huntback / deceive

Decoys that capture the whole attack, not a log line

Spin up decoys that look and respond exactly like the products in your stack, deployed where attackers hunt. Nothing on them is real, so every single touch is hostile, and you keep the full evidence.

Deploy a decoySee how it worksNo credit card required.
Full fidelity

Emulate the real product, byte for byte

A decoy is not a banner. It replays byte-exact fixtures captured from the real product, holds stateful multi-step flows, and fakes just enough success to make an attacker proceed and reveal their next move.

  • Byte-exact product fixtures
  • Stateful multi-step emulation
  • Never executes a payload, only captures it
  • Redacted in the shared feed so its identity never leaks
# a decoy comes up as an F5 BIG-IP
decoy f5-bigip live, replaying fixtures
decoy erp-suite live at 4 edge locations
# every request is an attacker.
What you capture

The full chain, kept as evidence

huntback records the whole interaction, not a truncated log line.

โ‰ฃ

Full request bytes

Method, path, headers, cookies and body, with a SHA-256 so you recognise exact repeats.

๐Ÿ”—

Session linkage

Cookie-aware session ids link a multi-step attacker even across IP rotation.

โค“

Stage-2 loaders

The dropper URL the exploit tries to pull, and the malware behind it, deduplicated.

โš‘

Loot harvesting

The fleet fetches the attacker's staged tooling and stores it, hashed and classified.

๐Ÿ›ฐ

Distributed fleet

Disposable decoys across regions, provisioned on demand, torn down when done.

๐Ÿ”’

Zero false positives

There is nothing real to break. If it touched the decoy, it is an attacker.

How it works

From lure to intelligence in five steps

1
DeployPick the products in your stack
2
LureDecoys go live across the internet
3
CaptureFull chain, sessions, payloads
4
HarvestPull the attacker's own tooling
5
Feed forwardInto hunt, code and CVE intel
FAQ

Deception, answered

Is it safe to run a decoy?

Yes. A decoy never executes a captured payload. It fakes responses to keep the attacker talking, and captures everything for you.

Will attackers know it is a honeypot?

The decoy replays byte-exact fixtures of the real product and its identifying strings are scrubbed from the shared feed, so it presents as a genuine, vulnerable target.

Where are decoys hosted?

On a disposable fleet we provision on demand, or in your own infrastructure. You only ever see outcomes for your own decoys.

Turn every probe into evidence

Deploy your first decoy in minutes and watch the intelligence roll in.