Skip to main content
Thumper is an open-source honeytoken platform for detecting credential theft on endpoints. It plants fake-but-realistic credentials in the paths attackers scan first. The tokens authenticate to nothing; a read is the signal. Credential-stealing malware - such as the Shai-Hulud npm worm - scans a machine for ~/.aws/credentials, ~/.npmrc, SSH keys and similar files, then exfiltrates what it finds. Thumper plants a credential file that no legitimate process reads, so a read indicates an attacker enumerating secrets. Thumper is self-hosted and ships as a single Docker image: a React dashboard, a FastAPI server, a database, and pluggable deploy and alert integrations. The on-endpoint agent is pure Bash - no runtime to install on the fleet.

How it works

1

Create a tripwire

Pick a credential type, a source, and a path. The tripwire is a definition - it lives on no machine yet.
2

Distribute its install command

Push the install command through MDM, SSH, or manually. Each machine self-enrolls and plants its own unique honeytoken - unique content and a unique HMAC secret.
3

A read fires the agent

When a process reads the bait, the on-box agent sends an HMAC-signed, enriched callback. The server verifies it, records an alert, and fans it out to the configured SIEM or webhook.

Get started

Quickstart

Run the stack and fire a trigger end-to-end.

How it works

The path from a tripwire definition to a fired alert.

Core concepts

Tripwires, endpoints, deployments, and alerts.

Architecture

One Docker image, three parts, two plugin seams.