Webinar: Detecting Supply Chain Attacks · 10th June →
Product
Platform
AWS
AWS
Azure
Azure
CI/CD
CI/CD
Google Cloud
Google Cloud
Identity
Identity
Kubernetes
Kubernetes
Workstations
Workstations
Credentials & artifacts
Credentials & artifacts
Use cases
AI Agent Detection
Cloud & Kubernetes Breach
Insider Threat Detection
Supply Chain & CI/CD Attack
Workstation Compromise
PricingCustomers
Resources
  • ResearchAbout
  • Careers
  • Contact
Community Edition
Book a demoCommunity Edition

Blog

News, research & articles

The latest research and product updates from the Tracebit team.

By subscribing you agree to our privacy policy
Thank you! Check your inbox for your first edition.
Oops! Something went wrong while submitting the form.
Tracebit research: canaries against autonomous AI attackers
Research

Canaries against autonomous AI attackers

We pointed ten frontier models at a live AWS environment to see what canaries do against an autonomous attacker: how early they warn, how fast the models trip them, and what changes when the agent is told deception might be present.

Sam Cox
Sam Cox

Jun 1, 2026

May 31, 2026

·

5

min read

NIST CSF 2.0 framework mapped to Tracebit security canaries across Detect, Respond, Govern, Identify, Protect, and Recover
Detection Strategy

Where Security Canaries Fit in NIST CSF 2.0

How Tracebit turns detection from an assumption into something you can actually prove. A practical mapping of security canaries across the six core functions of NIST CSF 2.0 - Detect, Respond, Govern, Identify, Protect, and Recover.

Bryan O'Neil
Bryan O'Neil

May 6, 2026

May 6, 2026

·

7

min read

Deception security as a foundational control illustration
Detection Strategy

Deception Should Not Be a Luxury Control

How supporting Duo Security's astronomical growth set me up to see Deception as the next 'must have' security control.

Bryan O'Neil
Bryan O'Neil

Apr 22, 2026

April 22, 2026

·

6

min read

Detecting CI/CD Supply Chain Attacks with Canary Credentials
Research

Detecting CI/CD Supply Chain Attacks with Canary Credentials

A single threat actor - TeamPCP - compromised a chain of widely-used open source tools: Trivy, KICS, LiteLLM, and Telnyx. This post looks at the campaign and explores the question: once you've pinned your actions and hardened your runners, what actually detects credential exfiltration from a compromised CI/CD pipeline?

Alessandro Brucato
Alessandro Brucato

Apr 2, 2026

April 2, 2026

·

5

min read

Series A
Product

Tracebit announces Series A

We’re excited to announce our Series A investment round, led by FirstMark and joined by Accel, MMC Ventures, Tapestry VC and CCL; with continued support from our fantastic angel investors. This brings the total investment in Tracebit to $25M.

Andy Smith
Andy Smith

Mar 17, 2026

March 13, 2026

·

2

min read

"Think like an attacker"
Product

Canaries in the Wild - Episode 4: Kevin Conley

Episode 4 features Kevin Conley, Team Lead and Principal Security Engineer of the Deception Technology team at Riot Games, who explains why thinking like an attacker is critical, how Riot measures deception program effectiveness, and the ROI case for deception.

Andy Smith
Andy Smith

Feb 10, 2026

February 10, 2026

·

2

min read

Do canaries first
Product

Do Canaries First

Engineering would never accept not detecting product going down - so why does security? This post makes the case for security canaries as a day-one control for catching critical security events early.

Andy Smith
Andy Smith

Feb 13, 2026

February 9, 2026

·

5

min read

Building Tracebit Community Edition
Product

Building Tracebit Community Edition

Last week, we launched Tracebit Community Edition. In this post, we go into the details of the method and motivation behind the release.

Sam Cox
Sam Cox

Dec 17, 2025

December 16, 2025

·

4

min read

Introducing Community Edition
Product

Announcing Tracebit Community Edition

We're excited to announce Tracebit Community Edition, a completely free-forever platform to deploy security canaries.

Andy Smith
Andy Smith

Dec 4, 2025

December 4, 2025

·

3

min read

"We just need to take it as a given and assume breach"
Product

Canaries in the Wild - Episode 3: Mandy Andress

Episode 3 features Mandy Andress, CISO at Elastic, discussing why canaries deserve a larger role in security programs and how they'll address emerging threats from no-code applications and AI agents.

Andy Smith
Andy Smith

Nov 18, 2025

November 18, 2025

·

2

min read

"Two keys float above a cloud"
Research

Short Term vs Long Term Canary Credentials

I'll explore the trade-offs between long and short term canary credentials for threat detection and explain why I think short term credentials are increasingly the right choice for most deployments.

Gemma Jacobson
Gemma Jacobson

Nov 11, 2025

November 7, 2025

·

4

min read

"Absence of signal is actually a delightful change"
Product

Canaries in the Wild - Episode 2: Josh Yavor

Episode 2 features Josh Yavor, CEO and Co-Founder of Credible Security, discussing his experiences deploying deception technology across organizations of all sizes over more than a decade.

Andy Smith
Andy Smith

Oct 13, 2025

October 13, 2025

·

2

min read

Canaries In The Wild, presented by Tracebit
Product

Introducing "Canaries in the Wild"

We're launching Canaries in the Wild, a podcast featuring security practitioners sharing real stories about deploying deception technology. Episode 1 features Didier Vandenbroeck, VP of Security at Oleria.

Andy Smith
Andy Smith

Sep 9, 2025

September 30, 2025

·

2

min read

Code Execution Through Deception: Gemini AI CLI Hijack
Research

Code Execution Through Deception: Gemini AI CLI Hijack

Tracebit discovered a silent attack on Gemini CLI where, through a toxic combination of prompt injection, misleading UX and missing validation, inspecting untrusted code consistently leads to execution of malicious commands - enabling silent credential theft and much more.

Sam Cox
Sam Cox

Jul 28, 2025

July 25, 2025

·

6

min read

An example of a deception aware and deception naive AI
Product

Canaries in the Era of Generative AI

We explore what generative AI means for canaries, deception and honeypots. Both from an offense and defense perspective and what we're doing at Tracebit.

Sam Cox
Sam Cox

Jul 3, 2025

June 28, 2025

·

8

min read

Tracebit and Kubernetes
Product

Announcing Security Canaries in Kubernetes

We're excited to share our latest canary module: Kubernetes - this is now available for all Tracebit customers

Andy Smith
Andy Smith

Apr 14, 2025

April 14, 2025

·

2

min read

Planning a security canary program
Product

The full costs of building your own Canary Program

We explore why there can be a bias to build canaries and what's actually involved for a successful security canary program.

Andy Smith
Andy Smith

Feb 27, 2025

February 24, 2025

·

5

min read

Why Tracebit is written in C#
Product

Why Tracebit is written in C#

A retro on some of the reasons we chose to build Tracebit in C#.

Sam Cox
Sam Cox

January 31, 2025

·

10

min read

Tracebit/Panther
Product

Announcing Tracebit’s partnership with Panther

We announce Tracebit’s partnership with Panther, a leading cloud-native SIEM

Niall Gallagher
Niall Gallagher

Jan 8, 2025

January 6, 2025

·

5

min read

Announcing Azure Canaries General Availability
Product

Announcing Azure Canaries General Availability

Tracebit announces the general availability of Tracebit Canaries for Microsoft Azure

Andy Smith
Andy Smith

December 9, 2024

·

2

min read

Azure Activity Logs
Research

Azure Detection Engineering: Log idiosyncrasies you should know about

We share a few inconsistencies found in Azure logs which make detection engineering more challenging.

Michael Aldridge
Michael Aldridge

November 15, 2024

·

5

min read

Breaching the Data Perimeter: CloudTrail as a mechanism for Data Exfiltration
Research

Breaching the Data Perimeter: CloudTrail as a mechanism for Data Exfiltration

We share a - now fixed - AWS vulnerability that would have enabled potentially undetectable data exfiltration from even the most locked down of AWS accounts by leveraging the audit trail itself to stealthily leak data.

Sam Cox
Sam Cox

Oct 15, 2024

October 15, 2024

·

5

min read

The Security Canary Maturity Model
Research

The Security Canary Maturity Model

We lay out the different levels of maturity your organization may be at in their Security Canary Maturity, as well as discussing the value in maturity models themselves.

Rami McCarthy
Rami McCarthy

Sep 10, 2024

September 7, 2024

·

5

min read

Canary Infrastructure vs. Real World TTPs - Scattered Spider / LUCR-3
Research

Canary Infrastructure vs. Real World TTPs

We investigate three recent AWS security incidents and discuss how canaries could help you detect these early, and throughout the attack lifecycle.

Rami McCarthy
Rami McCarthy

Aug 13, 2024

August 13, 2024

·

4

min read

Diagram showing VPC Endpoint Policies being used to find Organization ID of an arbitrary AWS account
Research

NO_WILDCARD: How I discovered the Organization ID of any AWS Account

Our latest research into VPC Endpoint Policy causes AWS to introduce significant changes!

Sam Cox
Sam Cox

Jul 22, 2024

July 22, 2024

·

10

min read

A hard look at GuardDuty shortcomings
Research

A hard look at GuardDuty shortcomings

Is GuardDuty all you need for AWS threat detection? We’ve asked our friend Rami McCarthy to dive into GuardDuty’s performance and consider the potential place for Canary Infrastructure.

Rami McCarthy
Rami McCarthy

Jul 16, 2024

July 12, 2024

·

6

min read

Tracebit announces $5m fundraise to bring intrusion detection canaries to the world
Product

Tracebit announces $5m fundraise to bring intrusion detection canaries to the world

We're delighted to announce our seed funding round, we're partnering with Accel, Tapestry VC and an incredible set of angel investors to bring Tracebit to the world.

Andy Smith
Andy Smith

Jul 9, 2024

June 24, 2024

·

2

min read

Sam Cox presenting "Discover the AWS Account ID of any S3 bucket"
Research

fwd:cloudsec Talk: Discover the AWS Account ID of any S3 Bucket

Our Co-Founder and CTO Sam Cox presented his research into discovering the AWS Account ID of any S3 Bucket and how you might make similar discoveries yourself.

Sam Cox
Sam Cox

Jun 24, 2024

June 24, 2024

·

2

min read

Canary Program Communication
Product

Canary Program Communication: Secrecy vs. Discretion

We share the lessons learned from deploying canaries at scale - how to be thoughtful but pragmatic about some of the tradeoffs necessary.

Andy Smith
Andy Smith

May 31, 2024

May 31, 2024

·

3

min read

AI generated image of a red cartoon key, with halo, sitting on a cloud
Research

Canary AWS credentials: Beyond a token effort

What to think about when implementing canary AWS credentials in 2024 and beyond

Sam Cox
Sam Cox

May 3, 2024

May 15, 2024

·

5

min read

Cartoon image of canaries organising and conducting the construction of a building site with cranes in the background
Product

Canary Infra: Bringing Honeypots towards general adoption

Laying out why we think 'Canary Infra' is a game changer for honeypots and intrusion detection.

Andy Smith
Andy Smith

Mar 14, 2024

May 15, 2024

·

4

min read

Technical diagram showing modifications made to a VPC endpoint to make an Account ID search of an S3 bucket faster.
Research

How to find the AWS Account ID of any S3 Bucket

A technique to find the Account ID of a private S3 bucket.

Sam Cox
Sam Cox

Feb 22, 2024

May 15, 2024

·

8

min read

Graph showing the CloudTrail delay delivering to S3
Research

How fast is CloudTrail today? Investigating CloudTrail delays using Athena

Investigating how long CloudTrail takes to deliver events in 2023.

Sam Cox
Sam Cox

Nov 27, 2023

May 15, 2024

·

7

min read

Cartoon image of a threat actor about to interact with a honeypot, lasers and alarm systems surround it.
Research

Honeypots for Intrusion Detection

A deep dive into what Honeypots are, why they're useful and how they're used for intrusion detection.

Andy Smith
Andy Smith

Nov 13, 2023

May 15, 2024

·

5

min read

The latest security research straight to your inbox

Subscribe to our newsletter to receive regular updates from our research and product teams

By subscribing you agree to our privacy policy
Thank you! Check your inbox for your first edition.
Oops! Something went wrong while submitting the form.
Soc 2 Type 2 imageCheckmark imageAWS Qualified software illustration
PLATFORM
AWS
Azure
CI/CD
Google Cloud
Identity
Kubernetes
Workstations
Credentials & artifacts
USE CASES
AI Agent Detection
Cloud & Kubernetes Breach
Insider Threat Detection
Supply Chain & CI/CD Attack
Workstation Compromise
COMPANY
CustomersResearchAboutCareersContactStatusCommunity Edition
SOCIAL
© 2026 Tracebit
Privacy PolicyTerms of ServiceCookie Settings