Vortacity Cyber · Early Access
Early-warning deception for Microsoft 365.
TrapLine plants believable decoys across SharePoint, Outlook, Teams, and Entra ID. When any identity touches one, your team gets an alert worth acting on. No agents, no appliances, live in minutes.
The problem
Attackers don’t explore Microsoft 365 the way employees do.
Legitimate users follow routine. Compromised identities, malicious insiders, and automated tooling wander: searching broadly, probing sensitive-looking resources, and opening locations no employee has a reason to visit. That behavioral gap is exactly what deception is built to catch.
A legitimate user
- Works in known files and frequent folders
- Visits expected teams and sites
- Repeats routine, predictable workflows
- Touches business-relevant resources only
A compromised identity
- Searches and enumerates broadly
- Probes sensitive-looking resources
- Accesses unfamiliar locations
- Follows curiosity toward apparent value
TrapLine creates resources legitimate users should never touch, but intruders are likely to discover. Any access to a decoy is a signal worth acting on.
How it works
Deception through Microsoft-native telemetry.
No endpoint agent. No network appliance. The signal is the resource access itself.
-
Deploy decoys
Connect your tenant and TrapLine places believable decoy resources across your Microsoft 365 environment. Administrator-approved, live in minutes.
-
Blend into real workloads
Decoys live where the work happens: in SharePoint, Outlook, Teams, and Entra ID, alongside the resources attackers go looking for.
-
Watch the Unified Audit Log
TrapLine monitors Microsoft’s own audit event stream, the same log your tenant is already writing.
-
Detect decoy access
When any identity touches a decoy, TrapLine turns that event into a high-signal alert. Legitimate users have no reason to be there.
-
Route the alert
Delivered to email, Slack, or Microsoft Teams with the identity and resource involved, so responders can move straight to action.
Illustrative alert: identities and resource names are examples.
Why TrapLine
Deception without the deployment project.
Nothing to install, nothing to maintain
No endpoint agent, no network appliance, no browser extension. TrapLine deploys through an administrator-approved tenant connection. There is nothing to package, patch, or push to devices, and setup averages under five minutes.
Built on telemetry you already have
Detection is built on the Unified Audit Log. Nothing new runs on endpoints and nothing sits in your network path. TrapLine reads the signal Microsoft is already producing for your tenant.
Alerts grounded in access, not anomalies
Legitimate users have no reason to touch a decoy, and detection doesn’t depend on anyone clicking a tracked link. When a decoy is accessed, you get the identity and the resource involved, not pattern-matching noise.
Coverage
Decoys across four Microsoft 365 workloads.
All four surfaces are live today, watched through the same Microsoft-native audit telemetry. Below: the kind of resource TrapLine plants in each.
Seeded alongside real sites and content, placed where broad enumeration is likely to look.
In the mail surface, so identity activity that strays beyond legitimate mailboxes surfaces as signal.
Inside the collaboration surface: the teams and channels a curious identity explores but an employee never needs.
Identity-layer decoys that no legitimate workflow should ever reference: a tripwire at the directory itself.
Resource names above are illustrative examples, not real customer data.
Early Access
Designed to deploy in minutes.
Design partners across organization sizes are validating deployment speed, alert workflows, and Microsoft 365 coverage, and MSP / MSSP multi-tenant support is live.
Who’s behind TrapLine
Built by offensive-security operators: an experienced pentester and red teamer with years of offensive operations against cloud-first enterprises, and a former Microsoft engineer who built and shipped inside the Microsoft 365 ecosystem. Multiple real-world M365 deception research efforts and public talks stand behind the product, and a multiple-time startup CEO leads go-to-market.
FAQ
Questions security teams ask first.
Does TrapLine require an endpoint agent?
No. TrapLine is agentless. Nothing is installed on user devices, and there is no software to package, patch, or push.
What Microsoft 365 signals does TrapLine use?
TrapLine monitors the Microsoft Unified Audit Log, the native event stream your tenant already produces. When an identity accesses a decoy resource, that event becomes an alert with the identity and resource involved.
What access does TrapLine need to my tenant?
TrapLine connects to your Microsoft 365 tenant through an administrator-approved connection, places decoy resources, and reads the Unified Audit Log, telemetry your tenant already produces. If you want a detailed permissions walkthrough before a pilot, write to info@vortacity.com.
What happens to my data?
Detection works from Unified Audit Log events in your tenant. Rather than gloss data handling on a marketing page, we answer it directly: ask us at info@vortacity.com and we’ll walk through exactly what is read and stored for your deployment.
How quickly can it deploy?
Deployment is administrator-approved and averages under five minutes from tenant connect to live decoys.
Early Access
Add deception to Microsoft 365 in minutes.
Connect your tenant, place believable decoys, and turn any decoy access into an alert your team can act on.