How it works
A decoy that is easy to find, and impossible to use
Tripwires runs on a machine of your own and pretends to be something an intruder wants: a file server, a workstation, a NAS. Everything it shows is fabricated, and everything anyone does to it is recorded.
The three parts
The decoy
Fake shares, logins and services that look ordinary from the network. Attempts to log in, passwords tried and files opened are all captured.
Tripwire files
Bait documents you place on your real machines. Opening one quietly calls home, so you learn about an intruder on a PC that has no decoy.
The alert
Push to your phone in seconds, plus a self-hosted channel and email as backup — so one broken path never means silence.
What happens when someone bites
They find the decoy
It advertises itself on the network like any other file server — that is the point.
They open something
A share, a login prompt, a document. Every keystroke of it is recorded, including the passwords they try.
Your phone knows
Who, from which address, and exactly what they touched — within seconds, wherever you are.
They get nowhere
The decoy cannot start a connection back into your network, so what they found is a dead end that reported them.
Containment: the part that matters
A decoy is only safe if a compromised one cannot become a foothold. The appliance enforces a one-way rule: your network can reach the decoy, and the decoy can start no connection back — not to your PCs, not to your servers, not to the internet.
Your data stays yours
Captured events live in a database on your appliance. We do not receive them, cannot read them, and the product keeps working if our servers are unreachable. The only thing that talks to us is licence validation.