Inside the network

Know they're inside before they reach what matters.

Every security control fails eventually. When one does, the intruder starts exploring. RipTide puts decoys beside your crown jewels so the first wrong turn is the finding, long before ransomware or data theft.

The problem

An intruder's first hours are your best chance.

After initial access, every intruder has to explore: list services, try logins, hunt for credentials. That's when they are most exposed, and when most tools are watching the wrong door.

Detection that leans on anomaly scores turns those hours into a pile of maybes. A decoy nobody legitimately uses turns them into one clear signal.

29 min

average eCrime breakout time, from initial access to moving laterally

CrowdStrike, 2026 Global Threat Report

11 days

global median dwell time before an intrusion is found

Mandiant, M-Trends 2025

57%

of organizations first learned of a compromise from someone outside

Mandiant, M-Trends 2025

How RipTide catches it

Put the tripwires where they'll walk.

No baseline to learn, no thresholds to tune.

  1. 01

    Place

    Run the sensor on hardware you already own, close to what you most need to protect.

  2. 02

    Disguise

    Login portals, Docker and GraphQL services, and web servers that speak nginx, Apache, IIS, Go and uvicorn down to the headers.

  3. 03

    Answer

    Paths nobody documented still get a believable reply, so the intruder keeps going and every request is recorded.

  4. 04

    Investigate

    Any touch is a finding: one investigation with the credentials tried, the paths walked, and a timeline that reads like a story.

Detection coverage

Detection across the intrusion.

Every move an intruder makes while finding their way around.

Moves an intruder makes inside a network, the RipTide decoy that answers each, and what you learn
What the intruder doesThe decoy that answersWhat you learn
Sweeps the network for open servicesDecoys on the ports their real services useWhich host is scanning, and what it's looking for.
Tries passwords on a login pageLogin portals with credential captureEvery sign-in attempt, captured for investigation.
Reaches an exposed Docker daemonDocker decoyWhat it enumerated: the daemon version, containers and images.
Maps an internal APIGraphQL introspection decoyThe schema it pulled and the queries it tried.
Fingerprints the web serverWire-perfect personalitiesThat it took the decoy for the real thing.

The detections that do the work

Where intruders look first.

Every decoy has zero legitimate users. So every touch is a finding.

See every detection

Login portals

Credential capture

A real sign-in form plus Basic and Bearer challenges. Every credential offered is fingerprinted and kept for investigation.

GraphQL & Docker

Classic

GraphQL with introspection switched on, and a read-only Docker daemon, freshly painted.

Wire-perfect personalities

Stealth

Speaks nginx, Apache, IIS, Go and uvicorn, down to header order and error pages.

What lands in your SOC

One finding, not a pile of maybes.

The console groups everything one intruder did into one investigation, ready to export for your SIEM and your incident responders.

  • OCSF 1.3.0 events your SIEM can ingest
  • Credentials tried, captured for investigation
  • Timeline first, raw HTTP and HAR export one click away

Illustrative example. Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.

Questions

Fair questions.

We already have EDR and NDR. Why add decoys?

Those tools judge behavior, so the best they can do is a probability. A decoy has no legitimate users, so a touch is a fact. It also catches what an endpoint agent can't see, like activity from unmanaged hosts.

How much tuning does it take?

Very little. There's no baseline to learn and no threshold to set. If something touches a decoy, that's the finding.

How long does deployment take?

Minutes. Copy one binary to a Linux or macOS machine and run it. In our October 2026 tests on fresh cloud servers, the console was ready 10 to 14 seconds after the first start, and on Linux it runs as a systemd service.

Make contact.

Tell us what your crown jewels are. We'll show you where to put the first decoy.

Book a briefing

Thirty minutes with the people who built it. Bring your hardest question.

  • Watch a live agent set off a detection
  • Map decoys to your crown jewels
  • Plan a first deployment in one sitting

We use your email only to reply. No newsletter, no list, no sharing.

Keyboard shortcuts

T
Change the theme. Shift+T goes back.
?
Show this list
Esc
Close whatever's open