Skip to main content
Stand up the server, create a tripwire, deploy it onto a machine, and trigger it by reading the bait. The agent runs on the endpoint, so the read it detects is a real read on a real machine.

Run the server

The whole stack - React UI, FastAPI server, database, and plugins - ships as one Docker image:
Open the dashboard at localhost:8000. For a real deployment, run this somewhere your endpoints can reach over the network (a VM, a container host) rather than on your laptop - the agent on each machine calls back to it.

Plant a tripwire on a machine

1

Create a tripwire

In the dashboard, create a tripwire - pick a token type (e.g. AWS access key), a source, and a path. It’s a definition; nothing is planted yet.
2

Copy its install command

Open the tripwire and copy its install command. It’s generated server-side and carries the install token, so it’s ready to run as-is:
3

Run it on the target machine

Run that command on the machine you want to protect - paste it into a shell, or push it through your MDM / SSH / Ansible. The agent downloads itself, self-enrolls, pulls its own unique honeytoken, plants the bait at the chosen path, and starts watching. (sudo is needed so macOS read detection can use fs_usage.)
4

Trigger it

On that machine, read the planted file the way an attacker scanning for credentials would:
The agent sees the read and fires an HMAC-signed, enriched callback to the server.
5

See the alert

The endpoint lights up as compromised on the dashboard, enriched with the host, user, and process that did the read - and the alert is delivered to every configured alert integration. Via the API:
For a server-only smoke test without a second machine, run the bundled agent with --simulate. It enrolls and fires one signed callback without planting anything:

Next steps

Deploy integrations

Push tripwires across a whole fleet via MDM or SSH.

How it works

The full path from definition to fired alert.