Back to browse
GitHub Repository

Honeypot canaries for AI agents. Detect compromised agents via fake credentials that phone home when used.

5 starsGo

Snare – catch hijacked AI agents before they make their first AWS call

by trevxr·Mar 18, 2026·1 point·1 comment

AI Analysis

●●●BangerBig BrainWizardry

AWS credential_process canary fires at T+0.01s before CloudTrail sees anything.

Strengths
  • Exploits credential_process shell hook for zero-daemon compromise detection.
  • Boto3 user agent and ASN data identify AI agents specifically.
  • Precision mode plants only high-signal canaries to avoid false positives.
Weaknesses
  • Only Linux and macOS support; Windows users cannot run the tool.
  • Requires webhook setup; no built-in dashboard for alert management.
Category
Target Audience

Security engineers running AI agents with cloud access

Similar To

Canary Tokens · AWS GuardDuty

Similar Projects

AI/ML●●●Banger

ToolGuard – Pytest for AI agent tool calls

Finally, pytest for AI tool calls when evals only test intelligence.

Solve My ProblemZero to One
Heer_J
122mo ago
Security●●Solid

Vectimus – Cedar policy enforcement for AI coding agents

Cedar policies block `terraform destroy` before AI agents execute it.

Big BrainShip It
JXavierH
322mo ago