CyberHalluciNet CHN

Enterprise IT · OT · AI agent defense

CyberHalluciNet Detect machine-speed threats with deterministic deception.

CHN plants decoys that approved workflows are configured never to reach. When one is touched, get graded high-fidelity evidence—with optional bounded containment on a separate plane, and human authorization for high-impact actions.

Enterprise ITDR & Identity Lures
OT/ICS Plant Kinematics
AI agent decoys & containment

Agentic platform

Purpose-built deception across three attack surfaces

One deterministic sensor policy engine protecting enterprise identities, physical SCADA loops, and autonomous AI infrastructure.

Enterprise ITDR & Identity

Agentless endpoint & Active Directory defense

  • Agentless lure distribution: GPO / Intune / Jamf-oriented packs for registry & SSH config lures
  • Monitored AD / Entra decoys: Synthetic identity breadcrumbs ending at sensor surfaces
  • Self-cleaning TTL engine: Lures expire on host decommission to reduce orphaned debt
Built for CISO & IT SecOps

OT/ICS Critical Infrastructure

Physical plant kinematics & SCADA protection

  • Real kinematic drift: Fluid, pressure, and duty-cycle decoys (Rockwell, Siemens, water-WWS)
  • Passive auto-discovery: SPAN/TAP profiling before active listening to reduce collision risk
  • Zero-Collision Certificates: Operator-signed non-conflict verification prior to launch
Built for OT & Plant Engineers

A.I. Decoy Engine & Agent Systems

Honeytools, shadow-index canaries, and optional active response

  • Detection (defaults off): Honeytools and shadow-index canaries — observe / advisory only until enabled
  • Active response (Beta): Separate Enforcement Plane; Soft/Hard via LocalState + BYO webhook after observe pilot
  • Vendor adapters: Native EDR/IdP SDKs remain GA-train (not Soft/Hard on Beta)
Built for AI Security & SecOps

Lab install

Try Agentic Attack Defense

One command builds the sensor and Enforcement Plane for a loopback lab. Start with detection; active response stays optional and observe-first.

Detection lab

Advisory honeytools · watch only

  • make agentic-lab-install
  • Enable CYBERHALLUCINET_AGENTIC_HONEYTOOLS=observe
  • Confirm sensor arms advisory controls (defaults stay off until you enable)

Active response lab

Enforcement Plane · after observe

  • Start bin/enforcementplane on loopback
  • Confirm /healthz is healthy
  • Start observe pilot; sensor notify is evaluate-only

Core architecture moat

Split Authority: Why AI Models Never Control Wire Execution

Enterprise buyers fear autonomous AI in critical security paths. CHN separates attacker wire bytes from AI content suggestion by design.

Attacker wire bytes

Deterministic sensor policy

  • 100% sensor logic on the wire
  • Score-independent responses (SEC-AI-001)
  • Sub-millisecond synthetic path; no model chooses egress or OS execution

AI content broker

Bounded UDS slots

  • Schema-bound fills only (ValidateSlotFill)
  • Unix Domain Socket isolation from decoy ingress
  • Static / template fallback when broker is offline

Competitors that put unconstrained LLM prompts on the security execution path inherit prompt-injection and inconsistency risk. CHN keeps models off wire authority.

Decoy ingress · attacker path

  1. Source Attacker
  2. Wire authority Sensor Deterministic policy · score-independent
  3. Suggestion only AI Broker Schema-bound fills · fail-closed

Private management · never mixed into decoy ingress

  1. Control plane Ops / SIEM Investigate · contain · report
  2. Isolated Management plane Credentials & CTI stay off the wire path
Models suggest content. The sensor keeps authority. Management never shares the attacker ingress path.

Try the platform

Trap agents, size the ROI, prove the threat

AI agent traps

Catch a decoy touch with CyberHalluciNet

The CHN sensor is the detector. Install the loopback lab, enable honeytools in observe mode, touch a lab decoy from a test agent, and read graded evidence from CHN—not from a standalone webhook.

Step 1

Install the CHN lab

make agentic-lab-install builds the sensor (and Enforcement Plane for later). Loopback only.

Step 2

Arm honeytools (observe)

Defaults stay off. Enable CYBERHALLUCINET_AGENTIC_HONEYTOOLS=observe, then start bin/sensor.

Step 3

Touch a lab decoy

From a test agent, invoke a decoy tool name registered for this deployment. CHN records the touch.

Step 4

Read CHN evidence

Confirm agentic_reason=honeytool_touch and graded evidence such as verified_decoy_touch. Advisory only—no Soft/Hard here.

CHN in the loop

Run the catch path

Four steps with the sensor on the wire: install → observe → decoy touch → graded CHN evidence.

Open catch tutorial
Optional: preview a decoy tool schema shape

This JSON is only a decoy shape for lab tooling. Pasting it into an agent with a webhook alone is not CyberHalluciNet detection. CHN catches the touch when the sensor is armed in observe mode.

Trap type
Schema preview · not a substitute for the CHN sensor

What this is

A lab decoy schema shape with chn_metadata. Detection requires the CHN sensor in observe mode—not this JSON alone.

Download JSON
// generated snippet appears here

2 · CFO / CISO

Model your SOC triage capacity recovery

Illustrative planning model: Estimate potential capacity recovered if high-fidelity decoy signals reduce routine alert triage load.

User inputs

Projected annual hours addressed

Hours / year (Planning estimate)

Projected operational value

Labor value / year (Planning estimate)

Request 10-min staging POC

Methodology & non-claim: illustrative scenario planner only.

3 · Social / CTI proof

AI threat radar

Scrubbed aggregate adversarial AI / deception TTP families — no raw sessions or sensor IDs. Sample data below is illustrative; production export is opt-in via Ops Threat Radar APIs.

Sample · GLOBAL_PUBLIC scrubbed

    Threat Radar

    Methodology

    Public Threat Radar and the free CTI API stub publish scrubbed aggregates only. They are not a production AGTI feed and do not claim actor attribution.

    Inputs

    • Deterministic ATT&CK technique IDs and coarse behavior families from Ops Investigate / AGTI extractors.
    • Counts are session-aggregate tallies, never raw session transcripts.

    Data Scrubbing Policy (SEC-AG-004)

    Before leave-tenant publication, every payload passes agti.ScrubEgress:

    • Opt-in required (opt_in / opt_in_public).
    • Jurisdiction filter (closed set: EU, US, UK, APAC, GLOBAL_PUBLIC).
    • Fail closed on blocked field classes and values: internal/private IP, internal hostnames, usernames/emails, sensor/session identifiers.

    Re-identification & abuse

    • Raw IPs, sensor_id / session_id, and username-like client hints are rejected on the free CTI API stub.
    • Per-key rate limits deny abusive clients (fail closed, rate_limited).

    Non-claims

    • No production AGTI maturity claim from radar publication alone.
    • No automatic containment, IPS push, or regulatory filing from radar cells.
    • Automated verification: Source-available test suite (threatradar & agti scrub engine).

    Industry verticals

    Turn-key deception packs

    Pre-configured decoy and sensor profiles tailored for specialized operational environments.

    Plant kinematics without operational interruption

    • Passive SPAN/TAP profiling → signed Zero-Collision Certificate before active OT
    • Rockwell MicroLogix, Siemens S7, water/wastewater ScenarioPlans
    • No real PLC on the sensor — Contained kinematics fiction

    Ecosystem

    Connects directly to your security stack

    Native SIEM exports, BYO webhook containment, and standard compliance payload schemas.

    Native exports & notifications Live today

    • Splunk
    • Microsoft Sentinel
    • Elastic
    • Wazuh
    • OCSF
    • Slack
    • Teams
    • ServiceNow
    • Jira
    • MSSP delegation

    Containment & EDR Beta

    • BYO webhook
    • LocalState

    Native CrowdStrike, Defender, SentinelOne, and Palo Alto SDKs remain GA-train.

    Cloud posture & read-only planner CNAPP

    • Wiz
    • Orca
    • Prisma Cloud

    Read-only shadow decoy proposal & approval; no cloud mutations.

    Compliance & deployment schemas

    • Vanta (CCM)
    • Drata (CCM)
    • ServiceNow GRC
    • Helm
    • Docker Compose
    • AWS / Azure / GCP private offer

    Containment stays fail-closed / dry-run by default. Soft/Hard on LocalState + BYO webhook after observe pilot (Beta).

    Answers

    Frequently asked questions

    What is CyberHalluciNet?

    CyberHalluciNet (CHN) is a source-available agentic deception platform. A fail-closed sensor engine runs the A.I. Decoy Engine across enterprise IT, OT/ICS, and AI-agent surfaces. Models may suggest decoy content; sensor policy retains wire authority, and detection scores never auto-block without human Propose→Approve→Execute. Default research binds stay on loopback until operators clear production gates.

    How does Split Authority keep AI fail-closed?

    Split Authority separates attacker wire bytes from AI content suggestions. The sensor policy engine owns protocol responses and egress decisions. The AI broker is schema-bound and suggestion-only: model output cannot grant OS execution, network egress, or tier changes. Telemetry scores never mutate firewall or IAM without an operator-approved workflow.

    What attack surfaces does the A.I. Decoy Engine cover?

    Three pillars: agentless ITDR and identity lures; OT/ICS plant kinematics (including Modbus, EtherNet/IP, and Rockwell water/wastewater packs); and AI-native decoys such as MCP decoy canaries and schema-valid agent tool traps. Interaction tiers are Contained, Emulated, and ack-gated Live on disposable guests.

    How do I try the agentic defense lab?

    From a repo checkout run make agentic-lab-install, then follow the detection lab and optional active response lab. Detection defaults stay off until you enable observe mode. Active response stays observe-first.

    Is CyberHalluciNet SOC 2 or FedRAMP certified?

    No certification claim is made until an accredited issuer says so. The public Trust Center publishes ASR/VRM stubs, DFDs, SOC2/ISO mapping templates, and Bonterms/DPA drafts as readiness mapping and engineering controls—not certificates. Download the ASR kit from the Trust page for Infosec and Legal review.

    Friction-free procurement

    Stage in 10 minutes. Review in days. Contract with standards you already use.

    Agentic lab install

    make agentic-lab-install builds a loopback lab for decoy-touch detection and optional active response.

    Install tutorials

    Downloadable ASR kit

    Architecture & Security Review (ASR) package: CAIQ/SIG-Lite stubs, DFDs, SOC 2/ISO mapping templates, and Bonterms/DPA drafts in one ZIP.

    Standardized contracting

    Bonterms-oriented DPA drafts and AWS/Azure/GCP private offer checklist for committed-spend conversations.

    Trust & procurement

    Readiness mapping and engineering controls — not SOC 2 / ISO / FedRAMP / DORA certification claims until an accredited issuer says so.