Vortacity Cyber · Early Access

Early-warning deception for Microsoft 365.

TrapLine plants believable decoys across SharePoint, OneDrive, Outlook, Entra ID, and Azure. When any identity touches one, your team gets an alert worth acting on. No agents, no appliances, live in minutes.

  • Avg deploy under 5 minutes
  • No endpoint agent

Inside TrapLine

See exactly what your team gets.

TrapLine dashboard showing the attention band, canary and trigger stats, activity sparkline, and a grouped work queue across multiple demo client tenants.
Dashboard · every client tenant on one attention band

The problem

Attackers don’t explore Microsoft 365 the way employees do.

Legitimate users follow routine. Compromised identities, malicious insiders, and automated tooling wander: searching broadly, probing sensitive-looking resources, and opening locations no employee has a reason to visit. That behavioral gap is exactly what deception is built to catch.

A legitimate user

  • Works in known files and frequent folders
  • Visits expected teams and sites
  • Repeats routine, predictable workflows
  • Touches business-relevant resources only

A compromised identity

  • Searches and enumerates broadly
  • Probes sensitive-looking resources
  • Accesses unfamiliar locations
  • Follows curiosity toward apparent value

TrapLine creates resources legitimate users should never touch, but intruders are likely to discover. Any access to a decoy is a signal worth acting on.

How it works

Deception through Microsoft-native telemetry.

No endpoint agent. No network appliance. The signal is the resource access itself.

  1. Deploy decoys

    Connect your tenant and TrapLine places believable decoy resources across your Microsoft 365 environment. Administrator-approved, live in minutes.

  2. Blend into real workloads

    Decoys live where the work happens: in SharePoint, OneDrive, Outlook, Entra ID, and Azure, alongside the resources attackers go looking for.

  3. Watch Microsoft’s audit telemetry

    TrapLine monitors the Unified Audit Log, Entra sign-in logs, and Azure resource audit logs: Microsoft’s own event streams, read from the cloud.

  4. Detect decoy access

    When any identity touches a decoy, TrapLine turns that event into a high-signal alert. Legitimate users have no reason to be there.

  5. Route the alert

    Delivered to Microsoft Teams and the TrapLine portal with the identity and resource involved, so responders can move straight to action.

TrapLine trigger investigation view with event timeline, actor identity, source IP, and correlated audit evidence for a decoy access.
Trigger investigation · identity, timeline, evidence

Why TrapLine

Deception without the deployment project.

Nothing to install, nothing to maintain

No endpoint agent, no network appliance, no browser extension. TrapLine deploys through an administrator-approved tenant connection. There is nothing to package, patch, or push to devices, and setup averages under five minutes.

Built on Microsoft-native telemetry

Microsoft 365 and identity decoys are watched through the Unified Audit Log and Entra sign-in logs, signal your tenant is already producing. Azure resource decoys get their own audit pipeline, provisioned automatically in your subscription at deploy time. Nothing runs on endpoints and nothing sits in your network path.

Alerts grounded in access, not anomalies

Legitimate users have no reason to touch a decoy, and detection doesn’t depend on anyone clicking a tracked link. When a decoy is accessed, you get the identity and the resource involved, not pattern-matching noise.

Coverage

Decoys across Microsoft 365, Entra ID, and Azure.

Seven decoy types, all live today, each watched through Microsoft-native audit telemetry. Below: the kind of resource TrapLine plants on each surface.

Microsoft 365 content Live
XLSX Acquisition-Targets-FY26.xlsx SharePoint · Corp-Finance · Archive Decoy
DOCX Exec-Severance-Terms.docx OneDrive · personal drive Decoy
MSG RE: Updated wire instructions Outlook · message in a real inbox Decoy

Decoy files and messages seeded alongside real content, including a decoy message placed directly in a real mailbox, where broad enumeration is likely to look.

Identity & applications Live
SVC svc-legacy-backup@tenant.example Entra ID · directory account Decoy
APP HR-Data-Sync Entra ID · app registration Decoy

Directory-layer tripwires no legitimate workflow should ever reference: a decoy account and a decoy app registration where any sign-in is signal.

Azure resources Live
KV kv-prod-secrets-bak Azure · Key Vault Decoy
BLOB stlegacyfinancearchive Azure · storage account Decoy

Believable infrastructure decoys in your subscription, with the audit telemetry that watches them provisioned automatically at deploy time.

TrapLine deploy wizard for placing a new decoy, with tenant and target selection.
Deploy · a decoy placed in minutes

Resource names above are illustrative examples, not real customer data.

MSP & MSSP

Built for service providers.

TrapLine is multi-tenant from the ground up: one portal to deploy decoys, watch collection health, and investigate triggers across every client you manage.

Monthly client-ready reports show coverage and what your team watched, in a document you can hand straight to the client, even in a quiet month.

Page one of a TrapLine monthly client report: masthead, stat strip, month-in-review narrative, analyst assessment, and recommended actions for a demo tenant.
Monthly report · client-ready evidence of value

Early Access

Designed to deploy in minutes.

<5 min average deployment

Design partners across organization sizes are validating deployment speed, alert workflows, and Microsoft 365 coverage, and MSP / MSSP multi-tenant support is live.

Who’s behind TrapLine

Built by offensive-security operators: an experienced pentester and red teamer with years of offensive operations against cloud-first enterprises, and a former Microsoft engineer who built and shipped inside the Microsoft 365 ecosystem. Multiple real-world M365 deception research efforts and public talks stand behind the product, and a multiple-time startup CEO leads go-to-market.

FAQ

Questions security teams ask first.

Does TrapLine require an endpoint agent?

No. TrapLine is agentless. Nothing is installed on user devices, and there is no software to package, patch, or push.

What signals does TrapLine use?

For Microsoft 365 and identity decoys, TrapLine monitors the Unified Audit Log and Entra sign-in logs, event streams your tenant already produces. For Azure resource decoys, TrapLine provisions audit logging in your subscription at deploy time and monitors it. When an identity accesses a decoy, that event becomes an alert with the identity and resource involved.

What access does TrapLine need to my tenant?

TrapLine connects to your Microsoft 365 tenant through an administrator-approved connection to place decoys and read audit telemetry. Azure resource decoys additionally use a role you grant in the target subscription. If you want a detailed permissions walkthrough before a pilot, write to info@vortacity.com.

What happens to my data?

Detection works from audit events in your tenant. Rather than gloss data handling on a marketing page, we answer it directly: ask us at info@vortacity.com and we’ll walk through exactly what is read and stored for your deployment.

How quickly can it deploy?

Deployment is administrator-approved and averages under five minutes from tenant connect to live decoys.

TrapLine anglerfish logo

Early Access

Add deception to Microsoft 365 in minutes.

Connect your tenant, place believable decoys, and turn any decoy access into an alert your team can act on.