Trapster — Deceptive Security, with Ballpoint
Catch the attacker
The moment they start looking.
Trapster deploys credible decoys inside your network: fake services, machines and accounts that no legitimate activity should ever touch.
Any interaction with a decoy is a strong signal, with almost no false positives. Ariovis designs the deception scenario around your identity reality and plugs the alerts into your detection and response chain.
- Trapster is published by Ballpoint.
- Ariovis handles identity scoping, deployment and operations.
Ariovis × Ballpoint
Trapster is a Deceptive Security solution published by Ballpoint, a French offensive security company. Ariovis does not publish Trapster.
Ariovis brings the identity reading: where to place decoys, which accounts to imitate, which attack paths to trap, and how to handle the alerts once they arrive.
The principle: make silence detectable.
Most tools try to spot an attack inside a flood of legitimate activity. Deception flips the logic: it creates objects that have no reason to ever be touched.
An attacker exploring the environment, enumerating the directory or testing credentials eventually hits a decoy. At that moment they reveal themselves — no signature or correlation required.
Attract
Realistic services, machines and accounts are deployed where an attacker looks first.
Signal
Any interaction is abnormal by design: the false positive rate is structurally very low.
Respond
The alert is qualified, tied to an identity, a machine and an attack path, then handled in your existing processes.
Why deception belongs on identity ground
A modern intrusion rarely relies on a spectacular exploit. It relies on identities: a valid account, a forgotten entitlement, a reused secret.
- Attackers almost always start by enumerating the directory
- They look for service accounts, shares and weakly protected machines
- They test credentials harvested elsewhere
- They look for an escalation path to a privileged account
- These actions often look like legitimate administration activity
Use cases
Deception does not replace securing identities: it complements it by showing what the attacker is attempting, before they reach a real asset.
Active Directory and internal network
- Detect directory enumeration
- Trap escalation paths to sensitive accounts
- Spot lateral movement
- Watch deliberately attractive shares and machines
Privileged accounts
- Fake administration and service accounts
- Fake secrets and fake access outside the PAM
- Detection of vault bypass attempts
Sensitive and legacy environments
- Industrial or legacy perimeters that are hard to instrument
- Zones where no agent can be deployed
- Isolated network segments
After a pentest or an incident
- Instrument the attack paths that were demonstrated
- Verify they are no longer used
- Keep a detection capability over time
How it is put in place
- 1
Design the scenario
Ariovis identifies the identities, network zones and attack paths to instrument, consistently with your entitlement model and privileged accounts.
- 2
Deploy the decoys
Fake services, machines and accounts are deployed with Trapster so they stay credible to an attacker and invisible to legitimate usage.
- 3
Wire up detection
Alerts are integrated into your tooling: SIEM, SOC, monitoring or internal response processes.
- 4
Operate over time
Ariovis supports alert qualification, decoy tuning and the link with identity remediation.
Technical details, product capabilities and commercial terms are owned by Ballpoint.
Who does what?
Ballpoint
Trapster publisher
- Product publishing and roadmap
- Decoy capabilities
- Detection engine
- Product documentation
- Commercial terms
- Vendor support
Ariovis
Identity scenario, integration and operations
- Deception scenario design
- Choice of identities and paths to trap
- Consistency with Active Directory, IAM and PAM
- Integration into the detection chain
- Alert qualification and handling
- Link with remediation
- Skills transfer
Ballpoint provides the deception capability.
Ariovis wires it into your identity reality and your processes.
What deception does not replace
Trapster is a detection capability. It does not replace the foundations of identity security.
It is not an antivirus or an EDR
Deception detects exploration behaviour, not a malicious binary.
It is not identity governance
It fixes neither excessive entitlements, nor orphan accounts, nor JML processes.
It is not a PAM
It does not remove standing privileges or exposed secrets.
Deception delivers most value while the foundations are being fixed: it gives visibility on what is happening as the attack surface shrinks.
Frequently asked questions
Who publishes Trapster?
Trapster is published by Ballpoint. Ariovis does not publish the solution: we work on deception scenario design, integration, alert handling and the related identity remediation.
Does it generate many false positives?
The very principle of deception limits false positives: decoys have no legitimate use, so any interaction is abnormal by design. Scoping work mainly ensures no internal tool or inventory scan touches them by accident.
Do we need a SOC or a SIEM already?
Not necessarily. Alerts can be routed to your existing tooling, or to a simpler handling process defined with you during scoping.
Can we start with a limited perimeter?
Yes. A first targeted scenario — for example Active Directory and privileged accounts — lets you measure the value before extending the setup.
How does it relate to a penetration test?
They complement each other: a pentest demonstrates exploitable attack paths, deception then detects when someone actually tries to use them.
See the attacker before they reach a real asset.
Let's build a deception scenario aligned with your identities, your privileged accounts and your real attack paths.