Controlled environments
Clone selected public pages, remove active content and add synthetic protected material behind an explicit access barrier.
Human-centred cyber deception
Simbotnik gives security teams one workspace to plan external deception operations, build controlled decoy environments, assess observed engagement and deliver reviewed findings into existing intelligence workflows.
Built on more than 25 years of experience in cybersecurity, telecommunications and threat intelligence.
Cyber defence through deception
Conventional cyber decoys wait for an adversary or automated tool to touch a server, service or protocol. Simbotnik creates controlled, externally hosted trails that a researcher can discover and choose to explore, without placing the decoy inside production.
Built for security teams that want to understand interest in their organisation, not simply count probes.
This focus aligns with MITRE ATT&CK Reconnaissance (TA0043), while the campaign model reflects MITRE Engage's planned approach to adversary engagement.
Clone selected public pages, remove active content and add synthetic protected material behind an explicit access barrier.
Record actions such as repeated login failures, use of planted credentials and access to protected decoy content.
Apply an operation-specific score, retain analyst control over promotion and deliver approved findings through STIX and TAXII.
How it works
Simbotnik applies the logic of an engagement funnel to adversary research. Each step through the deception adds context, turning an anonymous visit into a measurable journey.
Set the collection objective, decoy domain, lure and behaviour policy in one managed workspace.
Clone selected public pages, remove forms, scripts and analytics, then review a private preview before activation.
Generate grounded publication copy from the approved source pages and keep publication as an explicit operator action.
Apply configured points and occurrence barriers to actions recorded inside the controlled environment.
Require an analyst decision before an eligible engagement becomes a malicious sighting or indicator.
Evidence remains bounded. A request to a decoy is an observation, not proof of malicious intent or identity. Simbotnik keeps directly observed activity separate from external context and analyst assessment.
Product evidence
The current operator interface connects operation planning, decoy preparation, evidence review and standards-based delivery. The views below use fictional demonstration data.
Move through planning, environment preparation, lures, launch review and results with explicit readiness checks.
Compare observed actions with operation-specific barriers before an analyst promotes a sighting.
Publish Observed Data and reviewed Indicator, Sighting and Note objects through a tenant-scoped TAXII 2.1 collection.



Interface captured from the current MVP using fictional local demonstration data. Product details may change during active development.
The model
Most honeypots emulate software, systems or protocols. Simbotnik creates an information environment for a human researcher to discover and explore, then analyses the journey through it.
The current workflow builds a controlled website decoy from selected public pages, with synthetic protected content and an attributed lure URL. Additional environment types remain part of ongoing development.
Each operation defines points and occurrence barriers for observable actions. The interface exposes every contribution and requires analyst review before promotion to a malicious sighting.
Recorded interactions produce STIX 2.1 Observed Data. Analyst-promoted findings additionally produce Indicator, Sighting and assessment Note objects, available through a tenant-scoped TAXII 2.1 collection.
The briefing covers operation design, decoy preparation, engagement scoring, STIX/TAXII output and the requirements for evaluating Simbotnik in your environment.
Experience
Simbotnik's founder brings more than 25 years of experience across telecommunications, cybersecurity and threat intelligence, including hands-on work with government and military customers. That background informs the product's focus: collecting useful evidence, understanding adversary behaviour and delivering intelligence that security teams can act on.
Private briefing
Walk through operation planning, a private decoy preview, behavioural assessment and STIX/TAXII delivery, then discuss how an authorised evaluation could be shaped around your organisation.
The product is in active development. Private demonstrations are available.
For investment enquiries, use the same form and select Investment.