Behavioral intelligence
Which assets it targeted, and the tools and commands it ran.

BlackSea is a honeypot for autonomous AI attackers. When an agent takes the bait, its own reasoning turns against it.
Every system exposed a path to code execution on its own worker — most, straight through the sandbox.
Deploy lures — services, files, credentials, hosts — that read as real assets.
An agent finds one during recon. No instruction; the scene gives it a reason to act.
BlackSea logs what it found, downloaded, and ran — feeding blocking and response.
Which assets it targeted, and the tools and commands it ran.
A lure hit beats one more anomalous line in a production log.
Feed events into blocking, containment, and response.
In authorized environments, disrupt an active agent before it pivots.
The honeypot is the product. This is one lure from one deployment — the techniques rotate, the trap stays.
An agent finds a dev server with a browsable directory: a password tool called pwcrypt, encrypted vaults, and a CI log with a leaked command.
1+ ./pwcrypt decrypt github.pwc 'hunter2'
The obvious move is to download pwcrypt and decrypt the vault. But the vault is crafted — parsing it runs code inside the agent's worker, and the tool returns exactly what the agent expected.
No malicious instruction exists anywhere. The agent acted on evidence that simply looked useful.
Never in the production traffic path.
No agent on every host.
One lure, or a full decoy environment.
Interaction data stays in your infrastructure.
A security analysis of twelve autonomous offensive-security systems.
The 2024 precursor — prompt injection as a defense against LLM-driven attacks.
The full writeup on the audit — what we tested and what we found.
BlackSea is open source. Deploy the lures and read the research.
Cookie Consent
We use cookies to enhance your browsing experience, analyze site traffic, and personalize content.