An answer for any path
Every planProbes for WordPress, .git, Jenkins, cloud metadata or Kubernetes get a believable reply instead of a 404: chosen on the box in Trial, written by an LLM in Professional.
Make yourself the wrong target
Attackers do the math, and AI made attacking cheap. RipTide runs up their cost in time, tokens and exposure until moving on to someone else is the only rational move.
The problem
An autonomous agent can probe target after target for the price of a few API calls. When attacking is that cheap, everyone is worth a try, including you.
Blocking an attacker costs them a second. Holding their attention costs them hours: every request against a decoy is compute, budget and time they don't spend on the systems that matter.
Every minute spent circling a RipTide decoy is a minute not spent on the systems that matter.
How RipTide catches it
All of it happens inside your own decoys. Nothing reaches out to anyone.
Every request gets a believable answer, chosen on the box in Trial or written by an LLM in Professional, so there's no dead end to tip the agent off.
Every path answers and none leads anywhere real, so an autonomous agent can spend its operator's tokens, compute and hours circling decoys.
Wire-perfect personalities and consistent answers keep the agent sure it's making progress.
Every minute they spend is logged as evidence and intelligence for your team.
Where their budget goes
What a long session on a decoy costs them, and what it gives you.
| They spend | On | You get |
|---|---|---|
| Tokens | Reading decoy pages that keep answering | A record of everything it read. |
| Compute | Planning against systems that don't exist | Its plan, step by step. |
| Hours | Paths that lead nowhere | Time for your team to respond. |
| Exposure | Every tool and technique it tries | Indicators for your threat feed. |
The detections that do the work
Every decoy has zero legitimate users. So every touch is a finding.
Probes for WordPress, .git, Jenkins, cloud metadata or Kubernetes get a believable reply instead of a 404: chosen on the box in Trial, written by an LLM in Professional.
Speaks nginx, Apache, IIS, Go and uvicorn, down to header order and error pages.
llms.txt, .well-known agent files and notes in page source, written for AI readers. Each points to a path of its own, so the path an agent fetches shows which one it followed.
What lands in your SOC
The console shows how long an intruder spent on decoys and what they did there, so you can see the cost you imposed.
02:14:07 SESSION ATA-3C9E10B4A7 · confirmed agentic 02:31:55 DEPTH 412 requests across 96 decoy paths 03:02:18 STILL reading /internal/docs/runbooks/… page 37 04:17:10 SUMMARY 2h 03m on decoys · 0 real systems touched
Illustrative example. Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.
Questions
No. Everything happens inside your own decoys. RipTide never reaches out to, or takes destructive action against, anyone's infrastructure. It only answers what it's asked.
In Trial, replies are chosen on the sensor's own CPU, so there's no per-token bill. In Professional, LLM-written replies are capped per minute and per day and cached for an hour, so a noisy scanner can't run up the meter. Either way, one setting turns replies off.
Canned responses are how honeypots get spotted. RipTide answers any path believably and speaks real server dialects down to the headers, which makes a decoy much harder to tell from the real thing.
Tell us who keeps knocking. We'll show you how to make it expensive.
Thirty minutes with the people who built it. Bring your hardest question.
Thanks. We'll reply to , usually within one business day.