> ## Documentation Index
> Fetch the complete documentation index at: https://docs.jesta.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Thumper

> Detect endpoint compromise with honeytoken tripwires.

Thumper is an open-source honeytoken platform for detecting credential theft on
endpoints. It plants fake-but-realistic credentials in the paths attackers scan
first. The tokens authenticate to nothing; a *read* is the signal.

Credential-stealing malware - such as the [Shai-Hulud](https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem)
npm worm - scans a machine for `~/.aws/credentials`, `~/.npmrc`, SSH keys and
similar files, then exfiltrates what it finds. Thumper plants a credential file
that no legitimate process reads, so a read indicates an attacker enumerating
secrets.

Thumper is self-hosted and ships as a single Docker image: a React dashboard, a
FastAPI server, a database, and pluggable deploy and alert integrations. The
on-endpoint agent is pure Bash - no runtime to install on the fleet.

## How it works

<Steps>
  <Step title="Create a tripwire">
    Pick a credential type, a source, and a path. The tripwire is a definition -
    it lives on no machine yet.
  </Step>

  <Step title="Distribute its install command">
    Push the install command through MDM, SSH, or manually. Each machine
    self-enrolls and plants its **own unique** honeytoken - unique content and a
    unique HMAC secret.
  </Step>

  <Step title="A read fires the agent">
    When a process reads the bait, the on-box agent sends an HMAC-signed,
    enriched callback. The server verifies it, records an alert, and fans it out
    to the configured SIEM or webhook.
  </Step>
</Steps>

## Get started

<CardGroup cols={2}>
  <Card title="Quickstart" icon="rocket" href="/thumper/quickstart">
    Run the stack and fire a trigger end-to-end.
  </Card>

  <Card title="How it works" icon="diagram-project" href="/thumper/how-it-works">
    The path from a tripwire definition to a fired alert.
  </Card>

  <Card title="Core concepts" icon="cube" href="/thumper/concepts">
    Tripwires, endpoints, deployments, and alerts.
  </Card>

  <Card title="Architecture" icon="sitemap" href="/thumper/architecture">
    One Docker image, three parts, two plugin seams.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.