AriovisPrivileged partner

Trapster — Deceptive Security, with Ballpoint

Catch the attacker
The moment they start looking.

Trapster deploys credible decoys inside your network: fake services, machines and accounts that no legitimate activity should ever touch.

Any interaction with a decoy is a strong signal, with almost no false positives. Ariovis designs the deception scenario around your identity reality and plugs the alerts into your detection and response chain.

  • Trapster is published by Ballpoint.
  • Ariovis handles identity scoping, deployment and operations.

Ariovis × Ballpoint

Trapster is a Deceptive Security solution published by Ballpoint, a French offensive security company. Ariovis does not publish Trapster.

Ariovis brings the identity reading: where to place decoys, which accounts to imitate, which attack paths to trap, and how to handle the alerts once they arrive.

The principle: make silence detectable.

Most tools try to spot an attack inside a flood of legitimate activity. Deception flips the logic: it creates objects that have no reason to ever be touched.

An attacker exploring the environment, enumerating the directory or testing credentials eventually hits a decoy. At that moment they reveal themselves — no signature or correlation required.

Attract

Realistic services, machines and accounts are deployed where an attacker looks first.

Signal

Any interaction is abnormal by design: the false positive rate is structurally very low.

Respond

The alert is qualified, tied to an identity, a machine and an attack path, then handled in your existing processes.

Why deception belongs on identity ground

A modern intrusion rarely relies on a spectacular exploit. It relies on identities: a valid account, a forgotten entitlement, a reused secret.

  • Attackers almost always start by enumerating the directory
  • They look for service accounts, shares and weakly protected machines
  • They test credentials harvested elsewhere
  • They look for an escalation path to a privileged account
  • These actions often look like legitimate administration activity
Decoys designed in identity terms — fake privileged accounts, fake service accounts, fake sensitive shares — sit exactly on that path. They turn quiet reconnaissance into an explicit alert.

Use cases

Deception does not replace securing identities: it complements it by showing what the attacker is attempting, before they reach a real asset.

Active Directory and internal network

  • Detect directory enumeration
  • Trap escalation paths to sensitive accounts
  • Spot lateral movement
  • Watch deliberately attractive shares and machines
Identity & Active Directory security service

Privileged accounts

  • Fake administration and service accounts
  • Fake secrets and fake access outside the PAM
  • Detection of vault bypass attempts
Privileged Access Management service

Sensitive and legacy environments

  • Industrial or legacy perimeters that are hard to instrument
  • Zones where no agent can be deployed
  • Isolated network segments
Identity governance service

After a pentest or an incident

  • Instrument the attack paths that were demonstrated
  • Verify they are no longer used
  • Keep a detection capability over time
Identity & access penetration testing

How it is put in place

  1. 1

    Design the scenario

    Ariovis identifies the identities, network zones and attack paths to instrument, consistently with your entitlement model and privileged accounts.

  2. 2

    Deploy the decoys

    Fake services, machines and accounts are deployed with Trapster so they stay credible to an attacker and invisible to legitimate usage.

  3. 3

    Wire up detection

    Alerts are integrated into your tooling: SIEM, SOC, monitoring or internal response processes.

  4. 4

    Operate over time

    Ariovis supports alert qualification, decoy tuning and the link with identity remediation.

Technical details, product capabilities and commercial terms are owned by Ballpoint.

Who does what?

Ballpoint

Trapster publisher

  • Product publishing and roadmap
  • Decoy capabilities
  • Detection engine
  • Product documentation
  • Commercial terms
  • Vendor support
Ariovis

Ariovis

Identity scenario, integration and operations

  • Deception scenario design
  • Choice of identities and paths to trap
  • Consistency with Active Directory, IAM and PAM
  • Integration into the detection chain
  • Alert qualification and handling
  • Link with remediation
  • Skills transfer

Ballpoint provides the deception capability.

Ariovis wires it into your identity reality and your processes.

What deception does not replace

Trapster is a detection capability. It does not replace the foundations of identity security.

It is not an antivirus or an EDR

Deception detects exploration behaviour, not a malicious binary.

It is not identity governance

It fixes neither excessive entitlements, nor orphan accounts, nor JML processes.

It is not a PAM

It does not remove standing privileges or exposed secrets.

Deception delivers most value while the foundations are being fixed: it gives visibility on what is happening as the attack surface shrinks.

Frequently asked questions

Who publishes Trapster?

Trapster is published by Ballpoint. Ariovis does not publish the solution: we work on deception scenario design, integration, alert handling and the related identity remediation.

Does it generate many false positives?

The very principle of deception limits false positives: decoys have no legitimate use, so any interaction is abnormal by design. Scoping work mainly ensures no internal tool or inventory scan touches them by accident.

Do we need a SOC or a SIEM already?

Not necessarily. Alerts can be routed to your existing tooling, or to a simpler handling process defined with you during scoping.

Can we start with a limited perimeter?

Yes. A first targeted scenario — for example Active Directory and privileged accounts — lets you measure the value before extending the setup.

How does it relate to a penetration test?

They complement each other: a pentest demonstrates exploitable attack paths, deception then detects when someone actually tries to use them.

See the attacker before they reach a real asset.

Let's build a deception scenario aligned with your identities, your privileged accounts and your real attack paths.