~/.aws/credentials, ~/.npmrc, SSH keys and
similar files, then exfiltrates what it finds. Thumper plants a credential file
that no legitimate process reads, so a read indicates an attacker enumerating
secrets.
Thumper is self-hosted and ships as a single Docker image: a React dashboard, a
FastAPI server, a database, and pluggable deploy and alert integrations. The
on-endpoint agent is pure Bash - no runtime to install on the fleet.
How it works
1
Create a tripwire
Pick a credential type, a source, and a path. The tripwire is a definition -
it lives on no machine yet.
2
Distribute its install command
Push the install command through MDM, SSH, or manually. Each machine
self-enrolls and plants its own unique honeytoken - unique content and a
unique HMAC secret.
3
A read fires the agent
When a process reads the bait, the on-box agent sends an HMAC-signed,
enriched callback. The server verifies it, records an alert, and fans it out
to the configured SIEM or webhook.
Get started
Quickstart
Run the stack and fire a trigger end-to-end.
How it works
The path from a tripwire definition to a fired alert.
Core concepts
Tripwires, endpoints, deployments, and alerts.
Architecture
One Docker image, three parts, two plugin seams.