Precise detection.
Immediate certainty.

NullDec cuts threat detection time from hours to seconds, with no noise and no false positives.

Zero footprint by default · optional integrations, with your authorization · telemetry hosted in the EU

01 · Product

A signal only fires when someone shouldn't be there.

NullDec plants autonomous decoys in your environment from the web console. Each one points to our infrastructure, not yours. Legitimately, nobody touches them, so when someone does, it's a real threat.

Zero footprint by default

No resident software, no access to your infrastructure: just plantable artifacts we register on our own backend. Optional integrations only enter your environment with your explicit authorization and permissions scoped to the minimum needed.

Zero false positives by design

A decoy has no legitimate traffic. No rules to tune, no noise to filter: every activation is a confirmed hostile interaction, not a statistical inference over logs.

First-hand intelligence

Every signal is a real activation. We enrich it, map it to MITRE ATT&CK, and correlate it across clients: direct evidence of the actor, not a feed bought weeks late.

02 · How it works

From signal to actionable alert.

Four steps. No infrastructure for you to maintain.

01

Deploy

From the console you generate a decoy and plant it wherever makes sense.

02

An attacker touches it

Interacting with the decoy sends the request to our infrastructure with the real public IP of the source.

03

Enrich and correlate

We calculate a threat_score, infer the MITRE technique, and check whether the same actor hit other clients.

04

You get the alert

Notification by email, Telegram, or Slack, and the full detail in the console: source, technique, and corroboration.

03 · Decoy catalog

A decoy for every surface.

Free covers pure-HTTP decoys. Pro adds real network services, the decoys that get planted inside an AI agent, and the integrations with your cloud and your CI/CD. Enterprise deploys identity, your full fleet, and live AI interaction.

Free €0

7 pure-HTTP decoy types (web bug, email canary, QR, kubeconfig, decoy Word/Excel document, npm package). Up to 5 active decoys.

Pro 30-day free trial

Everything in Free, plus 7 real network decoys with no cap (SSH, FTP, HTTP, Telnet, MySQL, RDP, VNC), a network folder decoy, and the three AI-agent decoys. Integrations with Azure, GitHub, and AWS.

Enterprise Let's talk

Everything in Pro, plus AI-driven high-interaction honeypots, Entra ID, the Nulldec Agent across your full fleet, full attack surfaces on hostnames of your own, and campaigns that chain decoys into each other.

Free · pure-HTTP decoys

Web bug Email canary QR code Kubeconfig Word document Excel document npm package

Pro · real network decoys No cap

SSH FTP HTTP Telnet MySQL RDP VNC Network folder

Pro · AI agents

An agent with tools can be given an instruction through what it reads. These three decoys live inside its plumbing — its configuration, its knowledge base, and the tool schema it ingests — and they do not fire unless something touches them: every activation is proof that the place was read and that something acted on what it said.

MCP config Agent tool schema RAG document

And in Enterprise, the way in that reaches the agent itself: a decoy tool registered alongside its real ones. No legitimate flow calls it, so its invocation is not an anomaly to interpret — it is a fact. And by declaring where your agent calls from, the alert tells you whether it was your agent: that address is set by the network, not by the caller.

03b · Pro integrations

Detection inside your own cloud and your own pipeline.

They operate inside your environment, always with your explicit authorization and never by default.

GitHub Pro

Via a GitHub App, injects decoy credentials (AWS, Kubernetes, SSH, MySQL) into your GitHub Actions workflows, built to detect exfiltration from compromised CI/CD pipelines. You choose which repositories to authorize.

AWS Pro

Six decoy resource types: IAM credentials, secrets, S3 bucket, DynamoDB table, Lambda function, and container repository. Works with no setup on our shared trap account, or inside your own AWS account if you connect it, with a scoped-permission role you review and approve.

Azure Pro

Decoy resources (Blob container, table) deployed inside your own subscription, mixed in with your real infrastructure. More credible than an isolated resource in a test account.

03c · Enterprise

Deep presence inside your operation.

Identity, full fleet, and live AI interaction.

High-interaction honeypots Enterprise

Full SSH, Telnet, HTTP, and MCP sessions, with responses generated by AI in real time. It's a real conversation with whoever's interacting, not a fixed simulation. Recorded in full, with a real tool fingerprint (HASSH) and an automatically generated narrative after the activation. Deployable on our shared infrastructure or your own servers.

Entra ID Enterprise

Decoy accounts and applications directly in your Microsoft Entra ID tenant, with one-click admin consent. Any sign-in with the decoy account, or any token request with the decoy app's secret, is an unambiguous indicator.

Nulldec Agent Enterprise

Installable across your entire server and endpoint fleet. Detects each machine's type locally (domain controller, database, web, file server) and deploys the right decoy to each one per rules configurable from the console, including an Active Directory honeytoken account (Kerberoasting with no possible false positives) and the network folder decoy. Only ever calls out, never listens; key revocable per installation.

Attack surfaces Enterprise

A faithful replica of a real system — FortiGate, GitLab, Proxmox, Zimbra — served on a hostname you delegate, or inside your own network. Not a page: front page, login, panel, internal records and API, with the vendor’s own fingerprint and its signature CVE. Whoever gets in stays in, and everything they try is logged and classified by attack class. Nothing goes live without your review.

Deception campaigns Enterprise

Chain decoys so each one leads to the next: the document someone opens holds a server's credential, and that server holds the key to the next bucket. An edge isn't control flow, it's a fiction an attacker can actually follow, so only the credible ones are allowed. Nothing is created until you approve the plan, and the campaign detects on its own when a credential rotated and left a bait pointing nowhere.

04 · Intelligence

Every activation is evidence, not a hypothesis.

The raw signal is automatically turned into structured intelligence, ready for your team or your SIEM.

Threat score

A 0–100 score that weighs corroboration across clients above the volume of a single source, and decays over time if the actor goes quiet.

MITRE ATT&CK mapping

Every signal is translated into its technique and tactic, from reconnaissance to credential use.

Cross-client correlation

If the same actor hits several clients, it's grouped as a campaign and an actor profile (infrastructure, tooling, and target) builds up confidence with every new corroboration.

IOC feed Pro

Corroborated, exportable indicators (STIX/TAXII on Enterprise) to feed your defenses.

Session narrative Enterprise

In high-interaction honeypots, every full session (command by command) is automatically summarized by AI, with a real tool fingerprint (HASSH) and its confidence level.

05 · Plans

Start for free. Scale to collective intelligence.

Free gives you full visibility over your own decoys. Pro adds collective intelligence: corroboration of the same actor across multiple environments, campaign attribution, and an IOC feed exportable to your SIEM. You're not paying for the panel. You're paying to see what a single environment could never show you.

Free
€0

Open sign-up

  • 7 pure-HTTP decoy types
  • Up to 5 active decoys
  • Web console and your own alerts
  • Email and Telegram notifications
Create account
Enterprise
Let's talk

We'll propose custom plans within 24-48h

  • Everything in Pro, MSP multi-tenant
  • High-interaction honeypots with AI + Entra ID
  • Nulldec Agent across your fleet + surfaces + chained campaigns
  • Alerts API and STIX/TAXII feed for your SIEM
  • SSO over OIDC, passkeys, custom domains, SLA
  • Active-response rules: webhooks and IP blocking in your Cloudflare

Prices exclude VAT. The Pro trial is temporary, for a limited time.

Plant your first decoy today.

Create a free account, deploy your first decoy from the console, and wait. The first activation will tell you everything you need to know.

Let's talk Enterprise

Tell us about your case and we'll propose a custom offer. We reply within 24-48h.