Zero footprint by default · optional integrations, with your authorization · telemetry hosted in the EU
threat contained
decoy
aws-keys
source
203.0.113.42 · ES
threat_score
87 / 100
mitre
T1552.001 · Unsecured Credentials
status: contained · latency: 42ms
01 · Product
A signal only fires when someone shouldn't be there.
NullDec plants autonomous decoys in your environment from the web console. Each one points to our infrastructure, not yours. Legitimately, nobody touches them, so when someone does, it's a real threat.
Zero footprint by default
No resident software, no access to your infrastructure: just plantable artifacts we register on our own backend. Optional integrations only enter your environment with your explicit authorization and permissions scoped to the minimum needed.
Zero false positives by design
A decoy has no legitimate traffic. No rules to tune, no noise to filter: every activation is a confirmed hostile interaction, not a statistical inference over logs.
First-hand intelligence
Every signal is a real activation. We enrich it, map it to MITRE ATT&CK, and correlate it across clients: direct evidence of the actor, not a feed bought weeks late.
02 · How it works
From signal to actionable alert.
Four steps. No infrastructure for you to maintain.
01
Deploy
From the console you generate a decoy and plant it wherever makes sense.
02
An attacker touches it
Interacting with the decoy sends the request to our infrastructure with the real public IP of the source.
03
Enrich and correlate
We calculate a threat_score, infer the MITRE technique, and check whether the same actor hit other clients.
04
You get the alert
Notification by email, Telegram, or Slack, and the full detail in the console: source, technique, and corroboration.
03 · Decoy catalog
A decoy for every surface.
Free covers pure-HTTP decoys. Pro adds real network services, the decoys that get planted inside an AI agent, and the integrations with your cloud and your CI/CD. Enterprise deploys identity, your full fleet, and live AI interaction.
Free€0
7 pure-HTTP decoy types (web bug, email canary, QR, kubeconfig, decoy Word/Excel document, npm package). Up to 5 active decoys.
Pro30-day free trial
Everything in Free, plus 7 real network decoys with no cap (SSH, FTP, HTTP, Telnet, MySQL, RDP, VNC), a network folder decoy, and the three AI-agent decoys. Integrations with Azure, GitHub, and AWS.
EnterpriseLet's talk
Everything in Pro, plus AI-driven high-interaction honeypots, Entra ID, the Nulldec Agent across your full fleet, full attack surfaces on hostnames of your own, and campaigns that chain decoys into each other.
Free · pure-HTTP decoys
Web bugEmail canaryQR codeKubeconfigWord documentExcel documentnpm package
Pro · real network decoys No cap
SSHFTPHTTPTelnetMySQLRDPVNCNetwork folder
Pro · AI agents
An agent with tools can be given an instruction through what it reads. These three decoys live inside its plumbing — its configuration, its knowledge base, and the tool schema it ingests — and they do not fire unless something touches them: every activation is proof that the place was read and that something acted on what it said.
MCP configAgent tool schemaRAG document
And in Enterprise, the way in that reaches the agent itself: a decoy tool registered alongside its real ones. No legitimate flow calls it, so its invocation is not an anomaly to interpret — it is a fact. And by declaring where your agent calls from, the alert tells you whether it was your agent: that address is set by the network, not by the caller.
03b · Pro integrations
Detection inside your own cloud and your own pipeline.
They operate inside your environment, always with your explicit authorization and never by default.
GitHub Pro
Via a GitHub App, injects decoy credentials (AWS, Kubernetes, SSH, MySQL) into your GitHub Actions workflows, built to detect exfiltration from compromised CI/CD pipelines. You choose which repositories to authorize.
AWS Pro
Six decoy resource types: IAM credentials, secrets, S3 bucket, DynamoDB table, Lambda function, and container repository. Works with no setup on our shared trap account, or inside your own AWS account if you connect it, with a scoped-permission role you review and approve.
Azure Pro
Decoy resources (Blob container, table) deployed inside your own subscription, mixed in with your real infrastructure. More credible than an isolated resource in a test account.
03c · Enterprise
Deep presence inside your operation.
Identity, full fleet, and live AI interaction.
High-interaction honeypots Enterprise
Full SSH, Telnet, HTTP, and MCP sessions, with responses generated by AI in real time. It's a real conversation with whoever's interacting, not a fixed simulation. Recorded in full, with a real tool fingerprint (HASSH) and an automatically generated narrative after the activation. Deployable on our shared infrastructure or your own servers.
Entra ID Enterprise
Decoy accounts and applications directly in your Microsoft Entra ID tenant, with one-click admin consent. Any sign-in with the decoy account, or any token request with the decoy app's secret, is an unambiguous indicator.
Nulldec Agent Enterprise
Installable across your entire server and endpoint fleet. Detects each machine's type locally (domain controller, database, web, file server) and deploys the right decoy to each one per rules configurable from the console, including an Active Directory honeytoken account (Kerberoasting with no possible false positives) and the network folder decoy. Only ever calls out, never listens; key revocable per installation.
Attack surfaces Enterprise
A faithful replica of a real system — FortiGate, GitLab, Proxmox, Zimbra — served on a hostname you delegate, or inside your own network. Not a page: front page, login, panel, internal records and API, with the vendor’s own fingerprint and its signature CVE. Whoever gets in stays in, and everything they try is logged and classified by attack class. Nothing goes live without your review.
Deception campaigns Enterprise
Chain decoys so each one leads to the next: the document someone opens holds a server's credential, and that server holds the key to the next bucket. An edge isn't control flow, it's a fiction an attacker can actually follow, so only the credible ones are allowed. Nothing is created until you approve the plan, and the campaign detects on its own when a credential rotated and left a bait pointing nowhere.
04 · Intelligence
Every activation is evidence, not a hypothesis.
The raw signal is automatically turned into structured intelligence, ready for your team or your SIEM.
Threat score
A 0–100 score that weighs corroboration across clients above the volume of a single source, and decays over time if the actor goes quiet.
MITRE ATT&CK mapping
Every signal is translated into its technique and tactic, from reconnaissance to credential use.
Cross-client correlation
If the same actor hits several clients, it's grouped as a campaign and an actor profile (infrastructure, tooling, and target) builds up confidence with every new corroboration.
IOC feed Pro
Corroborated, exportable indicators (STIX/TAXII on Enterprise) to feed your defenses.
Session narrative Enterprise
In high-interaction honeypots, every full session (command by command) is automatically summarized by AI, with a real tool fingerprint (HASSH) and its confidence level.
05 · Plans
Start for free. Scale to collective intelligence.
Free gives you full visibility over your own decoys. Pro adds collective intelligence: corroboration of the same actor across multiple environments, campaign attribution, and an IOC feed exportable to your SIEM. You're not paying for the panel. You're paying to see what a single environment could never show you.