RESEARCH FLEET — LIVE PATENT PENDING 49M+ POTENTIALLY ADVERSARIAL EVENTS

Catch threats your other tools miss.

Adaptive honeypots that look and act like your real systems — so attackers reveal themselves the moment they touch one. Built for small security teams, utilities, and municipalities. No analyst army required.

── capture.logREC · ssh-XX78a4e1f0
{{ heroLog }}
A real attacker, captured and classified by our research fleet. They thought this was your server.
  Deploys in an afternoon   No dedicated SOC required   Works fully air-gapped   Minimizes false alarms by design   Priced for small teams
24+
device profiles emulated
13.0M
events captured, 23 Jul – 2 Aug 2026
13.5K
unique IP addresses in that window
5–8×
longer engaged sessions
vs. open-source control
WHAT IT DOES

Deception that adapts in real time

Old-school honeypots follow a script, and attackers spot them in seconds. Ours use a local AI to improvise like a real server — so attackers stay engaged and keep revealing their playbook.

001 Works anywhere — even air-gapped Runs fully offline with local AI, on-prem, or cloud-managed. Nothing leaves your network — safe for ITAR, CMMC, and OT environments.
002 Convincing enough to fool real attackers File systems, credentials, and command outputs are improvised live by AI — never replayed from a static script attackers can fingerprint.
003 Covers IT and plant-floor protocols SSH, HTTP, Telnet, SMB, and SCADA-Modbus — including the OT protocols most vendors ignore.
004 Mapped to MITRE ATT&CK automatically Every session ships as STIX 2.1 / TAXII into your SIEM or inbox inside 60 seconds — no analyst translation step.
005 Attackers stay 5–8× longer Measured against Cowrie controls on the same network. In our most fully preserved run, 29,213 engaged sessions: mean 20.7 s against 4.1 s, median 6.2 s against 1.5 s — 5×. A later run on the same fleet measured 8×. The ratio moves with how you define an engaged session, so we publish the range rather than our best number, and averages rather than our longest single capture. Longer sessions mean more techniques revealed per intruder.
006 Every alert is a real intruder A decoy has no legitimate users, so there is no baseline to model and nothing to triage. False alarms are the exception, not the workload.
HOW IT WORKS

Deploy in minutes, not months

Three steps from download to catching your first threat.

STEP 01

Set the traps

Spin up SSH, HTTP, Telnet, SMB, and SCADA-Modbus decoys with a single configuration file. Each one assumes a realistic persona tailored to your environment.

STEP 02

Let them bite

When an adversary connects, a local AI improvises responses in real time. They interact with what looks and feels like production — revealing tools, techniques, and objectives.

STEP 03

Collect the intelligence

Every keystroke and lateral-movement signal is logged, auto-mapped to MITRE ATT&CK, and shipped to your SIEM or SOC platform as STIX 2.1 / TAXII.

FROM THE RESEARCH FLEET

One real session, captured live

An actual adversary session from the April 2026 research window. The attacker thought they had root on a real Linux server. Every command logged, every technique mapped, the full record in the SOC pipeline inside 60 seconds.

SESSION
ssh-XX78a4e1f0 — redacted
SOURCE IP
XXX.XX.XXX.XXX — redacted
NODE
prod-fleet-llm
LLM BACKEND
Claude Haiku 4.5
BESTIARY MATCH
Human Attacker · rare
SESSION REPLAY {{ replayStatus }}
{{ sessionReplay }}
360K
SESSIONS
13.5K
UNIQUE IP ADDRESSES
5–8×
VS COWRIE CONTROL
0
REAL ASSETS AT RISK

What happened: the attacker spent twenty-two minutes walking around our fake server — reconnaissance, credential dumping, payload staging, log tampering, and a C2 callback. They left with a fake SHA-512 hash they'll spend hours trying to crack. This is the session every SOC should be getting from their perimeter. Most aren't.

FROM THE BESTIARY

Know what's knocking

Every attacker our fleet catches is classified into an archetype and rated on how often you'll meet one — a field guide to the things probing your network, drawn from 7M+ real events.

LEGENDARY 1 in 3,245
RAT Operator
The Puppeteer. Persistent, stealthy remote control — their zombies don't break in, they move in.
RARE 1 in 197
Human Attacker
Fingers on keyboard, brain engaged. Irregular timing and genuine curiosity about what's on the box.
UNCOMMON 1 in 39
ICS/OT Prober
The Substation Stalker. It doesn't want your files — it wants your turbines. Fluent in Modbus, S7, and SNMP.
12 archetypes catalogued so far, and more on the way. Browse the full Bestiary →
RESEARCH

Built on data, not theory

Validated by a multi-cloud fleet capturing real adversary traffic against active attacker infrastructure since early 2026.

FLEET SNAPSHOT — 23 JUL – 2 AUG 2026
13.0Mevents captured in that window
13,486unique IP addresses in that window
37/41ATT&CK techniques observed, of those our classifier maps (the gap is ICS traffic we have not seen yet)
360,081attacker sessions captured in that window
WHY THIS MATTERS IN 2026
82%of 2025 detections were malware-free (CrowdStrike)
82.4%of OT protocol traffic on our sensors is commercial scanning (Deception Check)
3,300industrial organizations hit by ransomware in 2025 (Dragos)
70%of water systems EPA inspected fall short of SDWA §1433 (EPA)
INSIGHTS

From the research blog

View all research →

Field notes, threat breakdowns, and what the fleet is catching — published as we capture it.

FLEET TELEMETRY2026-09-04After the login: what bots sent to a fake FortiGateAcross 53,509 sessions, a FortiGate-persona decoy captured 44 command sessions. Seventeen sessions from eight sources resubmitted the same Linux profiling sequence unchanged, alongside GPU checks, password guessing, and an SSH-first loader.Read →ACTIVE EXPLOITATION2026-09-03SMA1000 is being exploited again. Third time in nine months.SonicWall confirms active exploitation of two new SMA1000 flaws. CISA added both to KEV with a September 5 deadline. The builds that fixed July are affected again, and Rapid7 assesses the flaws can potentially be chained to unauthenticated remote code execution.Read →VULNERABILITY2026-08-26A public PoC changes the priority, not the evidence: CVE-2026-41551Siemens documents unauthenticated arbitrary file read and write in the ROS# file_server service, and rates it CVSS v4.0 9.3. The fixed release shipped on 22 April 2026, before the advisory. What changed on 25 August is that an independent public proof-of-concept appeared demonstrating the read path. That lowers the effort required to test this flaw. It is not, on its own, evidence that anyone is exploiting it.Read →VULNERABILITY2026-08-14The Overflow That Owns the Gateway: CVE-2026-8452Citrix disclosed this NetScaler flaw in late June and called it a crash. On August 14 a working proof of concept turned the same SAML signature bug into unauthenticated remote code execution as root, with persistence. There is no workaround and no confirmed in-the-wild use of this CVE yet, but the sibling flaw from the same bulletin was exploited within 24 hours, and it was caught on decoy infrastructure.Read →ACTIVE EXPLOITATION2026-08-12The Request That Reboots the Firewall: CVE-2026-20349An actively exploited, unauthenticated denial of service in the Remote Access SSL VPN of Cisco ASA and FTD. One crafted HTTP request reloads the firewall, taking the perimeter, the remote access, and the box's own logs down together. Industrials are the top exposed sector, roughly 19,200 instances face the internet, and the federal deadline is August 14.Read →ACTIVE EXPLOITATION2026-08-09Public Exploit Code Is Now Circulating for a Root-Level Palo Alto Firewall Bug: CVE-2026-0300Exploit tooling for an unauthenticated root flaw in the PAN-OS User-ID Captive Portal matured this week into a documented exploit, a payload generator, and a packaged scanner. Plus what our own decoys see around it, with the research scanners stripped out.Read →
THE CAMPAIGN

Three checks. One party.

Deception Check is the first of a family built for the same small teams — detect, govern, and train, without hiring a department for each.

Deception Check Deception Check LIVE
Catch attackers in the act with adaptive honeypots. The detection layer.
Arcana Check COMING
Compliance without the dark arts. Evidence, frameworks, and audits — the governance layer.
20Initiative Check COMING
Roll for initiative. Tabletop incident drills your whole team will actually show up for — the training layer.

Deploy adaptive deception today

Plans start at $99/month — two months free on annual billing.

Deception Check mark © 2026 Deception Check, Inc.
Research Bestiary Pricing Contact