish them from production assets.
- Diversion tactics: deliberate misdirection cost the red team time and forced it to reveal intent earlier than it otherwise would have.
360 Deception: the three-vector framework behind the results
These differentiators run on Acalvio’s 360 Deception framework: fake assets that look real, real assets that appear deceptive, and intentionally suspicious artifacts that can’t be safely ignored. Combining all three vectors is what let Acalvio move past detection alone and actively deny red team objectives during ANTX. For the reasoning behind the framework, see Why We Built 360 Deception.
What these results mean for enterprise and government security teams
A 100% true-positive rate against a Navy red team is a different kind of evidence than a vendor’s own lab results. It answers the question a financial services CISO or federal security architect actually has: does this hold up against a sophisticated, motivated adversary, not just a controlled demo. The ANTX result sits alongside two other third-party validations. Acalvio has been named a Leader and Outperformer in the GigaOm Radar for Deception Technology for four consecutive years, and Gartner named Acalvio the “Company to Beat” in AI-powered advanced cyber deception.
For teams evaluating deception technology, the practical takeaway is coverage: ANTX validated detection across network, endpoint, identity, and OT surfaces in one exercise, including credential access paths that typically run through Active Directory. That breadth is what separates a point solution from a platform capable of covering the kill chain end to end.
Ready to see what ShadowPlex would surface in your environment? Explore the ShadowPlex Preemptive Cybersecurity Platform or schedule a demo.
Key takeaways
- Acalvio’s ANTX result is adversarial-tested evidence, not a lab benchmark: a live Navy red team, not a vendor-run demo.
- 100% true positives and 80% denial of attacker objectives are two different claims. The first is detection accuracy; the second is active disruption of the attacker’s mission.
- Coverage spanned all five kill-chain stages, from initial enumeration through data exfiltration, not just early-stage detection.
- The 360 Deception three-vector framework (fake-looks-real, real-looks-fake, intentionally suspicious) is the mechanism behind the denial figure, not just the detection figure.
- The ANTX result now sits alongside GigaOm’s four-year Leader and Outperformer recognition and Gartner’s “Company to Beat” citation as a third, independently adversarial data point.
References
- Cyber Resilient Systems Advanced Naval Technology Exercise (ANTX): challenge.gov
- Emerging Tech: Tech Innovators in Preemptive Cybersecurity: Acalvio analyst report
- Assume You Are Compromised: Navy Announces Winners of Cyber Challenge to Seek New Ways of Operating: niwcatlantic.navy.mil
FAQs
A competitive exercise run by the Naval Information Warfare Center Pacific to test emerging cyber defense technologies against a live red team. Five finalists were selected from 14 proposals, and Acalvio won first prize.
It means every alert Acalvio’s deception layer generated during the exercise was a confirmed malicious interaction, with no false alarms. Because decoys have no legitimate business use, any interaction with one is inherently suspicious by design.
Assume-compromise planning treats a breach as inevitable and shifts focus to fast detection and containment. Deception supports that directly: decoys detect attacker presence based on interaction, not on catching an intrusion before it starts.
Preemptive cybersecurity detects and diverts attackers before they reach their objective, rather than only alerting after damage occurs. ShadowPlex delivers this through 360 Deception, engaging attackers with decoys across network, endpoint, identity, and OT environments.
The kill-chain stages ANTX tested, credential access, lateral movement, privilege escalation, are the same stages enterprise and federal security teams defend against daily. A result validated against a live red team carries more weight than a self-reported benchmark.