Login portals
Credential captureA real sign-in form plus Basic and Bearer challenges. Every credential offered is fingerprinted and kept for investigation.
Inside the network
Every security control fails eventually. When one does, the intruder starts exploring. RipTide puts decoys beside your crown jewels so the first wrong turn is the finding, long before ransomware or data theft.
The problem
After initial access, every intruder has to explore: list services, try logins, hunt for credentials. That's when they are most exposed, and when most tools are watching the wrong door.
Detection that leans on anomaly scores turns those hours into a pile of maybes. A decoy nobody legitimately uses turns them into one clear signal.
29 min
average eCrime breakout time, from initial access to moving laterally
How RipTide catches it
No baseline to learn, no thresholds to tune.
Run the sensor on hardware you already own, close to what you most need to protect.
Login portals, Docker and GraphQL services, and web servers that speak nginx, Apache, IIS, Go and uvicorn down to the headers.
Paths nobody documented still get a believable reply, so the intruder keeps going and every request is recorded.
Any touch is a finding: one investigation with the credentials tried, the paths walked, and a timeline that reads like a story.
Detection coverage
Every move an intruder makes while finding their way around.
| What the intruder does | The decoy that answers | What you learn |
|---|---|---|
| Sweeps the network for open services | Decoys on the ports their real services use | Which host is scanning, and what it's looking for. |
| Tries passwords on a login page | Login portals with credential capture | Every sign-in attempt, captured for investigation. |
| Reaches an exposed Docker daemon | Docker decoy | What it enumerated: the daemon version, containers and images. |
| Maps an internal API | GraphQL introspection decoy | The schema it pulled and the queries it tried. |
| Fingerprints the web server | Wire-perfect personalities | That it took the decoy for the real thing. |
The detections that do the work
Every decoy has zero legitimate users. So every touch is a finding.
A real sign-in form plus Basic and Bearer challenges. Every credential offered is fingerprinted and kept for investigation.
GraphQL with introspection switched on, and a read-only Docker daemon, freshly painted.
Speaks nginx, Apache, IIS, Go and uvicorn, down to header order and error pages.
What lands in your SOC
The console groups everything one intruder did into one investigation, ready to export for your SIEM and your incident responders.
14:22:09 TOUCH decoy touched: 10.20.3.5:8090 /login 14:22:11 CREDS 3 sign-in attempts captured and fingerprinted 14:23:40 TOUCH docker decoy: GET /containers/json 14:23:40 SOURCE 10.20.1.44, a workstation, first seen 14:21 14:23:41 FINDING hands-on intrusion · 1 investigation
Illustrative example. Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.
Questions
Those tools judge behavior, so the best they can do is a probability. A decoy has no legitimate users, so a touch is a fact. It also catches what an endpoint agent can't see, like activity from unmanaged hosts.
Very little. There's no baseline to learn and no threshold to set. If something touches a decoy, that's the finding.
Minutes. Copy one binary to a Linux or macOS machine and run it. In our October 2026 tests on fresh cloud servers, the console was ready 10 to 14 seconds after the first start, and on Linux it runs as a systemd service.
Tell us what your crown jewels are. We'll show you where to put the first decoy.
Thirty minutes with the people who built it. Bring your hardest question.
Thanks. We'll reply to , usually within one business day.