Run the server
The whole stack - React UI, FastAPI server, database, and plugins - ships as one Docker image:Run it from source instead (dev mode)
Run it from source instead (dev mode)
Plant a tripwire on a machine
1
Create a tripwire
In the dashboard, create a tripwire - pick a token type (e.g. AWS access
key), a source, and a path. It’s a definition; nothing is planted yet.
2
Copy its install command
Open the tripwire and copy its install command. It’s generated
server-side and carries the install token, so it’s ready to run as-is:
3
Run it on the target machine
Run that command on the machine you want to protect - paste it into a shell,
or push it through your MDM / SSH / Ansible. The agent downloads itself,
self-enrolls, pulls its own unique honeytoken, plants the bait at the
chosen path, and starts watching. (
sudo is needed so macOS read detection
can use fs_usage.)4
Trigger it
On that machine, read the planted file the way an attacker scanning for
credentials would:The agent sees the read and fires an HMAC-signed, enriched callback to the
server.
5
See the alert
The endpoint lights up as compromised on the dashboard, enriched with the
host, user, and process that did the read - and the alert is delivered to
every configured alert integration. Via the API:
For a server-only smoke test without a second machine, run the bundled agent
with
--simulate. It enrolls and fires one signed callback without planting
anything:Next steps
Deploy integrations
Push tripwires across a whole fleet via MDM or SSH.
How it works
The full path from definition to fired alert.