Vortacity Cyber · Early Access
Early-warning deception for Microsoft 365.
TrapLine plants believable decoys across SharePoint, OneDrive, Outlook, Entra ID, and Azure. When any identity touches one, your team gets an alert worth acting on. No agents, no appliances, live in minutes.
Inside TrapLine
See exactly what your team gets.
The problem
Attackers don’t explore Microsoft 365 the way employees do.
Legitimate users follow routine. Compromised identities, malicious insiders, and automated tooling wander: searching broadly, probing sensitive-looking resources, and opening locations no employee has a reason to visit. That behavioral gap is exactly what deception is built to catch.
A legitimate user
- Works in known files and frequent folders
- Visits expected teams and sites
- Repeats routine, predictable workflows
- Touches business-relevant resources only
A compromised identity
- Searches and enumerates broadly
- Probes sensitive-looking resources
- Accesses unfamiliar locations
- Follows curiosity toward apparent value
TrapLine creates resources legitimate users should never touch, but intruders are likely to discover. Any access to a decoy is a signal worth acting on.
How it works
Deception through Microsoft-native telemetry.
No endpoint agent. No network appliance. The signal is the resource access itself.
-
Deploy decoys
Connect your tenant and TrapLine places believable decoy resources across your Microsoft 365 environment. Administrator-approved, live in minutes.
-
Blend into real workloads
Decoys live where the work happens: in SharePoint, OneDrive, Outlook, Entra ID, and Azure, alongside the resources attackers go looking for.
-
Watch Microsoft’s audit telemetry
TrapLine monitors the Unified Audit Log, Entra sign-in logs, and Azure resource audit logs: Microsoft’s own event streams, read from the cloud.
-
Detect decoy access
When any identity touches a decoy, TrapLine turns that event into a high-signal alert. Legitimate users have no reason to be there.
-
Route the alert
Delivered to Microsoft Teams and the TrapLine portal with the identity and resource involved, so responders can move straight to action.
Illustrative alert: identities and resource names are examples.
Why TrapLine
Deception without the deployment project.
Nothing to install, nothing to maintain
No endpoint agent, no network appliance, no browser extension. TrapLine deploys through an administrator-approved tenant connection. There is nothing to package, patch, or push to devices, and setup averages under five minutes.
Built on Microsoft-native telemetry
Microsoft 365 and identity decoys are watched through the Unified Audit Log and Entra sign-in logs, signal your tenant is already producing. Azure resource decoys get their own audit pipeline, provisioned automatically in your subscription at deploy time. Nothing runs on endpoints and nothing sits in your network path.
Alerts grounded in access, not anomalies
Legitimate users have no reason to touch a decoy, and detection doesn’t depend on anyone clicking a tracked link. When a decoy is accessed, you get the identity and the resource involved, not pattern-matching noise.
Coverage
Decoys across Microsoft 365, Entra ID, and Azure.
Seven decoy types, all live today, each watched through Microsoft-native audit telemetry. Below: the kind of resource TrapLine plants on each surface.
Decoy files and messages seeded alongside real content, including a decoy message placed directly in a real mailbox, where broad enumeration is likely to look.
Directory-layer tripwires no legitimate workflow should ever reference: a decoy account and a decoy app registration where any sign-in is signal.
Believable infrastructure decoys in your subscription, with the audit telemetry that watches them provisioned automatically at deploy time.
Resource names above are illustrative examples, not real customer data.
MSP & MSSP
Built for service providers.
TrapLine is multi-tenant from the ground up: one portal to deploy decoys, watch collection health, and investigate triggers across every client you manage.
Monthly client-ready reports show coverage and what your team watched, in a document you can hand straight to the client, even in a quiet month.
Early Access
Designed to deploy in minutes.
Design partners across organization sizes are validating deployment speed, alert workflows, and Microsoft 365 coverage, and MSP / MSSP multi-tenant support is live.
Who’s behind TrapLine
Built by offensive-security operators: an experienced pentester and red teamer with years of offensive operations against cloud-first enterprises, and a former Microsoft engineer who built and shipped inside the Microsoft 365 ecosystem. Multiple real-world M365 deception research efforts and public talks stand behind the product, and a multiple-time startup CEO leads go-to-market.
FAQ
Questions security teams ask first.
Does TrapLine require an endpoint agent?
No. TrapLine is agentless. Nothing is installed on user devices, and there is no software to package, patch, or push.
What signals does TrapLine use?
For Microsoft 365 and identity decoys, TrapLine monitors the Unified Audit Log and Entra sign-in logs, event streams your tenant already produces. For Azure resource decoys, TrapLine provisions audit logging in your subscription at deploy time and monitors it. When an identity accesses a decoy, that event becomes an alert with the identity and resource involved.
What access does TrapLine need to my tenant?
TrapLine connects to your Microsoft 365 tenant through an administrator-approved connection to place decoys and read audit telemetry. Azure resource decoys additionally use a role you grant in the target subscription. If you want a detailed permissions walkthrough before a pilot, write to info@vortacity.com.
What happens to my data?
Detection works from audit events in your tenant. Rather than gloss data handling on a marketing page, we answer it directly: ask us at info@vortacity.com and we’ll walk through exactly what is read and stored for your deployment.
How quickly can it deploy?
Deployment is administrator-approved and averages under five minutes from tenant connect to live decoys.
Early Access
Add deception to Microsoft 365 in minutes.
Connect your tenant, place believable decoys, and turn any decoy access into an alert your team can act on.