NodeZero Tripwires
Bring the attacker's perspective to threat detection.
NodeZero uses pentest findings to drop expert-designed decoys as it discovers critical risk. Tripwires alert in real time when they detect potentially malicious activity. Catch and contain bad actors with autonomous threat detection and deception. Stop guessing where to add threat detection — use production penetration tests and your business context to place decoys strategically, not sporadically.

Cover your window of exposure
In the real world, organisations are never risk-free. Tripwires reduce the potential blast radius if an attacker breaks in by adding overwatch across the three windows where you remain exposed: remediation that is still in flight; risk you have consciously accepted; and risk you have not yet discovered. Wherever one of those gaps exists, a triggered decoy turns it into a high-fidelity alert before an attacker can capitalise on it.

Active Directory is your biggest risk
Active Directory is the ultimate prize for an attacker. Nearly 90% of Global 1000 organisations rely on it to manage on-prem and hybrid users and assets, and more than 40% of attacks against it end in a compromise (Horizon3.ai) — reach Active Directory and an attacker can move through every system and identity it controls.
Why defences keep missing
Attackers don't hack in — they log in. They enumerate accounts, steal Kerberos tickets, and abuse weak trust relationships under the guise of normal activity, evading traditional detection until they escalate privileges, seize the domain, and deploy ransomware or destructive sabotage.
Flip the script with AD Tripwires
AD Tripwires are decoy accounts created to catch attackers. They are designed to blend in with production identities — to look exploitable and irresistible — while targeting the specific techniques threat actors use most: kerberoasting, AS-REP roasting, and metadata scraping. A Kerberoastable decoy — a service account with a Service Principal Name (SPN) configured — catches anyone requesting Ticket-Granting Service tickets looking for crackable credentials. An AS-REP Roastable decoy has Kerberos pre-authentication disabled, so any AS-REP request against it is malicious by definition. And credential bait exposed in the `description` field of decoy accounts triggers the moment anyone scrapes domain user attributes. Because these accounts have long, random passwords and no legitimate use, any interaction with them is suspicious by definition — touch one and you know an attacker is in your AD. Pair them with domain controller Kerberos logging (via an included Group Policy) and the detection pipeline needs no additional agent.

Why AD Tripwires matter
AD Tripwires turn identity defence into something you can prove in production. Cut through false positives with high-fidelity alerts the moment a tripwire is touched — proof of real attacker activity instead of noisy guesses. Stop domain admin compromise by detecting privilege escalation attempts in minutes, before attackers reach domain admin. Prove your defences are working by validating that your SOC and detection tools can detect and respond to identity attacks in production. Expose hidden escalation attempts that bypass traditional monitoring, minimising attacker dwell time. And lean on detection methods validated by government-backed research as the only effective approach.
How AD Tripwires work
AD Tripwires are planted where attackers escalate — embedded directly into Active Directory, where they appear vulnerable to attack but are in actuality uncrackable. They trigger on credential abuse: from Kerberos ticket harvesting to AS-REP roasting and attribute scraping, the tripwires fire only on real identity misuse, not noise from normal operations. And each alert delivers the context defenders need — showing the attempted attack and revealing the adversary's technique and intention, helping guide investigations.
What AD Tripwires prove to your stakeholders
AD Tripwires let a security team demonstrate three things in production, not theory: we are monitoring the crown jewels — the identities and privileges attackers target most; we are validating our identity defences in production, confirming our SOC can detect and respond to real AD exploitation attempts; and we are reducing risk from identity compromise by catching exploitation of AD in real time, before it spreads.

Autonomous deception, deployed where it matters
Smart deployment
Tripwires (decoys and monitoring files) are automatically deployed during pentests as NodeZero exploits assets and proves critical downstream impact. In most cases up to two tripwires are deployed per asset, depending on the asset type.
Concrete decoy types
AWS credentials files on Windows, Linux, and network shares; MySQL dump files on Linux and shares; a Windows suspicious-process monitor watching for tasklist.exe, certutil.exe, systeminfo.exe, netstat.exe, and at.exe — chosen for attacker appeal, not convenience.
Selected asset coverage
Control to add overwatch against crown jewel assets or assets with lower-level risk exposure reflects your business context.
Centralised, real-time alerts
Immediate, detailed alerting in the Tripwires dashboard and via your security tools of choice equips teams to contain breaches, fast.
Expert-designed deception
Enticing tripwire types and placement is backed by expert attack research to maximise decoy efficacy while minimising noise.
Diverse test coverage
One-click activation within internal, external, AWS, phishing, insider threat, or Rapid Response tests.
Integration with your SOC
Integrate Tripwires into your existing incident response workflow with seamless data flow into your SIEM, SOAR, and more.
Three steps to autonomous threat detection
Start a pentest — enable Tripwires
NodeZero deploys appropriate tripwire types onto assets with critical risk as part of one-off or recurring tests, ensuring coverage as soon as exposure is discovered.
Add coverage for select assets
NodeZero extends coverage to any assets — whether crown jewels or those with known-but-lower risk profiles — to proactively add detection.
Get immediate alerts
When an attacker triggers a tripwire, NodeZero alerts you with relevant information about the threat and pushes it to your SIEM or tools of choice so you can kick off your response.
Gaining control of Active Directory gives malicious actors privileged access to all systems and users… bypassing other controls and accessing critical business applications at will.
Deploy autonomous threat detection
NodeZero Tripwires places expert-designed decoys where your pentests prove critical risk exists — and alerts your team in real time when triggered.