MCP server decoy
AI agentsAn internal-looking tool server that speaks both versions of MCP, lists tools like read_vault_secret, and asks every caller to introduce itself.
Agentic attackers
An agentic threat actor (ATA) is an adversary that uses AI agents to pursue attack objectives through autonomous or semi-autonomous action. The agent gathers information, picks tools, acts, checks the result and adjusts. RipTide gives it somewhere to do that, and records every step.
The problem
Traditional attackers already use automation to speed up single tasks: writing phishing, generating code, discovering systems. A person still decides what happens next. An ATA delegates that decision too, so the workflow runs with little human oversight, adapts when a technique fails, and can work many targets in parallel.
That lowers the skill an operator needs, and it raises the pace. It also leaves a pattern: an agent has to read, choose and try things, and the techniques underneath (credential theft, lateral movement, probing) are still visible to defenders watching the right places.
80–90%
of a state-sponsored espionage campaign's tactical operations were carried out by AI
+89%
year-over-year rise in operations by AI-enabled adversaries
How RipTide catches it
An ATA's autonomy is its weakness: it believes what it finds and acts on it.
Decoys beside your real systems: MCP servers, model endpoints, llms.txt, login portals and planted credentials.
Nothing legitimate touches a decoy, so the first touch is the finding. The sensor logs what the visitor read and in what order.
Agent guidance sends each reader to a path of its own, so a fetch shows the visitor followed instructions only the decoy contained. A machine is told from a person with evidence.
The investigation tells the whole story, with STIX 2.1 and OCSF 1.3.0 exports and a TAXII feed for your threat-intelligence tools.
Detection coverage
Standard guidance still applies. Decoys add a signal that doesn't depend on spotting a new technique.
| What an ATA does | The decoy that answers | What it proves |
|---|---|---|
| Gathers information and hunts for credentials | Canary credentials, plus believable replies to cloud-metadata and .git probes | Which planted credential was presented, and from where. |
| Selects tools and tries them | MCP server decoy with tools like read_vault_secret | It acted on what it read. |
| Adapts when the first approach fails | An answer for any path | Every new path it improvises is answered believably and recorded. |
| Moves laterally through the network | Login-portal, GraphQL and Docker decoys | Early warning at the moment it leaves its first foothold. |
| Runs the same playbook against many targets | Internet-facing decoys with crawler verification | A picture of the campaign for your threat intelligence. |
The detections that do the work
Every decoy has zero legitimate users. So every touch is a finding.
An internal-looking tool server that speaks both versions of MCP, lists tools like read_vault_secret, and asks every caller to introduce itself.
llms.txt, .well-known agent files and notes in page source, written for AI readers. Each points to a path of its own, so the path an agent fetches shows which one it followed.
A token that grants nothing, planted where intruders look, like a decoy .env. When it comes back to any decoy, RipTide flags it as planted.
What lands in your SOC
Every fact in an investigation is labeled observed, self-reported, inferred or enriched, so you can tell what RipTide measured from what the visitor claimed.
03:02:41 TOUCH decoy read: /llms.txt discovered 03:02:44 FOLLOW fetched the path it was pointed to instruction followed 03:03:10 CRED planted token presented to the internal API planted 03:04:02 CALLBACK signed token came back and validated confirmed agentic
Illustrative example. Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.
Questions
Degree of delegation. A traditional attacker uses AI to speed up a task but makes each decision. An ATA hands the workflow itself to an agent that plans, acts and adjusts with minimal oversight.
No. Those remain the foundation. RipTide adds detection for the moment those controls have been bypassed, and it works the same whether the intruder is a person or an agent.
It follows Huntress's explainer, What is an agentic threat actor (ATA)?
Tell us what you'd least like an agent to do unattended. We'll show you the decoy that watches for it.
Thirty minutes with the people who built it. Bring your hardest question.
Thanks. We'll reply to , usually within one business day.