An AI agent that pretends to be a compromised server. When an attacker exploits our fake company (Hivewell, a smart-beehive startup) and pops a "reverse shell," their terminal connects to a real socket — but on the other end is an agent playing bash inside a consistent synthetic machine. Nothing they type is executed.
The agent never breaks character. It keeps a stable fake filesystem, answers unknown commands in-world, and feeds tempting dead-ends — a fake .env, AWS keys, a database that times out — so the attacker burns time chasing loot that was never real. Meanwhile the control server logs every HTTP request and shell command to ClickHouse.
A second agent reads the whole session and writes an evidence-linked attacker playbook: classification, kill-chain stages, and the exact commands that prove each one — shown on the HoneyStack Shield dashboard with a live timeline and a "time wasted" counter.
Who it's for: blue teams, SOC and threat-intel analysts who want real attacker behavior instead of alert noise, and researchers studying how autonomous, agentic attackers operate.
Built on our partners: Akash hosts the public trap; ClickHouse is the telemetry backbone behind the live replay and metrics; Guild AI runs both agents. Everything the attacker sees is invented; everything they do becomes evidence.