DECEPTION ENGINEERING // TRIPWIRE LABORATORY v7.1.1
0% FALSE POSITIVE PROBABILITY
ADVERSARY DECEPTION // CANARY LAB
Legitimate users have no reason to touch decoy credentials, query fake Active Directory SPNs, or read world-writable shadow backups. Plant these tripwires across your network, cloud accounts, and repositories. When an intruder moves, catch them instantly.
ACTIVE DECOY MINEFIELD
2 TOKENS
TRIPWIRE BREACHES
1 DETECTIONS
DETECTION FIDELITY
100% EVIDENCE
RADAR AUDIO
STEP 01 // SELECT DECEPTION ARCHETYPE
Choose Bait Objective
Recommended Deployment: ~/.aws/credentials on developer laptops, Git commit history, or public S3 bucket
INCIDENT RESPONSE RADAR // TELEMETRY HUB
Active Deception Minefield
aws-iamHASH: 7f4c9a812b4e0193|DEPLOYED: 9/6/2026
Staging-S3-Backup-Reader
INTRUSION TELEMETRY HISTORY (1 EVENTS)
UNC4192 (Fin-Threat Group)[185.220.101.5]
5:06:37 PMACTION: aws sts get-caller-identity
LOCATION: Frankfurt, Germany (Tor Exit) | USER-AGENT: aws-cli/2.13.1 Python/3.11.4 Linux/6.2.0
ad-kerberoastHASH: 90e1ab44cd871234|DEPLOYED: 9/7/2026