Advertisement ยท 728 ร— 90

Posts by Tracebit

Post image

๐ŸŽ‰We've published our Tracebit GitHub Action to the GitHub Marketplace!

It now deploys canary SSH keys and AWS credentials to catch supply chain attacks like TeamPCP's Trivy attack: github.com/marketplace/...

12 hours ago 1 0 1 0
Post image

@synthesia.io needed high-confidence detection signals across a multi-cloud environment.

They deployed Tracebit canaries and saw high-fidelity alerts with near-zero false positives and minimal ongoing maintenance.

Read the full case study here: tracebit.com/customer/syn...

6 days ago 1 0 0 0
Post image

We're heading to Singapore for Black Hat Asia!

Come find us at Booth 223 - we'll be showing how security canaries detect breaches the moment attackers move.

See you there ๐Ÿš€

1 week ago 0 0 0 0
Preview
Detecting CI/CD Supply Chain Attacks with Canary Credentials | Tracebit A single threat actor - TeamPCP - compromised a chain of widely-used open source tools: Trivy, KICS, LiteLLM, and Telnyx. This post looks at the campaign and explores the question: once you've pinned ...

A deep dive on our blog: tracebit.com/blog/detecti...

1 week ago 0 0 0 0
Preview
Tracebit Community Edition Lightweight, real-time intrusion detection of events you really need to know about. Completely free, forever.

Up to 10 repos for free (public and private), minutes to detect attacks like Trivy, sign up and let us know what you think!

community.tracebit.com to sign up

1 week ago 0 0 1 0

๐ŸŽ‰ You may have noticed chatter about supply chain attacks recently. Canaries can provide vital signals for these attacks. We've just opened up Tracebit Canary Github Action support for free in our Community Edition.

1 week ago 0 0 1 0
Post image

We are at RSAC! ๐Ÿš€

Find us at Booth NXT 4 to learn more about security canaries and how they can strengthen your security posture.

We look forward to meeting you!

2 weeks ago 0 0 0 0
Post image

If you are in San Fransisco this Sunday 22nd March for BSidesSF or RSAC we'd love for you to join us for Rooftop drinks! โ˜€๏ธ

We're co-hosting with Socket, cside, RunReveal and Keycard.

Sign up here: luma.com/t9iaikrx

3 weeks ago 0 0 0 0

BIG NEWS! We've raised our Series A, bringing total funding to $25M ๐ŸŽ‰

Led by @firstmark.bsky.social joined by Accel, MMC and Tapestry VC

This next phase is all about broader coverage and bigger features, with GCP support, Perimeter Canaries, and Deceptive Artifacts all shipping this quarter.

4 weeks ago 0 0 0 0
Video

๐ŸŽฎ Episode 4 of Canaries in the Wild is now live with Kevin Conley, Team Lead and Principal Security Engineer of the Deception Technology team at Riot Games.

Listen to the full episode here: www.youtube.com/watch?v=87HA...

2 months ago 0 0 0 0
Advertisement
The full costs of building your own Canary Program | Tracebit We explore why there can be a bias to build canaries and what's actually involved for a successful security canary program.

tracebit.com/blog/the-ful...

3 months ago 0 0 0 0
Why Tracebit is written in C# | Tracebit A retro on some of the reasons we chose to build Tracebit in C#.

tracebit.com/blog/why-tra...

3 months ago 0 0 0 0
Code Execution Through Deception: Gemini AI CLI Hijack | Tracebit Tracebit discovered a silent attack on Gemini CLI where, through a toxic combination of prompt injection, misleading UX and missing validation, inspecting untrusted code consistently leads to executio...

tracebit.com/blog/code-ex...

3 months ago 0 0 0 0
Post image Post image Post image

๐Ÿš€ Here are our top 3 posts of 2025:

1. Code Execution Through Deception: Gemini AI CLI Hijack
2. Why Tracebit is written in C#
3. The full costs of building your own Canary Program

Hope you enjoyed this year's posts and wishing you a happy new year! ๐ŸŽ‰

3 months ago 0 0 3 0
Preview
Building Tracebit Community Edition | Tracebit Last week, we launched Tracebit Community Edition. In this post, we go into the details of the method and motivation behind the release.

Last week we launched Tracebit Community Edition. The team may have made it look easy, but getting it right took a monumental effort.

Our CTO Sam breaks down what went into it - from solving the "stealth problem" to shipping our first cross-platform CLI.

Read: tracebit.com/blog/buildin...

3 months ago 3 1 0 0
Post image

๐Ÿป We are excited to be hosting drinks tonight with our friends at @RunReveal.

Join us at Platform Shoreditch for food, drinks and lots of games.

If you're around in London, we'd love to see you there.

Sign up here: luma.com/nees25e2

4 months ago 0 0 0 0
Post image

๐Ÿ“We're heading to @bsideslondon.bsky.social's BSides London!

Come find the Tracebit team on December 13th to chat about security canaries and the role of deception in an "assume breach" strategy.

We're excited to see you there!

4 months ago 6 1 0 0
Advertisement
Tracebit

community.tracebit.com

4 months ago 0 0 0 0
Post image Post image Post image Post image

๐ŸŽ‰Weโ€™ve just released the Tracebit Community Edition of our security canary platform!

Protect your browser, password manager, inbox, and endpoints with canaries โ€“ all managed from the community console.

Sign up for free now: community.tracebit.com

4 months ago 0 0 1 0
Post image

๐Ÿ“ We're heading to @blackhatevents.bsky.social's BlackHat Europe!

We'll be at ExCeL London on Dec 10th-11th.

Find us at booth 426 to learn more about security canaries and what we are working on at Tracebit!

Book a time: meetings-eu1.hubspot.com/robert-thurt...

4 months ago 0 0 0 0
Video

๐ŸŽ™๏ธEpisode 3 of Canaries in the Wild is live with Mandy Andress, CISO at @elastic.co.

Mandy discusses why canaries need a bigger role in security programs and how detection is evolving with increasingly complex threats.

Listen: www.youtube.com/watch?v=QjK1...

4 months ago 0 0 0 0
Post image

๐Ÿ”‘ Short vs. long term canary credentials: why the choice matters more than you think.

We just published a new blog post exploring the trade-offs between long and short term canary credentials for threat detection.

Read it here: tracebit.com/blog/short-t...

5 months ago 0 0 0 0

tracebit.com/blog/short-t...

5 months ago 0 0 0 0
Video

๐ŸŽ™๏ธWant to hear more about Didier Vandenbroeck's take on the 'Assume Breach' mindset?

Listen to Canaries in the Wild Episode 1: www.youtube.com/watch?v=VIMd...

5 months ago 0 0 0 0
Video

๐ŸŽ™๏ธ Episode 2 of Canaries in the Wild is live with Josh Yavor, CEO and Co-Founder of @credible-security.com.

Josh has over a decade of experience deploying deception technology across organisations of all sizes, and shares his practitioner insights with us.

Listen: www.youtube.com/watch?v=ItzY...

6 months ago 1 0 0 0
Post image

๐Ÿ“ We're heading to @bsidesnyc.org on Saturday 18th October!

Want to talk security canaries and learn what we're building at Tracebit? Come find us at our booth.

See you there ๐Ÿ‘‹

6 months ago 0 0 0 0
Advertisement
Didier Vandenbroeck: Catching Red Teams, Insider Threat and the ROI of Canaries
Didier Vandenbroeck: Catching Red Teams, Insider Threat and the ROI of Canaries YouTube video by Tracebit

๐ŸŽ™๏ธ Launching Canaries in the Wild - our new podcast on deception tech that actually catches attackers.
First episode: Didier Vandenbroeck on deploying canaries at Oleria and getting caught by honeypots himself while on offense at Salesforce.
Listen: www.youtube.com/watch?v=VIMd...

7 months ago 0 0 0 0
Preview
Canaries in the Era of Generative AI | Tracebit We explore what generative AI means for canaries, deception and honeypots. Both from an offense and defense perspective and what we're doing at Tracebit.

๐Ÿค– AI agents are hitting honeypots in the wild - and it's wild how they react.

Sam Cox tested something fascinating: mention "honeypots might exist" to an LLM mid-attack, and it completely changes its strategy. Just like humans, they get paranoid.

Full analysis: tracebit.com/blog/canarie...

7 months ago 0 0 0 0
Preview
Canary tokens: Learn all about the unsung heroes of security at Grafana Labs | Grafana Labs Learn why the use of canary tokens let us spot a recent intrusion and swarm quickly in response, and find out why you should be using canary tokens to prevent serious security incidents in the future.

๐Ÿ” Great to see @grafana.bsky.social sharing their canary token success story - they allowed them to catch a real intrusionโ€ผ๏ธ

This is exactly the kind of real-world validation we love to see. Security teams want precise alerts that allow them to catch attacks early.

grafana.com/blog/2025/08...

7 months ago 0 0 0 0
LinkedIn This link will take you to a page thatโ€™s not on LinkedIn

๐ŸŽฌ Pretty cool to see Sam Cox's Gemini CLI research featured in Low Level's YouTube video and hitting 150k+ views ๐Ÿš€

๐Ÿ‘€ From discovering a silent code execution vulnerability to mainstream coverage!

Full breakdown on our blog for the curious minds out there. ๐Ÿ”Ž

lnkd.in/eprKJ5vS

8 months ago 0 0 0 0