Skip to content
@tracebit-com

Tracebit

Tracebit automates the deployment of security canaries and deception technology

Tracebit

Detect attacks in your environment at scale.

Tracebit detects attackers in your environment in real time, with high fidelity, and at scale. It is deception technology built for modern environments: canaries deployed as infrastructure as code, kept fresh automatically by AI, so coverage scales to your entire estate without going stale or ballooning operational cost.

Tracebit deploys canaries wherever an attacker actually lands, across cloud accounts, identity, SaaS, CI/CD, workstations and perimeter sensors, as code, in a single motion.

What is a canary?

A canary is a decoy credential or resource with no legitimate production use. A trigger gives you a high-confidence signal to investigate. Credential canaries alert when someone attempts to use them.

Open source

tracebit-community-cli Command-line tool for Tracebit Community Edition. Deploys and maintains canary AWS credentials, SSH keys, browser cookies, website passwords and emails across your devices and accounts. MIT licensed.

tracebit-community-action GitHub Action that injects canary AWS credentials and SSH keys into your build pipelines, so use of credentials harvested by a compromised dependency or action triggers an alert. MIT licensed.

awesome-deception Curated list of articles, research, guides, talks and tools on cybersecurity deception. Contributions welcome.

tracebit-canary-honeytokens-skill Agent skill for end-to-end canary coverage using Tracebit Community Edition.

Research

Context Bombs — our research into disrupting AI attackers as well as detecting them. A context bomb is text placed inside a canary to trigger an attacking model's safety guardrails. Our working paper reports tests across five frontier models and 152 attack runs. Results depend on the model and attack; see the research for methods, outcomes and limitations.

The trigger strings are published at context-bombs.

Other work:

More at tracebit.com/blog.

Getting started

Community Edition is free. Create an account at community.tracebit.com and install the CLI, then connect it with tracebit auth and place your first canaries with tracebit deploy all.

For cloud accounts, identity providers, CI/CD and Kubernetes at scale, see tracebit.com. Common questions about canaries and deception technology are answered at ai.tracebit.com.

Popular repositories Loading

  1. context-bombs context-bombs Public

    Context bomb strings

    134 5

  2. awesome-deception awesome-deception Public

    An awesome collection of articles, papers, conferences, guides, and tools relating to deception in cybersecurity.

    131 11

  3. find-s3-account find-s3-account Public

    Sample code for finding AWS Account ID of an S3 bucket.

    Python 49 6

  4. tracebit-community-action tracebit-community-action Public

    The Tracebit Community GitHub Action helps developers detect intrusions and supply-chain attacks across their GitHub workflows and pipelines by deploying canary credentials.

    TypeScript 20 3

  5. tracebit-community-cli tracebit-community-cli Public

    The Tracebit Community CLI is the command-line tool for Tracebit Community Edition, which deploys and maintains security canaries, proactively detecting intrusions across your devices and accounts.

    C# 18

  6. tracebit-canary-honeytokens-skill tracebit-canary-honeytokens-skill Public

    Agent skill to set up end-to-end security canary coverage using Tracebit Community Edition

    Shell 16

Repositories

Showing 9 of 9 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Sponsoring

  • @woodruffw
  • @wixtoolset
  • @bigskysoftware

Top languages

Loading…

Most used topics

Loading…