Our new “Agent Provocateur” deploys in minutes, lets you know when agents are running wild, and exploits “credulous clankers”.
Read how you too can get a reverse shell on autonomous attacking agents. 💪💚🤖
AI/Agentic attacks have made headlines recently, but agents are highly "suggestible", allowing us to easily detect (or derail) them.
Our new "Agent Provocateur" deploys in minutes & works.
Read more here, including how to ask agents for reverse shells https://t.co/FTFJfIieNg
@ThinkstCanary Deception is about to be the highest ROI defense we have, for a boring reason: an agent can’t triage by smell. It resolves ambiguity by touching the thing. Planted creds don’t get opsec triage, they get used.
We never ambulance-chase, but there's a good reason that smart security teams have suggested honeypots and deception to detect agentic attacks.
Dead simple && Works!
https://t.co/7uNUHJBgDN
Last month:
🌍 free https://t.co/WCHU95kI8v were created in ~75% of the countries around the world;
🤯 a single (@ThinkstCanary) customer deployed >500,000 Canarytokens per hour (embedded in their workflows);
💪 we uncovered at least 1 major breach at an AI cloud infra provider
AI attackers have terrible OPSEC.
Use it against them.
Hallucinate exposed services. Waste their tokens. Seed prompt-injection traps, canaries, and honeytokens where attacker LLM will read them.
Have fun.
You should absolutely watch this talk.
1) It is totally ok to not have a strong opinion 5 secs after it's done;
2) It's kinda great that the agents first created #hack & it all went wrong from there;
3) https://t.co/zMt6TdqnZH remains free - you should absolutely deploy tokens.
At BlackHat, and want to talk about detection that “just works” ?
Pop by our booth (2767) and find out why some of the best security teams in the world run @ThinkstCanary
I often try to convince hacker friends to start product companies (because hackers build cool things && building a company is mostly a series of hacks).
I read the Wright-Brothers biography & it reminded me of bits of company building i often gloss over:
https://t.co/ICIGOCXrBv
Attackers have inserted policy-violating text into malware to trip up agent-based analysis.
Defenders can use this too.
Enable "Guardrail Triggers" when creating Word & Excel tokens on (free) https://t.co/712OurVlda - your tokens will cause agents to bail.
Take it for a spin.