Tracebit's Avatar

Tracebit

@tracebit.bsky.social

Expect the unexpected with cloud canaries | https://tracebit.com

72 Followers  |  229 Following  |  41 Posts  |  Joined: 25.11.2024  |  1.7753

Latest posts by tracebit.bsky.social on Bluesky


Video thumbnail

๐ŸŽฎ Episode 4 of Canaries in the Wild is now live with Kevin Conley, Team Lead and Principal Security Engineer of the Deception Technology team at Riot Games.

Listen to the full episode here: www.youtube.com/watch?v=87HA...

10.02.2026 15:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
The full costs of building your own Canary Program | Tracebit We explore why there can be a bias to build canaries and what's actually involved for a successful security canary program.

tracebit.com/blog/the-ful...

30.12.2025 12:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Why Tracebit is written in C# | Tracebit A retro on some of the reasons we chose to build Tracebit in C#.

tracebit.com/blog/why-tra...

30.12.2025 12:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Code Execution Through Deception: Gemini AI CLI Hijack | Tracebit Tracebit discovered a silent attack on Gemini CLI where, through a toxic combination of prompt injection, misleading UX and missing validation, inspecting untrusted code consistently leads to executio...

tracebit.com/blog/code-ex...

30.12.2025 12:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image

๐Ÿš€ Here are our top 3 posts of 2025:

1. Code Execution Through Deception: Gemini AI CLI Hijack
2. Why Tracebit is written in C#
3. The full costs of building your own Canary Program

Hope you enjoyed this year's posts and wishing you a happy new year! ๐ŸŽ‰

30.12.2025 12:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0
Preview
Building Tracebit Community Edition | Tracebit Last week, we launched Tracebit Community Edition. In this post, we go into the details of the method and motivation behind the release.

Last week we launched Tracebit Community Edition. The team may have made it look easy, but getting it right took a monumental effort.

Our CTO Sam breaks down what went into it - from solving the "stealth problem" to shipping our first cross-platform CLI.

Read: tracebit.com/blog/buildin...

17.12.2025 15:05 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿป We are excited to be hosting drinks tonight with our friends at @RunReveal.

Join us at Platform Shoreditch for food, drinks and lots of games.

If you're around in London, we'd love to see you there.

Sign up here: luma.com/nees25e2

12.12.2025 12:28 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ“We're heading to @bsideslondon.bsky.social's BSides London!

Come find the Tracebit team on December 13th to chat about security canaries and the role of deception in an "assume breach" strategy.

We're excited to see you there!

09.12.2025 16:43 โ€” ๐Ÿ‘ 6    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Tracebit

community.tracebit.com

04.12.2025 12:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

๐ŸŽ‰Weโ€™ve just released the Tracebit Community Edition of our security canary platform!

Protect your browser, password manager, inbox, and endpoints with canaries โ€“ all managed from the community console.

Sign up for free now: community.tracebit.com

04.12.2025 12:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

๐Ÿ“ We're heading to @blackhatevents.bsky.social's BlackHat Europe!

We'll be at ExCeL London on Dec 10th-11th.

Find us at booth 426 to learn more about security canaries and what we are working on at Tracebit!

Book a time: meetings-eu1.hubspot.com/robert-thurt...

02.12.2025 15:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

๐ŸŽ™๏ธEpisode 3 of Canaries in the Wild is live with Mandy Andress, CISO at @elastic.co.

Mandy discusses why canaries need a bigger role in security programs and how detection is evolving with increasingly complex threats.

Listen: www.youtube.com/watch?v=QjK1...

18.11.2025 15:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ”‘ Short vs. long term canary credentials: why the choice matters more than you think.

We just published a new blog post exploring the trade-offs between long and short term canary credentials for threat detection.

Read it here: tracebit.com/blog/short-t...

12.11.2025 10:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

tracebit.com/blog/short-t...

12.11.2025 10:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

๐ŸŽ™๏ธWant to hear more about Didier Vandenbroeck's take on the 'Assume Breach' mindset?

Listen to Canaries in the Wild Episode 1: www.youtube.com/watch?v=VIMd...

20.10.2025 16:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

๐ŸŽ™๏ธ Episode 2 of Canaries in the Wild is live with Josh Yavor, CEO and Co-Founder of @credible-security.com.

Josh has over a decade of experience deploying deception technology across organisations of all sizes, and shares his practitioner insights with us.

Listen: www.youtube.com/watch?v=ItzY...

14.10.2025 12:59 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ“ We're heading to @bsidesnyc.org on Saturday 18th October!

Want to talk security canaries and learn what we're building at Tracebit? Come find us at our booth.

See you there ๐Ÿ‘‹

06.10.2025 16:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Didier Vandenbroeck: Catching Red Teams, Insider Threat and the ROI of Canaries
YouTube video by Tracebit Didier Vandenbroeck: Catching Red Teams, Insider Threat and the ROI of Canaries

๐ŸŽ™๏ธ Launching Canaries in the Wild - our new podcast on deception tech that actually catches attackers.
First episode: Didier Vandenbroeck on deploying canaries at Oleria and getting caught by honeypots himself while on offense at Salesforce.
Listen: www.youtube.com/watch?v=VIMd...

10.09.2025 13:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Canaries in the Era of Generative AI | Tracebit We explore what generative AI means for canaries, deception and honeypots. Both from an offense and defense perspective and what we're doing at Tracebit.

๐Ÿค– AI agents are hitting honeypots in the wild - and it's wild how they react.

Sam Cox tested something fascinating: mention "honeypots might exist" to an LLM mid-attack, and it completely changes its strategy. Just like humans, they get paranoid.

Full analysis: tracebit.com/blog/canarie...

03.09.2025 15:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Canary tokens: Learn all about the unsung heroes of security at Grafana Labs | Grafana Labs Learn why the use of canary tokens let us spot a recent intrusion and swarm quickly in response, and find out why you should be using canary tokens to prevent serious security incidents in the future.

๐Ÿ” Great to see @grafana.bsky.social sharing their canary token success story - they allowed them to catch a real intrusionโ€ผ๏ธ

This is exactly the kind of real-world validation we love to see. Security teams want precise alerts that allow them to catch attacks early.

grafana.com/blog/2025/08...

28.08.2025 10:05 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
LinkedIn This link will take you to a page thatโ€™s not on LinkedIn

๐ŸŽฌ Pretty cool to see Sam Cox's Gemini CLI research featured in Low Level's YouTube video and hitting 150k+ views ๐Ÿš€

๐Ÿ‘€ From discovering a silent code execution vulnerability to mainstream coverage!

Full breakdown on our blog for the curious minds out there. ๐Ÿ”Ž

lnkd.in/eprKJ5vS

11.08.2025 12:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐ŸŽฉ We're at @blackhatevents.bsky.social USA today and tomorrow ๐ŸŽฉ

If you're around and want to chat about security canaries or detection engineering - Andy, Sam, and Rob are at booth 6219 in Start Up City.

Book time with the team here: tracebit.com/event/black-...

See you in Vegas!

06.08.2025 18:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ’ฅAchievement Unlocked, thanks @mattjay.com for the call out!

01.08.2025 07:08 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

This is a fun vuln

youtu.be/jsygONOr_f4

31.07.2025 21:58 โ€” ๐Ÿ‘ 8    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image

The Tracebit team will be in Vegas August 2-7 for BSides and BlackHat ๐ŸŽฉ

โ˜๏ธ If you're working on intrusion detection, cloud environments, or just want to chat about what's actually working in security right now - let's meet up!

๐Ÿค You can grab some time with us at Blackhat here: lnkd.in/ebCGMpxW

29.07.2025 17:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

The demo:

28.07.2025 10:59 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Code Execution Through Deception: Gemini AI CLI Hijack | Tracebit Tracebit discovered a silent attack on Gemini CLI where, through a toxic combination of prompt injection, misleading UX and missing validation, inspecting untrusted code consistently leads to executio...

๐Ÿ‘€ We found a way to steal credentials through Google Gemini AI CLI just by asking "tell me about this repo" on some untrusted code.

Check out our research here: tracebit.com/blog/code-ex...

28.07.2025 10:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

@bsidesnyc.org welcomes @tracebit.bsky.social as a Megabit sponsor for our conference on Oct 18, 2025. bsidesnyc.org Tracebit deploys and maintains tailored security canaries, proactively detecting intrusions across your organization. tracebit.com

22.07.2025 12:38 โ€” ๐Ÿ‘ 3    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

We caught up with Cedric - SOC Lead at
Coveo - to talk about the value he's seen in canaries and Tracebit!

You can also check the full case study here: tracebit.com/customer/coveo

10.07.2025 15:42 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

โœˆ๏ธ Not long now until our co-founders Andy Smith and Sam Cox head out for @bsidessf.org this weekend.

We'll be in the sponsor area - if you want to see the our latest product features or just talk canaries, come say hello!

#bsidessf

23.04.2025 14:05 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@tracebit is following 20 prominent accounts