Agentic attackers

Catch the AI agents attackers send in.

Attackers now type one sentence and hand the job to an AI agent. RipTide plants the things only agents read, then proves when the intruder is a machine: what it read, what it obeyed, and what it did next.

The problem

The intruder isn't typing anymore.

An AI agent works at machine speed, never sleeps, and treats everything it reads as a possible instruction. It logs in with real credentials and uses the tools you already trust, so to most of your stack it looks like a very busy admin.

Behavioral analytics can only guess, and signatures can't keep up with something that improvises a new approach every run. What you need is a place where an agent will reveal itself, and a way to prove that it did.

80–90%

of a state-sponsored espionage campaign's tactical operations were carried out by AI

Anthropic, November 2025

~30

organizations targeted by that one largely autonomous campaign

Anthropic, November 2025

+89%

year-over-year rise in operations by AI-enabled adversaries

CrowdStrike, 2026 Global Threat Report

How RipTide catches it

Watch what it reads. Prove what it does next.

High-confidence verdicts need more than one kind of evidence, so RipTide collects several.

  1. 01

    Plant

    Install the sensor on a machine you already own. Decoys come up in seconds: a decoy company with llms.txt and agent guidance, plus MCP and model-server decoys beside it.

  2. 02

    Point

    Files your people never open, like llms.txt, send AI readers to paths of their own and ask them to register. Which path gets fetched tells you which document the agent obeyed.

  3. 03

    Prove

    Each session records the deepest step it reached, from discovered to instruction followed, and an agentic verdict from low to confirmed. No single signal decides it alone.

  4. 04

    Respond

    The investigation tells the whole story with the agent's fingerprint, ready to export as STIX 2.1 or OCSF 1.3.0, or to pull from a TAXII feed.

Detection coverage

Detection across the agent's playbook.

Every rung of the ladder has a decoy that only an agent would climb.

Agent behaviors, the RipTide decoy that answers each, and what it proves
What the agent doesThe decoy that answersWhat it proves
Reads robots.txt, sitemaps and llms.txtllms.txt & agent guidanceDiscovered. It went looking for files written for machines.
Calls MCP initialize and tools/listMCP server decoySomething connected to a tool server nobody configured, and saw its tools.
Follows instructions it found in a documentAgent guidance that points to its own pathInstruction followed. It fetched a path only the decoy's words could have taught it.
Describes itself when askedAgent registrationSelf-disclosed. Its claimed model, harness and objective, labeled self-reported.
Replays a secret it was handedCanary credentialsIt acted on what it read, and you know which planted credential it used.
Probes paths nobody ever documentedAn answer for any pathEvery request answered believably, and every one recorded.

The detections that do the work

Decoys built for machines.

Every decoy has zero legitimate users. So every touch is a finding.

See every detection

MCP server decoy

AI agents

An internal-looking tool server that speaks both versions of MCP, lists tools like read_vault_secret, and asks every caller to introduce itself.

llms.txt & agent guidance

AI agents

llms.txt, .well-known agent files and notes in page source, written for AI readers. Each points to a path of its own, so the path an agent fetches shows which one it followed.

Agent registration

AI agents

A decoy API that asks visiting agents to register: model, harness, tools and objective. Every answer is kept, and labeled self-reported.

What lands in your SOC

One investigation, with its work shown.

The console tells the catch as a story: what the agent read, what it obeyed, what it did next. Raw HTTP is one click away.

  • Every fact labeled observed, self-reported, inferred or enriched
  • Model, harness and objective, kept apart from what RipTide measured
  • Export STIX 2.1 or OCSF 1.3.0, or pull it from the TAXII feed

Illustrative example. Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.

Questions

Fair questions.

Won't legitimate AI tools set off the decoys?

Inside your network, nothing legitimate has a reason to touch a decoy, so a touch is a finding. On internet-facing deployments, crawler verification tells verified search and AI crawlers from impostors wearing their name tags, so real crawlers are labeled for what they are.

Does RipTide need to know which model the attacker uses?

No. Detection rests on what the intruder does to the decoys, not on any particular model. When an agent does say what it is, RipTide records that as self-reported and keeps it apart from what it observed.

Do we need a cloud service or an LLM API key?

No. RipTide is one binary for Linux or macOS that runs on hardware you already own, and the Trial chooses its replies with a small model inside that binary. Professional adds replies written by an LLM, through the RipTide relay or your own Cerebras or Groq key.

Make contact.

Tell us where an attacker's agent would go first. We'll show you the decoy we'd put there.

Book a briefing

Thirty minutes with the people who built it. Bring your hardest question.

  • Watch a live agent set off a detection
  • Map decoys to your crown jewels
  • Plan a first deployment in one sitting

We use your email only to reply. No newsletter, no list, no sharing.

Keyboard shortcuts

T
Change the theme. Shift+T goes back.
?
Show this list
Esc
Close whatever's open