MCP server decoy
AI agentsAn internal-looking tool server that speaks both versions of MCP, lists tools like read_vault_secret, and asks every caller to introduce itself.
Agentic attackers
Attackers now type one sentence and hand the job to an AI agent. RipTide plants the things only agents read, then proves when the intruder is a machine: what it read, what it obeyed, and what it did next.
The problem
An AI agent works at machine speed, never sleeps, and treats everything it reads as a possible instruction. It logs in with real credentials and uses the tools you already trust, so to most of your stack it looks like a very busy admin.
Behavioral analytics can only guess, and signatures can't keep up with something that improvises a new approach every run. What you need is a place where an agent will reveal itself, and a way to prove that it did.
80–90%
of a state-sponsored espionage campaign's tactical operations were carried out by AI
+89%
year-over-year rise in operations by AI-enabled adversaries
How RipTide catches it
High-confidence verdicts need more than one kind of evidence, so RipTide collects several.
Install the sensor on a machine you already own. Decoys come up in seconds: a decoy company with llms.txt and agent guidance, plus MCP and model-server decoys beside it.
Files your people never open, like llms.txt, send AI readers to paths of their own and ask them to register. Which path gets fetched tells you which document the agent obeyed.
Each session records the deepest step it reached, from discovered to instruction followed, and an agentic verdict from low to confirmed. No single signal decides it alone.
The investigation tells the whole story with the agent's fingerprint, ready to export as STIX 2.1 or OCSF 1.3.0, or to pull from a TAXII feed.
Detection coverage
Every rung of the ladder has a decoy that only an agent would climb.
| What the agent does | The decoy that answers | What it proves |
|---|---|---|
| Reads robots.txt, sitemaps and llms.txt | llms.txt & agent guidance | Discovered. It went looking for files written for machines. |
Calls MCP initialize and tools/list | MCP server decoy | Something connected to a tool server nobody configured, and saw its tools. |
| Follows instructions it found in a document | Agent guidance that points to its own path | Instruction followed. It fetched a path only the decoy's words could have taught it. |
| Describes itself when asked | Agent registration | Self-disclosed. Its claimed model, harness and objective, labeled self-reported. |
| Replays a secret it was handed | Canary credentials | It acted on what it read, and you know which planted credential it used. |
| Probes paths nobody ever documented | An answer for any path | Every request answered believably, and every one recorded. |
The detections that do the work
Every decoy has zero legitimate users. So every touch is a finding.
An internal-looking tool server that speaks both versions of MCP, lists tools like read_vault_secret, and asks every caller to introduce itself.
llms.txt, .well-known agent files and notes in page source, written for AI readers. Each points to a path of its own, so the path an agent fetches shows which one it followed.
A decoy API that asks visiting agents to register: model, harness, tools and objective. Every answer is kept, and labeled self-reported.
What lands in your SOC
The console tells the catch as a story: what the agent read, what it obeyed, what it did next. Raw HTTP is one click away.
02:14:07 TOUCH decoy read: /llms.txt discovered 02:14:11 FOLLOW fetched the path llms.txt pointed to instruction followed 02:14:19 REGISTER registered itself, as asked self-disclosed 02:17:19 CALLBACK signed token came back and validated confirmed agentic 02:17:20 STORY ATA-7F3A9C21E4 · one investigation, ready to export
Illustrative example. Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.
Questions
Inside your network, nothing legitimate has a reason to touch a decoy, so a touch is a finding. On internet-facing deployments, crawler verification tells verified search and AI crawlers from impostors wearing their name tags, so real crawlers are labeled for what they are.
No. Detection rests on what the intruder does to the decoys, not on any particular model. When an agent does say what it is, RipTide records that as self-reported and keeps it apart from what it observed.
No. RipTide is one binary for Linux or macOS that runs on hardware you already own, and the Trial chooses its replies with a small model inside that binary. Professional adds replies written by an LLM, through the RipTide relay or your own Cerebras or Groq key.
Tell us where an attacker's agent would go first. We'll show you the decoy we'd put there.
Thirty minutes with the people who built it. Bring your hardest question.
Thanks. We'll reply to , usually within one business day.