Vortacity Cyber · Early Access

Early-warning deception for Microsoft 365.

TrapLine plants believable decoys across SharePoint, Outlook, Teams, and Entra ID. When any identity touches one, your team gets an alert worth acting on. No agents, no appliances, live in minutes.

  • Avg deploy under 5 minutes
  • No endpoint agent

The problem

Attackers don’t explore Microsoft 365 the way employees do.

Legitimate users follow routine. Compromised identities, malicious insiders, and automated tooling wander: searching broadly, probing sensitive-looking resources, and opening locations no employee has a reason to visit. That behavioral gap is exactly what deception is built to catch.

A legitimate user

  • Works in known files and frequent folders
  • Visits expected teams and sites
  • Repeats routine, predictable workflows
  • Touches business-relevant resources only

A compromised identity

  • Searches and enumerates broadly
  • Probes sensitive-looking resources
  • Accesses unfamiliar locations
  • Follows curiosity toward apparent value

TrapLine creates resources legitimate users should never touch, but intruders are likely to discover. Any access to a decoy is a signal worth acting on.

How it works

Deception through Microsoft-native telemetry.

No endpoint agent. No network appliance. The signal is the resource access itself.

  1. Deploy decoys

    Connect your tenant and TrapLine places believable decoy resources across your Microsoft 365 environment. Administrator-approved, live in minutes.

  2. Blend into real workloads

    Decoys live where the work happens: in SharePoint, Outlook, Teams, and Entra ID, alongside the resources attackers go looking for.

  3. Watch the Unified Audit Log

    TrapLine monitors Microsoft’s own audit event stream, the same log your tenant is already writing.

  4. Detect decoy access

    When any identity touches a decoy, TrapLine turns that event into a high-signal alert. Legitimate users have no reason to be there.

  5. Route the alert

    Delivered to email, Slack, or Microsoft Teams with the identity and resource involved, so responders can move straight to action.

Why TrapLine

Deception without the deployment project.

Nothing to install, nothing to maintain

No endpoint agent, no network appliance, no browser extension. TrapLine deploys through an administrator-approved tenant connection. There is nothing to package, patch, or push to devices, and setup averages under five minutes.

Built on telemetry you already have

Detection is built on the Unified Audit Log. Nothing new runs on endpoints and nothing sits in your network path. TrapLine reads the signal Microsoft is already producing for your tenant.

Alerts grounded in access, not anomalies

Legitimate users have no reason to touch a decoy, and detection doesn’t depend on anyone clicking a tracked link. When a decoy is accessed, you get the identity and the resource involved, not pattern-matching noise.

Coverage

Decoys across four Microsoft 365 workloads.

All four surfaces are live today, watched through the same Microsoft-native audit telemetry. Below: the kind of resource TrapLine plants in each.

SharePoint Live
XLSX Acquisition-Targets-FY26.xlsx Sites · Corp-Finance · Archive Decoy

Seeded alongside real sites and content, placed where broad enumeration is likely to look.

Outlook Live
MBX payroll-archive@tenant.example Shared mailbox Decoy

In the mail surface, so identity activity that strays beyond legitimate mailboxes surfaces as signal.

Teams Live
TEAM HR-Restricted › #exec-compensation Private team · channel Decoy

Inside the collaboration surface: the teams and channels a curious identity explores but an employee never needs.

Entra ID Live
SVC svc-legacy-backup@tenant.example Directory account Decoy

Identity-layer decoys that no legitimate workflow should ever reference: a tripwire at the directory itself.

Resource names above are illustrative examples, not real customer data.

Early Access

Designed to deploy in minutes.

<5 min average deployment

Design partners across organization sizes are validating deployment speed, alert workflows, and Microsoft 365 coverage, and MSP / MSSP multi-tenant support is live.

Who’s behind TrapLine

Built by offensive-security operators: an experienced pentester and red teamer with years of offensive operations against cloud-first enterprises, and a former Microsoft engineer who built and shipped inside the Microsoft 365 ecosystem. Multiple real-world M365 deception research efforts and public talks stand behind the product, and a multiple-time startup CEO leads go-to-market.

FAQ

Questions security teams ask first.

Does TrapLine require an endpoint agent?

No. TrapLine is agentless. Nothing is installed on user devices, and there is no software to package, patch, or push.

What Microsoft 365 signals does TrapLine use?

TrapLine monitors the Microsoft Unified Audit Log, the native event stream your tenant already produces. When an identity accesses a decoy resource, that event becomes an alert with the identity and resource involved.

What access does TrapLine need to my tenant?

TrapLine connects to your Microsoft 365 tenant through an administrator-approved connection, places decoy resources, and reads the Unified Audit Log, telemetry your tenant already produces. If you want a detailed permissions walkthrough before a pilot, write to info@vortacity.com.

What happens to my data?

Detection works from Unified Audit Log events in your tenant. Rather than gloss data handling on a marketing page, we answer it directly: ask us at info@vortacity.com and we’ll walk through exactly what is read and stored for your deployment.

How quickly can it deploy?

Deployment is administrator-approved and averages under five minutes from tenant connect to live decoys.

TrapLine anglerfish logo

Early Access

Add deception to Microsoft 365 in minutes.

Connect your tenant, place believable decoys, and turn any decoy access into an alert your team can act on.