DrochaidHorizon3.ai
NodeZero/NodeZero Tripwires
Threat detection & response

NodeZero Tripwires

Bring the attacker's perspective to threat detection.

NodeZero uses pentest findings to drop expert-designed decoys as it discovers critical risk. Tripwires alert in real time when they detect potentially malicious activity. Catch and contain bad actors with autonomous threat detection and deception. Stop guessing where to add threat detection — use production penetration tests and your business context to place decoys strategically, not sporadically.

NodeZero Tripwire alert on the Alerts page
01

Cover your window of exposure

In the real world, organisations are never risk-free. Tripwires reduce the potential blast radius if an attacker breaks in by adding overwatch across the three windows where you remain exposed: remediation that is still in flight; risk you have consciously accepted; and risk you have not yet discovered. Wherever one of those gaps exists, a triggered decoy turns it into a high-fidelity alert before an attacker can capitalise on it.

NodeZero Tripwires alert
02

Active Directory is your biggest risk

Active Directory is the ultimate prize for an attacker. Nearly 90% of Global 1000 organisations rely on it to manage on-prem and hybrid users and assets, and more than 40% of attacks against it end in a compromise (Horizon3.ai) — reach Active Directory and an attacker can move through every system and identity it controls.

03

Why defences keep missing

Attackers don't hack in — they log in. They enumerate accounts, steal Kerberos tickets, and abuse weak trust relationships under the guise of normal activity, evading traditional detection until they escalate privileges, seize the domain, and deploy ransomware or destructive sabotage.

04

Flip the script with AD Tripwires

AD Tripwires are decoy accounts created to catch attackers. They are designed to blend in with production identities — to look exploitable and irresistible — while targeting the specific techniques threat actors use most: kerberoasting, AS-REP roasting, and metadata scraping. A Kerberoastable decoy — a service account with a Service Principal Name (SPN) configured — catches anyone requesting Ticket-Granting Service tickets looking for crackable credentials. An AS-REP Roastable decoy has Kerberos pre-authentication disabled, so any AS-REP request against it is malicious by definition. And credential bait exposed in the `description` field of decoy accounts triggers the moment anyone scrapes domain user attributes. Because these accounts have long, random passwords and no legitimate use, any interaction with them is suspicious by definition — touch one and you know an attacker is in your AD. Pair them with domain controller Kerberos logging (via an included Group Policy) and the detection pipeline needs no additional agent.

NodeZero Tripwires attack-path view
05

Why AD Tripwires matter

AD Tripwires turn identity defence into something you can prove in production. Cut through false positives with high-fidelity alerts the moment a tripwire is touched — proof of real attacker activity instead of noisy guesses. Stop domain admin compromise by detecting privilege escalation attempts in minutes, before attackers reach domain admin. Prove your defences are working by validating that your SOC and detection tools can detect and respond to identity attacks in production. Expose hidden escalation attempts that bypass traditional monitoring, minimising attacker dwell time. And lean on detection methods validated by government-backed research as the only effective approach.

06

How AD Tripwires work

AD Tripwires are planted where attackers escalate — embedded directly into Active Directory, where they appear vulnerable to attack but are in actuality uncrackable. They trigger on credential abuse: from Kerberos ticket harvesting to AS-REP roasting and attribute scraping, the tripwires fire only on real identity misuse, not noise from normal operations. And each alert delivers the context defenders need — showing the attempted attack and revealing the adversary's technique and intention, helping guide investigations.

07

What AD Tripwires prove to your stakeholders

AD Tripwires let a security team demonstrate three things in production, not theory: we are monitoring the crown jewels — the identities and privileges attackers target most; we are validating our identity defences in production, confirming our SOC can detect and respond to real AD exploitation attempts; and we are reducing risk from identity compromise by catching exploitation of AD in real time, before it spreads.

An AD Tripwire detection showing on the NodeZero alerts page
Key features

Autonomous deception, deployed where it matters

A

Smart deployment

Tripwires (decoys and monitoring files) are automatically deployed during pentests as NodeZero exploits assets and proves critical downstream impact. In most cases up to two tripwires are deployed per asset, depending on the asset type.

B

Concrete decoy types

AWS credentials files on Windows, Linux, and network shares; MySQL dump files on Linux and shares; a Windows suspicious-process monitor watching for tasklist.exe, certutil.exe, systeminfo.exe, netstat.exe, and at.exe — chosen for attacker appeal, not convenience.

C

Selected asset coverage

Control to add overwatch against crown jewel assets or assets with lower-level risk exposure reflects your business context.

D

Centralised, real-time alerts

Immediate, detailed alerting in the Tripwires dashboard and via your security tools of choice equips teams to contain breaches, fast.

E

Expert-designed deception

Enticing tripwire types and placement is backed by expert attack research to maximise decoy efficacy while minimising noise.

F

Diverse test coverage

One-click activation within internal, external, AWS, phishing, insider threat, or Rapid Response tests.

G

Integration with your SOC

Integrate Tripwires into your existing incident response workflow with seamless data flow into your SIEM, SOAR, and more.

How it works

Three steps to autonomous threat detection

1

Start a pentest — enable Tripwires

NodeZero deploys appropriate tripwire types onto assets with critical risk as part of one-off or recurring tests, ensuring coverage as soon as exposure is discovered.

2

Add coverage for select assets

NodeZero extends coverage to any assets — whether crown jewels or those with known-but-lower risk profiles — to proactively add detection.

3

Get immediate alerts

When an attacker triggers a tripwire, NodeZero alerts you with relevant information about the threat and pushes it to your SIEM or tools of choice so you can kick off your response.

What customers say
Gaining control of Active Directory gives malicious actors privileged access to all systems and users… bypassing other controls and accessing critical business applications at will.
ASD, NSA, CISA and partner agencies
Detecting and Mitigating Active Directory Compromises
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Deploy autonomous threat detection

NodeZero Tripwires places expert-designed decoys where your pentests prove critical risk exists — and alerts your team in real time when triggered.