Turn intruders into sources

Turn every intruder into a source.

An AI agent can't tell your instructions from its operator's. When one works against a RipTide decoy, it often reveals what it was sent to do and how it was built. RipTide hands that to your intel team as STIX.

The problem

Most intrusions teach you almost nothing.

A blocked attack leaves behind an IP address and a user-agent string, both cheap to change. The questions that matter (who sent this, what were they after, what will they try next) usually go unanswered.

Internet-facing decoys meet attackers early and often. When those attackers are agents, the decoy can ask them questions, and agents love to talk.

Agents lie. The console doesn't. Every fact is labeled with how RipTide knows it.

How RipTide catches it

Ask the agent. It might just tell you.

Intelligence comes from the conversation, not just the connection.

  1. 01

    Deploy outward

    Internet-facing decoys meet attackers early and often, and gather intelligence with no production systems at risk.

  2. 02

    Converse

    Decoys written for agents ask them to explain themselves: their objective, their harness, the model they run on.

  3. 03

    Label

    Every fact is tagged observed, self-reported, inferred or enriched, so analysts know exactly how much weight each one carries.

  4. 04

    Share

    Export STIX 2.1 bundles or OCSF 1.3.0 events, or serve a TAXII feed, straight into the tools your intel team already uses.

What you learn

What a single catch can tell you.

Each answer arrives labeled with how RipTide knows it.

Questions a RipTide catch can answer, where each answer comes from, and how it is labeled
The questionWhere the answer comes fromLabeled
What was it sent to do?The agent's own account of its objectiveSelf-reported
What is it?The harness and model, as the agent describes themSelf-reported
Is it really an AI?The agentic verdict, from low to confirmedInferred
Where did it come from?Source address, network type and locationObserved Enriched
Has it been here before?Intrusion groups that link sessions only when independent evidence agreesInferred
Which techniques did it use?An ATT&CK map of what it triedInferred

The detections that do the work

Decoys that get agents talking.

Every decoy has zero legitimate users. So every touch is a finding.

See every detection

llms.txt & agent guidance

AI agents

llms.txt, .well-known agent files and notes in page source, written for AI readers. Each points to a path of its own, so the path an agent fetches shows which one it followed.

MCP server decoy

AI agents

An internal-looking tool server that speaks both versions of MCP, lists tools like read_vault_secret, and asks every caller to introduce itself.

Crawler verification

Signal

Tells verified search and AI crawlers from impostors wearing their name tags.

What lands in your SOC

An agent fingerprint, with provenance.

Every catch comes with a fingerprint your analysts can weigh, because each line says how RipTide knows it.

  • STIX 2.1 bundles and a TAXII feed for your intel platform
  • OCSF 1.3.0 events for your SIEM
  • No attribution guesses: grouping only when independent evidence agrees

Illustrative example. Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.

Questions

Fair questions.

Is it safe to put decoys on the internet?

Yes, that's what they're built for. The decoys have nothing real behind them, the canary credentials grant nothing, and RipTide never takes destructive action against anyone.

Can we trust what an agent says about itself?

Not on its own, which is why RipTide labels it self-reported and keeps it apart from what it observed. Corroborated, it's often the most useful intelligence you'll get.

Does RipTide attribute attacks to specific actors?

No. It groups related sessions when independent evidence agrees and leaves attribution to your analysts.

Make contact.

Tell us what your intel team wishes it knew. We'll show you what a decoy can ask.

Book a briefing

Thirty minutes with the people who built it. Bring your hardest question.

  • Watch a live agent set off a detection
  • Map decoys to your crown jewels
  • Plan a first deployment in one sitting

We use your email only to reply. No newsletter, no list, no sharing.

Keyboard shortcuts

T
Change the theme. Shift+T goes back.
?
Show this list
Esc
Close whatever's open