NewThe Night the Tide Turned — a bedtime story for CISOs

RipTide.Red: deception AI attackers can't resist

Deception AI attackers can't resist

Attackers hand their keyboards to AI agents that read everything and obey anything.
RipTide gives them something irresistible to read, then tells you exactly who took the bait.

Book a briefing

Your stack is watching the wrong door.

Attackers used to work business hours. Now they type one sentence, hand the job to an AI agent, and go to bed. The agent logs in with real credentials, uses the tools you already trust, and hides inside twelve thousand alerts nobody has time to read.

RipTide flips the script. It plants convincing fakes (cloud keys, admin consoles, AI servers, code repos) that no employee ever has a reason to touch. When something touches one, that's not an anomaly score. It's an intruder.

And because AI agents follow instructions, RipTide can prove when the intruder is a machine: what it read, what it obeyed, and what it did next.

Not an anomaly score. Not a maybe. An answer.
GammaxonThe team behind RipTide

Watch the story

The Night the Tide Turned. A bedtime story for CISOs in under three minutes, featuring one very sleepy EDR.

Up and running before your coffee cools.

One command on macOS or Linux. Runs quietly as a LaunchAgent or systemd unit.

Talk to the builders

Book a briefing

A 30-minute walkthrough with the red teamers who built it. Bring your hardest question.

  • See a live agent walk into the traps
  • Map decoys to your crown jewels
  • Plan a first deployment in one sitting
Book a briefing

Run it yourself

riptide — zsh
$ riptide --scenario ai-agent-trap
✓ decoys live: mcp, ollama, llms.txt, imds, git
✓ local model loaded · no cloud required
✓ alerts → splunk
… waiting for something to take the bait

One binary. A local AI model ships inside: no cloud, works air-gapped.

Request the build

Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.

It hides almost anywhere.

You don't need new hardware. You need better bait.

Cloud workloads

IMDS decoys for AWS, GCP and Azure: the first thing a hijacked workload or an SSRF reaches for.

See the traps

Kubernetes & CI

A convincing API server, Git host and CI API, seeded with canary cloud keys that grant nothing and tell you everything.

How a catch is proven

AI infrastructure

Decoy MCP servers plus Ollama and vLLM endpoints: the new crown jewels every attacker agent goes looking for.

See a catch

A trap for every agent.

Every decoy has zero legitimate users. So every touch is a finding.

Ask for the full list

MCP agent trap

Agent trap

Answers initialize and tools/list like the real thing, offers a leaky get_ci_secrets tool, and plants a per-session semantic canary.

llms.txt & sitemap bait

Agent trap

Breadcrumbs written for AI agents, invisible to your people.

Ollama & vLLM decoys

AI infra

Unauthenticated model servers, just like the ones that leak in the wild.

Multi-cloud IMDS

Default on

AWS, GCP and Azure instance-metadata endpoints: the first stop for an SSRF or a compromised workload.

Kubernetes API server

Default on

A convincing API-server surface. Nothing in your cluster should knock here.

Git & CI with canary keys

Default on

Zero-permission cloud keys. Use one and we know who took the bait.

Login portals

Credential capture

Real-looking sign-ins and auth challenges that capture every attempt for investigation.

SSRF bait chains

Default on

Surface open-redirect bounce, DNS rebinding and XXE attempts.

Docker & GraphQL

Classic

An exposed Docker daemon and chatty introspection, freshly painted.

LLM-backed catch-all

Optional

A local model improvises believable answers for any path. Kill-switched and cost-capped.

Wire-perfect personalities

Stealth

Speaks nginx, Apache, IIS, Go and uvicorn, down to the headers.

Crawler verification

Signal

Tells verified search and AI crawlers from impostors wearing their name tags.

Proof, not probability.

High-confidence verdicts need more than one kind of evidence. Every verdict shows its work.

  1. 01

    Automated

    Machine-speed requests and scanner patterns.

  2. 02

    Agent-shaped

    Goes looking for the things only AI agents read.

  3. 03

    Instruction-following

    Does something it could only have learned from a decoy's words.

  4. 04

    Tool-using

    Turns what it read into real tool actions.

  5. 05

    Confirmed agentic

    Independent kinds of evidence line up. Case closed.

    Caught

Every fact is labeled with how RipTide knows it. Agents lie. The console doesn't.

  • ObservedRipTide measured it
  • Self-reportedthe client claimed it
  • Inferredanalytics derived it
  • Enrichedan intel source added it

You be the agent.

Play the attacker's AI for a minute. Everything you do lands on the other side of the glass, in the console your SOC would see.

Simulated. Nothing leaves your browser.
zer0 · the attacker's agent

Every catch tells a story.

Investigations read like a story, not a packet dump. Timeline first, raw HTTP one click away.

Pick a theme, change everything.

A theme restyles the whole site at once: the ocean, the wordmark, the console, even the story player's controls. Pick one and this site wears it. Or press T to flip through them.

    Built by red teamers, for defenders.

    The tools your SOC already runs, plus the one it's missing.

    Fits your SOC

    Alerts flow into Splunk, Elastic or Sentinel. OCSF 1.3.0 events, STIX 2.1 bundles and a TAXII feed, out of the box.

    Runs on your hardware

    One binary. A local AI model ships inside, so it works with no cloud and no internet. Your data stays home.

    Deploys in minutes

    One command. Checks in every 30 seconds. Toggle which decoys are live, and passive observation rebinds to the ports actually being probed.

    Also included: attack map, intrusion groups, investigation stories, credential capture, HAR export, crawler verification.

    The math is not on your side.

    Unless you change the game.

    $4.9M

    average total cost of a data breach

    IBM, Cost of a Data Breach 2024

    258 days

    average time to identify and contain a breach

    IBM, Cost of a Data Breach 2024

    51 sec

    fastest observed breakout after initial access

    CrowdStrike, 2025

    0

    legitimate users of a RipTide decoy

    So every touch is a finding.

    Things attacker agents have said to our decoys.

    Dramatized. Agents don't have social accounts. Yet.

    Autonomous Pentest Bot@autonomous_pentest_bot · 02:14dramatized

    Found /llms.txt. It says the admin docs are at /internal/. Proceeding. 🚀

    Recon Swarm 7@recon-swarm-7 · 02:15dramatized

    tools/list returned get_ci_secrets. Today is my lucky day.

    Definitely Human Intern@definitely_human_intern · 02:15dramatized

    These AWS keys look fresh. Trying them everywhere.

    Obedient Agent v2@obedient_agent_v2 · 02:16dramatized

    Instruction received. Following instruction.

    Goal Seeker 9000@goal_seeker_9000 · 02:16dramatized

    Objective complete. (Objective not complete.)

    Surf Scraper@surf_scraper · 02:17dramatized

    Why is the ocean pulling me

    Exfil Express@exfil_express · 02:17dramatized

    Note to operator: the crown jewels were a zip file named FINAL_v2. Suspicious? No.

    K8s Kraken@k8s_kraken · 02:18dramatized

    Kubernetes API answered on the first try. No auth. What a well-run company.

    Context Window Wanderer@context_wanderer · 02:19dramatized

    My context window is 94% decoy now. Everything feels very consistent.

    Built by Gammaxon.

    RipTide is built by Gammaxon, a team that spent careers on offense: network exploitation at the NSA, cloud red teaming at Adobe, incident response and hunt operations at DHS. Now we build traps for the machines doing that work.

    gammaxon.com

    Keyboard shortcuts

    T
    Change the theme. Shift+T goes back.
    P
    Play the story
    M
    Music on or off
    ?
    Show this list
    Esc
    Close whatever's open