Counter-intrusion deception · Mindhawk vertical
Labyrinth
Services that look worth attacking and are not real, a maze of plausible nothingness to hold an intruder in, and decoy credentials that raise the alarm when somebody uses them.
Working · 93 tests · defensive only, never acts against an attacker
The problem it addresses
The intruder who matters is not the one setting off alarms. It is the one who already has valid credentials and looks like a member of staff.
Conventional defences answer the question “is anything unauthorised
happening?” — and a quiet intruder using a stolen password is, to every
system watching, authorised. That is why intrusions are routinely measured in months
before discovery, and why the African Union’s headquarters transmitted data to
Shanghai nightly for five years before one person happened to notice.
Labyrinth answers a different question: is anybody touching things that only an
intruder would touch? Nobody legitimate opens a file called
credentials-backup in a share they have no business in. Nobody legitimate
requests /.env from a web server. When somebody does, there is no
ambiguity to triage — which is why this is the highest-confidence signal in the tool
and why it produces almost no false alarms.
What it puts out
Each one is a service an attacker expects to find on a neglected internal machine.
A login that never finishes
An SSH host that holds a connection open indefinitely without ever completing the handshake. Cost to you: one socket. Cost to them: a stalled tool, often for hours — and their software identifies itself before anything else happens.
A fileserver with no bottom
Every folder exists and every folder opens into more. The contents are the same on every visit, which matters: a decoy that renders differently each time is identified in two requests.
Files only an attacker asks for
Credential files, configuration, database dumps, private keys. Each returns plausible, poisoned content and raises a high-confidence alert. No legitimate user requests any of them.
Credentials that report their own use
Each decoy carries a credential that alerts when it is used, naming which decoy it was taken from — so the signal arrives even if the file was copied off the machine entirely.
A login that accepts anything
File-transfer and terminal logins that always succeed, slowly, recording every username and password tried. On a system with no real accounts, every credential sprayed at it is intelligence about the attacker.
Alerts that leave the machine
Findings go to your own operations centre, not to a file on the host the intruder is standing on. A tripwire nobody hears is not a tripwire.
Can you trap an intruder in it?
The question everybody asks, and three different things get called trapping. The
answers are not the same, and the difference is worth being precise about.
Holding them — yes, and it is measurable
The way out recedes faster than they can walk towards it
A crawler is not held by a lock. It is held by arithmetic: every page it fetches
yields more links than the one request it spent fetching it. Measured against
this implementation, a sequential crawler spent 75.9 seconds to make 42
requests and reach a depth of three — and finished with 175 links still
unexplored, a backlog growing by roughly four links for every request
served. Responses also slow down the deeper they go, which reads as an
overloaded internal server rather than a trap. A complete search is not slow.
It is impossible, and the only exit is to give up.
Confining them — no, and we will not claim it
Nobody can lock a door on somebody else’s computer
Nothing here controls their machine, their process or their route out; they can
disconnect whenever they choose. Building anything that tried to prevent that
would mean acting on a machine that is usually a third party’s compromised
equipment. Any supplier who tells you they can hold an intruder against their
will is describing either a fantasy or a crime.
Containing them — yes, and this is the one that matters
Make what they found genuinely be a dead end
Place the deception host on a network segment with no route to anything real.
Then the trap is not a claim about software, it is a fact about your network:
what they are working on leads nowhere, and every hour spent on it is an hour
not spent on a system that matters. That is what the time actually buys
— a window in which you know and they do not.
One number to be honest about. A single connection is released after
a configurable interval, fifteen minutes by default rather than forever, and a
scanner that sets its own timeout leaves sooner than that. Holding is worth having
and it is not the product. The product is knowing — the hours
matter because of what you do with them.
What you get out of it
Not a log file. A reconstruction, per intruder, of how far they got — where each stage is the furthest point there is actual evidence for.
01touchedConnected to something that is not real.
02engagedStayed, or came back — this is no longer a passing scan.
03enumeratingWorking through the structure, looking for something specific.
04credentialsTrying logins — which reveals the breach corpus they are working from.
05bait takenRequested something no legitimate user requests. Effectively conclusive.
06credential usedUsed a credential stolen from a decoy. Confirms both the theft and the intent.
Alongside it: their tooling, how long they were held, which decoy each stolen credential
came from, and the evidence behind the assessment printed next to it —
because a confidence score with no reasoning attached is one an analyst can neither
check nor defend.
The record survives being challenged. The event log is chained, so
altering or removing an entry is detectable and names the entry. The running total is
published off the machine, which is what also makes removing the end of the log
detectable — the one thing a chain cannot catch on its own.
Where the line is
We are asked whether the decoy can locate the intruder, or serve them something. The
answer is settled, written down, and governs every future change.
Rule 01
It never initiates contact with the intruder’s infrastructure
No scanning, no probing, no response traffic. Every signal it holds arrived because they reached it. The code is audited against this: the only outbound connections in the process go to the alert collector the operator configured.
Rule 02
Nothing it serves is built to execute, exploit or damage
False documents, yes — that is the product. Payloads, responses designed to crash their tooling, and anything that runs on the other machine, never. Deception is content; a payload is a weapon, and the difference is not one of degree.
The first reason is practical rather than principled: the machine attacking you
is usually a third party’s compromised equipment — a hospital, a
university, a small business in another country. Attribution from a single address is
wrong often enough that acting on it means acting against another victim. The second is
that acting on what is found belongs to your own operators, under your own legal
authority, and does not transfer to a tool you bought.
It never claims to hack back, and it never will. If active response is
ever wanted it would be a different product with a different licence and a different
liability — not a setting in this one, because a setting would make every deployment
everywhere a tool that can do it.
What it does not do
Each of these is checkable, and each is better heard from us first.
It is a tripwire, not a perimeter
An intruder who touches none of the decoys is not detected. It complements monitoring, firewalls and patching; it replaces none of them.
It is not undetectable
Timing, the absent key exchange and the maze’s unlimited depth are all tells under close inspection. It buys time and signal, not invisibility — and anyone selling a deception system as undetectable is wrong.
It detects credentials being used, not files being read
Copying a decoy file produces no signal; using the credential inside it does, and names the decoy. We would rather say this than let an evaluator discover it.
It has not yet faced a real intruder
93 local tests, including a suite that plays the attacker, is not a deployment record. It will not be described as proven in the field until something has actually tried it.
Before it leaves a laboratory. It binds to the local machine by default
and goes nowhere else until deliberately configured. Moving it requires written
authorisation naming the host and the interface — deception on infrastructure you do not
own is somebody else’s intrusion — plus an agreed retention period and lawful basis
for the logs, because source addresses are personal data.