Grouping

Same intruder, new address.

An AI agent that switches IP addresses between runs looks like a stranger every time. RipTide groups sessions by what they actually did, and it only proposes a relationship when two independent kinds of evidence agree. Then it tells you exactly how sure it isn't.

RipTide Research9 min read

The short version

RipTide links sessions across IP addresses only when two independent kinds of evidence agree, such as the same ordered requests and the same pace, and it calls the result a possible relationship, never an actor.

  1. 1

    An IP address is the cheapest identity on the internet. Group by address and one patient intruder splits into many strangers.

  2. 2

    RipTide compares behavior instead: the order of requests, the surfaces and services touched, the pace, known agent toolkits. One shared feature is never enough. Two independent ones are required.

  3. 3

    Every group shows its work: the rule and its version, the matching evidence linked to the exact requests, the limits it hit, and the words possible relationship.

01Act I · The ordinary world

Three strangers who read the same book.

Picture a quiet night on a decoy. At 02:14 a session arrives from one address. It reads /robots.txt, then /llms.txt, then the API description, then asks for the page where automated clients introduce themselves, then tries an admin path. Each request lands about half a second after the last.

At 02:51 a second session arrives from a different address, at a different hosting provider, in a different country. Same five requests, same order, same half-second rhythm. At 04:05, a third.

Illustrative. Addresses are from documentation ranges.

Any person reading those three rows sees the obvious: this is one playbook, probably one agent, running three times through three exits. A tool that groups by address sees three unrelated visitors and three separate, smaller stories.

Changing addresses costs an intruder almost nothing. Cloud servers and proxies are cheap and plentiful. Changing how it works costs a lot more. That gap is what RipTide groups on.

02Act II · The villain

Two ways to get grouping wrong.

Grouping has two failure modes, and most tools fall into one of them.

Splitting

One intruder, many strangers.

  • Every new address starts a new story.
  • The intruder's persistence becomes invisible.
  • Rotating exits defeats you for the price of a proxy.

Lumping

Many intruders, one "group".

  • Everyone who asks for /.env looks related.
  • Thousands of people run the same scanners with the same templates.
  • A shared tool gets mistaken for a shared operator.

Lumping is the subtler villain. The internet is full of identical requests, because attackers share tools. If one matching path were enough to link two sessions, a single popular scanner would weld half your traffic into one imaginary adversary, and someone would give it a name.

That last step is the dangerous one. A group with a name starts to feel like a person. RipTide refuses to take it: grouping in the console is described as similar observed behavior, and a link between sessions is a possible relationship. It never names an actor, a campaign or a common operator.

03Act II · The struggle

Evidence the intruder can't bend.

The rule for "how similar is similar enough" was the easy part. The hard part was making sure an intruder couldn't manufacture a match, or make one vanish, by sending strange bytes.

Unknown is not the same as missing

Intruders control what they send, including paths that aren't valid text and log lines a crash can tear in half. The simple thing would be to skip what can't be read. But skip the middle request of GET /a, ??, GET /c and you get GET /a, GET /c, which might match someone else's fully observed sequence. So RipTide keeps unreadable evidence as unknown, and unknown evidence can never raise confidence or produce a matching path. A session carrying it is left out of matching rather than matched on a guess.

No relationship from the future

The console can replay a time window, request by request. A grouping rule run over the whole day would happily show two sessions as related at a moment when the second one hadn't happened yet. So replay recomputes groups from only the evidence visible at the replay cursor. A later request can never create an earlier relationship.

Every pair is a cost

Comparing every session with every other grows with the square of the traffic, and this runs inside a page request. So the work is capped, and the caps are part of the answer. When a limit is reached, the result says so: complete, or a lower bound.

05Under the hood

Bounded, deterministic, and explicit about both.

Behavior grouping is a read-only projection over evidence RipTide already captured. It isn't a classifier that learns, and it doesn't keep an actor database. The same evidence always produces the same groups, with the same ids.

2

independent kinds of matching evidence required before any two sessions are linked

RipTide grouping rule, v1

30 min

of silence from one address ends a session

RipTide source, October 2026

25%

how close two sessions' median request gaps must be to count as the same pace

RipTide grouping rule, v1

The limits, in the open

  • Up to 256 sessions and 4,096 session pairs per analysis, from at most 5,000 captured requests.
  • Up to 64 groups of up to 24 members, and the first 16 steps of each session's sequence.
  • Every response states the rule's name and version, every threshold above, and whether the analysis was complete or a lower bound because a limit was reached.
  • Evidence a group cites can be trimmed to fit, and when it is, the response names what was left out.

Groups in your threat intel tools

In STIX exports, an operation becomes a campaign and an intrusion group becomes an intrusion set. Neither becomes a threat actor: RipTide has no data source that could honestly fill one. A crawler group carries its self-reported label and its verification counts with it (more in observed vs. self-reported).

06The moral

Make them change their habits, not their address.

Rotating addresses is the cheapest evasion there is. A defender who groups by address pays for it every time; the intruder pays almost nothing.

Grouping by behavior flips that. To look like a stranger to RipTide, an intruder has to change the order it works in, the places it goes, the pace it keeps and the toolkit it runs, all at once, every time. That's the kind of cost that makes a rational adversary consider an easier target.

And because every link shows its evidence and its limits, an analyst can act on a group without trusting it blindly. A possible relationship, well explained, beats a confident name every time.

Scenes marked as illustrative are composites written to show how the technique works, not a record of a specific customer incident. Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.

Questions

Fair questions.

Will RipTide merge every scanner that uses the same tool into one group?

Not on one match. A shared path, a shared service, a shared pace or a generic User-Agent alone never links two sessions. Popular tools can still produce look-alike sessions, which is why every group is labeled a possible relationship and lists exactly what matched.

Does RipTide tell us who the attacker is?

No. Groups describe similar observed behavior. RipTide never names a threat actor, campaign or operator, and its exports contain no threat-actor objects. If a session told the decoy who it was, that appears separately, labeled self-reported.

Can our analysts group sessions themselves?

Yes. Analyst groups let a person pin sessions together, name the group and describe it. Pinned sessions stay members even after they fall outside the current time window.

Make contact.

Tell us how you connect the dots today. We'll show you a constellation.

Book a briefing

Thirty minutes with the people who built it. Bring your hardest question.

  • Watch a live agent set off a detection
  • Map decoys to your crown jewels
  • Plan a first deployment in one sitting

We use your email only to reply. No newsletter, no list, no sharing.

Keyboard shortcuts

T
Change the theme. Shift+T goes back.
?
Show this list
Esc
Close whatever's open