Creating Tripwires

A step-by-step guide to creating tripwires from the dashboard for different detection scenarios.

β–Ά Browse the technology catalog and deploy a PostgreSQL tripwire.

No Account? No Problem

This guide covers creating tripwires from the dashboard. For document tripwires without an account, see Create Free Tripwire.

The Create Page

From the dashboard, click the "Create Tripwire" button in the top-right corner to open the dedicated creation page.

Create tripwire page

Choosing a Tripwire Type

The create page displays all available tripwire types organized by category. Use the tabs to switch between categories or the search bar to find a specific type:

Protocol Honeypots

These tripwires generate fake service credentials that trigger alerts when someone attempts to connect:

🐘
PostgreSQL
🐬
MySQL
πŸ’Ύ
MSSQL
πŸ”
Elasticsearch
πŸƒ
MongoDB
πŸ”΄
Redis
⚑
Memcached
πŸ”‘
SSH
πŸ“Ÿ
Telnet
πŸ–₯️
RDP
πŸ“Ί
VNC
πŸ“‚
LDAP
πŸ—‚οΈ
SMB
πŸ“§
SMTP
πŸ“
FTP
🐳
Docker API
πŸ”
HTTP Admin

Tripwire Documents

These tripwires are downloadable files that trigger alerts when opened:

πŸ“Š
Excel (.xlsx)
πŸ“„
Word (.docx)
☸️
Kubeconfig
πŸ”’
WireGuard
🐬
MySQL Dump
🐘
PostgreSQL Dump
πŸ’Ύ
SQLite Dump
🐒
SVN Config

Cloud Credentials

Generate fake cloud provider API keys that alert when used. Only AWS is available today (aws_session); Azure and GCP are not yet supported and are rejected by the API, CLI and MCP server:

☁️
AWS
πŸ”·
Azure (Coming Soon)
πŸ”΅
GCP (Coming Soon)

QR Codes

QR codes for physical security that trigger when scanned:

πŸ“±
QR Code

Print and place on physical assets - server rooms, equipment, documents

Phishing Detection

Detect when your own site is cloned for a phishing campaign:

πŸͺž Cloned Site

A JavaScript snippet you embed in your pages. It fires only when the page is served from a hostname you haven't allow-listed β€” i.e. when a phishing kit clones it onto another domain β€” and reports the cloning domain and referrer. Zero false positives on your own site.

The token generates a ready-to-embed .js file. List your real hostnames in its EXPECTED_HOSTS array, then drop it into the pages attackers are most likely to clone β€” your login and password-reset pages. Any use of the clone raises an alert with the attacker's staging domain and the victim's source.

Redirect URLs

A link that records the visit and then sends the visitor on to a destination URL you choose, so whoever clicks it lands somewhere believable and never sees an error page:

⚑ Fast Redirect

Records the hit and answers with an immediate HTTP 302 to your destination. Works for any client, including curl and link previewers.

🐌 Slow Redirect

Records the hit, shows a brief loading page that reports screen size, time zone, language and platform, then forwards to your destination (at most 3 seconds; immediately without JavaScript).

  • The destination must be an absolute http:// or https:// URL of at most 2,048 characters, with no username or password in it. Anything else is rejected with a 400 when you create or edit the tripwire.
  • You can change the destination later with the CLI (tripwire update <id> --dest <url>), the MCP server, or the API (destination_url in a tripwire update). Links you already handed out keep working, because the destination is looked up on every visit rather than baked into the URL. A change takes up to a minute to reach every sink.
  • The destination is only ever read from your tripwire, never from the request, so the tracking URL can't be abused as an open redirect. An unknown, deleted or expired link answers 404.
  • The visit is recorded before the redirect is sent, so you're alerted even if the visitor never reaches the destination. The destination site doesn't receive the tracking URL as a referrer.

Self-hosted: the control server answers redirect URLs itself when the HTTP sink host (SINK_HOST) points at it, which is the default in the Terraform module. If you point SINK_HOST at the sink instead, the sink fetches the destination from the control server's /ingest/redirect/<id> endpoint using the same INGEST_TOKEN it already sends detections with. No extra configuration is needed, but the sink has to be a release that includes this lookup.

Technology Reference (API, CLI & MCP)

Every type on the create page is also creatable from the REST API (POST /tripwires), the CLI (tripwire create <technology>) and the MCP server (create_tripwire) using the same technology slug. The low-level type (dns, tcp or aws) is derived from the technology, so you only need to send technology:

curl -X POST https://api.gettripwires.com/tripwires \
  -H "Authorization: Bearer $TRIPWIRE_API_KEY" -H "Content-Type: application/json" \
  -d '{"name":"prod-db-replica","technology":"postgresql"}'
technologyNameCategorytypeCreate returns
docker_apiDocker APIProtocol honeypottcpHoneypot username (tcp_username)
elasticsearchElasticsearchProtocol honeypottcpHoneypot username (tcp_username)
ftpFTPProtocol honeypottcpHoneypot username (tcp_username)
http_admin (alias: http)HTTP AdminProtocol honeypottcpHoneypot username (tcp_username)
ldapLDAPProtocol honeypottcpHoneypot username (tcp_username)
memcachedMemcachedProtocol honeypottcpHoneypot username (tcp_username)
mongodbMongoDBProtocol honeypottcpHoneypot username (tcp_username)
mssqlSQL ServerProtocol honeypottcpHoneypot username (tcp_username)
mysqlMySQLProtocol honeypottcpHoneypot username (tcp_username)
postgresqlPostgreSQLProtocol honeypottcpHoneypot username (tcp_username)
rdpRDPProtocol honeypottcpHoneypot username (tcp_username)
redisRedisProtocol honeypottcpHoneypot username (tcp_username)
smbSMBProtocol honeypottcpHoneypot username (tcp_username)
smtpSMTPProtocol honeypottcpHoneypot username (tcp_username)
sshSSHProtocol honeypottcpHoneypot username (tcp_username)
telnetTelnetProtocol honeypottcpHoneypot username (tcp_username)
vncVNCProtocol honeypottcpHoneypot username (tcp_username)
dns_tokenDNS TokenDocument / tokendnsHostname (hostname)
docxWordDocument / tokendnsGenerated file (download_url)
fast_redirectFast RedirectDocument / tokendnsTracking URL (needs destination_url)
kubeconfigKubeconfigDocument / tokendnsGenerated file (download_url)
mysqldumpMySQL DumpDocument / tokendnsGenerated file (download_url)
pgdumpPostgreSQL DumpDocument / tokendnsGenerated file (download_url)
slow_redirectSlow RedirectDocument / tokendnsTracking URL (needs destination_url)
sqlitedumpSQLite DumpDocument / tokendnsGenerated file (download_url)
svnSVNDocument / tokendnsGenerated file (download_url)
web_tokenWeb TokenDocument / tokendnsTracking URL (tracking_url)
wireguardWireGuardDocument / tokendnsGenerated file (download_url)
xlsxExcelDocument / tokendnsGenerated file (download_url)
beacon_exeBeacon ScriptExecution triggerdnsGenerated file (download_url)
cloned_siteCloned SiteExecution triggerdnsGenerated file (download_url)
javascriptJavaScriptExecution triggerdnsGenerated file (download_url)
powershellPowerShellExecution triggerdnsGenerated file (download_url)
shell_scriptShell ScriptExecution triggerdnsGenerated file (download_url)
zip_windowsWindows FolderExecution triggerdnsGenerated file (download_url)
qr_code (alias: qr, qrcode)QR CodeQR codednsGenerated file (download_url)
aws_session (alias: aws)AWS Session TokenCloud credentialsawsAWS access key, secret and session token
saml_idpSAML IdP AppPhishing detectiondnsACS URL + entity ID
  • Type is derived. If you also send type, it must match the technology’s type above; a conflicting value (e.g. "type":"tcp" with "technology":"docx") is rejected with 400.
  • Aliases. The older slugs aws, qr / qrcode and http are still accepted and behave exactly like aws_session, qr_code and http_admin; the slug you send is the one stored and returned.
  • Not yet supported. gcp, azure, oracle, rabbitmq, kafka, url and document are rejected with 400 “technology … is not yet supported”. An unrecognised slug returns 400 listing the valid values.
  • Self-hosted installations can switch each category off in System Setup; creating a disabled category returns 403. Cloud credentials are off by default on self-host.

Naming Your Tripwire

After selecting a type, you'll be prompted to enter a name. Choose a descriptive name that helps you:

  • Identify the purpose - Where will these credentials be planted?
  • Remember the context - What system or environment does it represent?
  • Recognize in alerts - When triggered, you'll want to know immediately what was accessed
Naming a tripwire

Naming Best Practices

Good Names

  • βœ“ Production Database Backup
  • βœ“ AWS Staging Redis
  • βœ“ Customer Data Warehouse
  • βœ“ Jenkins CI MongoDB

Avoid

  • βœ— Test
  • βœ— DB1
  • βœ— Honeypot (too obvious)
  • βœ— Fake credentials (too obvious)

Creating the Tripwire

Click "Create Tripwire" to generate the tripwire. The system will:

  1. Generate a unique hostname for your honeypot
  2. Create randomized, realistic-looking credentials
  3. Configure the detection endpoint
  4. Activate monitoring immediately

After Creation

Once created, you'll be redirected to the tripwire details page where you can view and copy the generated credentials. See the Tripwire Details documentation for more information.

Important Security Note

Tripwire credentials are designed to look realistic. Make sure your team knows which credentials are honeypots to avoid accidentally triggering alerts during legitimate operations.