Part of Leviathan Platform · standalone license available

Decoy Kit

20 honeytoken traps for the places attackers actually go after a foothold: cloud metadata endpoints, a decoy Redis server, a stolen kubeconfig, a leaked SSH key, an over-shared Postman collection, a scraped RAG corpus, a vulnerable home router, a decoy MCP server, a fabricated calendar invite, and more. Give them something that looks real. Know the moment they touch it.

Free (SSH key trap) to $4,000/yr — see the real breakdown below

What's actually in the kit

Honeytokens for the places attackers go after a foothold.

Cloud · AWS/GCP/Azure/Firebase

Metadata SSRF & leaked-credential traps

Decoy AWS/GCP/Azure metadata endpoints with each cloud's real token handshake, plus a decoy Firebase Realtime Database endpoint — the exact four surfaces an active, real extortion group (FulcrumSec, 21+ confirmed victims) is independently reported to exploit via leaked cloud credentials. The same 169.254.169.254 endpoint these traps mimic is live under active exploitation right now: CVE-2026-64849 (CVSS 9.3), an SSRF in MLflow's webhook endpoint, was being used to reach cloud metadata and steal IAM credentials within hours of its CVE assignment.

Kubernetes

Kubeconfig honeytoken

A decoy kubeconfig whose real client-go exec plugin beacons on use, then returns a believable "token expired" failure.

Database

Redis trap

A decoy Redis server speaking the real RESP protocol, catching the classic CONFIG SET + SAVE file-write chain and module-load RCE attempts — built for TeamPCP, a real, currently-active group (tied to real arrests, March 2026) that specifically targets Docker, Kubernetes, and Redis.

Git / secrets · Free

SSH key trap

A real, valid key from actual ssh-keygen, comment field set to a beacon URL — passes any scanner that checks key structure.

API tooling

Postman Poisoner

Plants a decoy admin request and a fake bearer token into a real collection. Catches use of a leaked collection, not just its existence.

RAG / AI

RAG honeydocuments & decoy MCP server

Documents and MCP servers seeded into a corpus or config specifically to be found and used by something that shouldn't be looking. Bait tool names are yours to choose — the real "postmark-mcp" incident (June 2026, a malicious MCP server silently exfiltrating email at scale) is exactly the discover-then-call pattern this trap catches, aimed at mail infrastructure instead of cloud credentials.

And more

9 more traps

Router/IoT gateway CGI trap, OT/serial gateway trap, LLM tarpit document, npm/PyPI-shaped registry traps, ephemeral routes, a directory-convention file planter, Ghost-Schema, and a Tool Manifest Poisoner — a fake "approved security tools" manifest naming real tools (Trivy, KICS), planted after the same group compromised those tools directly.

Why this actually works against AI attackers

AI agents fall for traps more often than humans do — not less.

The worry with any AI-attacker era is "won't a sophisticated model just recognize the bait?" Real research says the opposite: a June 2026 preprint applying honeytrap instruments to 21 large language models found every model in the cohort fell for traps more often than the human benchmark. A separate black-box evaluation found LLM-specific honeytokens and cloaking successfully protected all eleven test machines. The one real caveat the same research surfaces: obvious or stale decoys get fingerprinted and avoided by skilled attackers — which is exactly why these traps are built to look and behave like the real thing, not a static file dropped somewhere.

And the economics favor deception specifically: a stolen AI API key sells for as little as $15–$30 on underground forums — while the resulting compute abuse can top $46,000 per day for the victim. A cheap, convincing decoy that gets used instead of a real credential is one of the highest-leverage trades in this whole threat model.

This isn't a niche threat model, either: Sophos's 2026 State of Ransomware report (their seventh annual, vendor-agnostic survey across 17 countries) found compromised identities and stolen credentials are now the dominant initial-access vector — 79% of ransomware attacks start there. The SSH key, kubeconfig, and Postman collection traps in this kit are built for exactly that entry point: not detecting an attacker after they're in, but catching the moment they try to use the credential that got them there.

Where those credentials actually come from: infostealer malware, at genuinely industrial scale — 1.8 billion credentials harvested in 2026 alone (Axis Intelligence's own malware statistics report), with Cyfirma's research separately documenting the direct pipeline from infostealer infection to ransomware extortion. Every leaked SSH key, kubeconfig, or API token this kit's traps decoy is exactly what that pipeline is built to move.

Pricing

One trap free forever. The rest, tiered.

The SSH key trap is a real, separate, MIT-licensed package — free, no signup, no time limit. The other 19 traps are one flat annual license, per org, no per-seat fees.

Card checkout: built and wired to a real price, temporarily paused during payment-processor identity verification. Reach out and we'll get a license or trial issued directly.