Skip to main content

Changelog

Follow new updates and improvements to Praetorian.

Knossos: Procedurally Generated Decoy Environments That Turn Attackers into Intelligence

June 26th, 2026 New Feature

Praetorian Guard now procedurally generates fully operational decoy cloud environments — realistic infrastructure designed to make attackers waste their time against a fake environment instead of investing it in your real one. Unlike static honeypots or manually configured decoys, Knossos generates complete Terraform plans with authentic attack paths, breadcrumb trails, and live alert wiring — all from a single style profile.

The core idea is simple: every hour an attacker spends navigating a decoy environment is an hour they’re not spending on production. Much of the engineering has been spent making these environments indistinguishable from the real thing. Every resource has realistic names, tags, security groups, IAM policies, and cross-references. Attackers who discover one resource find breadcrumbs leading them deeper into the labyrinth — burning their time and operational budget while every step triggers real-time alerts back to the defender.

What’s new

Knossos introduces a full deception generation pipeline — from environment design through Terraform plan output to active threat intelligence — directly inside Guard.

  • Style profile inference — Point Knossos at your real infrastructure data and it reverse-engineers a style profile: naming conventions, tag patterns, region preferences, resource distributions, and security posture. Your deception environment mirrors what attackers expect to find

  • Environment generation — One API call produces a complete Terraform plan with VPCs, subnets, EC2 instances, RDS databases, Lambda functions, S3 buckets, IAM roles, secrets, and security groups — all wired together with realistic dependencies

  • Breadcrumb trails — Automated attack-path injection plants discoverable cross-references between resources: secrets that reference database endpoints, S3 objects containing SSH configs, Lambda environment variables pointing to the next hop. Each breadcrumb is a trap

  • Live alert wiring — Every deception resource is instrumented with CloudWatch alarms, EventBridge rules, and API destination callbacks that fire the moment an attacker touches anything — ingest events flow directly into Guard for triage and response

  • Camouflage layer — Beyond the resources that serve the attack paths, Knossos pads the environment with camouflage resources — extra VPCs, instances, buckets, and roles — distributed to match the cardinality ratios of your real infrastructure. Operators control the camouflage density through a single scale parameter so the deception environment never looks suspiciously sparse or bloated

  • Defense in depth — Every generated environment ships with three isolation layers: a dedicated VPC with deny-all NACLs that prevents any network path to production, an IAM permission boundary that blocks privilege escalation while appearing fully permissive to the attacker, and a ready-to-apply Service Control Policy (SCP) that operators attach at the account or OU level to enforce the boundary from outside the environment

  • Cost estimation — Before deploying, Knossos estimates the monthly cost of the deception environment using live pricing data, so operators can tune resource caps and stay within budget

  • Activity simulation — Optional simulator roles generate background API activity against deception resources, making the environment appear actively used and increasing attacker dwell time

  • Multi-provider roadmap — The emitter architecture is provider-pluggable. AWS ships first with full coverage; GCP and Azure emitters follow the same registry pattern and are in development

Why Knossos?

In Greek mythology, Daedalus built the Labyrinth beneath the palace of Knossos on Crete — an inescapable maze designed to contain the Minotaur. Those who entered could not find their way out. The labyrinth was not a prison for the monster alone; it was a trap for anyone who dared enter uninvited. King Minos used it as the ultimate defensive architecture: a structure so complex that the threat eliminated itself. Knossos brings the same principle to cloud security — deception environments so realistic that attackers walk in willingly, and every step they take becomes intelligence for the defender.

NewFeature

Hannibal: Autonomous, Long-Running Agentic Offensive Cyber Operations

Praetorian Guard now supports AI-enabled, fully autonomous, persistent attacks. Users can now define directives that continuously task the compute fleet to investigate specific targets or attack hypotheses. Unlike unsophisticated vulnerability scans or human-in-the-loop AI penetration testing, Hannibal runs autonomously and iteratively, accumulates cross-iteration learning, and files risks based on demonstrated compromise, linked back to the operational directive. Much of the engineering time has been spent on implementing enterprise-grade controls for efficacy, safety, and token efficiency.

Key features include:

  • Asset risk scores — When all tenant infrastructure is in scope, Hannibal leverages pre-computed asset risk scores for target selection

  • Guardrails — Safety and prevention controls to restrict scope, targeting, and actions through code enforcement and policy

  • Iterative memory — Rather than each run starting cold, working state persists across iterations so signal and compromises from earlier runs inform subsequent investigations

  • Judge agents — Adversarial review agents to help control hallucinations and false positives

  • Operation directives — Operators define a scoped hunt with a target, goal, and allowed tool set; the platform enqueues and manages execution across the compute fleet

  • Orchestration — Orchestrator/subagent architecture to coordinate delegation and execution

  • Subagents — Subagent delegation for specialized attack vectors across attack surfaces

  • Skills — A collection of offensive security agent skills benchmarked against 15 models

  • Risk linkage — Compromises from an operation are filed as Guard risks tagged with the originating hunt, enabling tracking and attribution

  • Authentication support — Works across various attack surfaces, including authenticated web applications, with compatibility for local authentication, single sign-on (SSO), two-factor authentication (2FA), and more

  • Watermarks — Hannibal uses watermarks to prevent retargeting recently targeted assets and risks

  • Workflows — Reusable, multi-step playbooks that chain skills and subagents into repeatable attack sequences, letting operators codify proven methodologies and apply them consistently across operations

Why Hannibal?

After Hannibal's invasion of Italy during the Second Punic War and following his devastating victory at the Battle of Cannae, Romans viewed the Carthaginian general as the greatest threat of their time. Roman children were taught that Hannibal grew up with a blood oath of eternal hatred toward Rome, and Roman parents would terrify their misbehaving children with the warning, “Hannibal ad portas!” …Hannibal is at the gates.

NewFeature

CrowdStrike Falcon Integration — Now Unified with Flight Control Support

Big update to our CrowdStrike Falcon integration! We've consolidated the experience into a single, modular integration and added Flight Control (MSSP) support — so whether you're managing one tenant or hundreds, the Praetorian Guard Platform (PGP) has you covered.

Continuous Visibility Into What's Exposed

Your CrowdStrike Falcon deployment already sees your endpoints and their vulnerabilities — now PGP pulls that data in automatically to enrich your attack surface. Hosts sync as assets, open CVEs from Spotlight flow in as risks filtered to network-reachable attack vectors, and everything correlates against your external exposure. The result: you can trace attack paths from the internet to vulnerable internal endpoints and prioritize remediation based on what's actually reachable — not just what has a high CVSS score.

What's New

  • One integration, three toggleable modules — Hosts, Spotlight, and Shield are now managed from a single CrowdStrike integration with per-module checkboxes in the UI. Smart cross-module caching means Spotlight reuses the Hosts device cache for vulnerability-to-asset correlation, eliminating redundant API calls.
  • Flight Control (MSSP) support — Connect at the master CID level and PGP automatically discovers all child tenants, fanning out per-tenant syncs using a single set of parent credentials. No more onboarding child CIDs one by one.

How It Connects to CrowdStrike

The integration authenticates via OAuth2 client credentials (POST /oauth2/token), with automatic member_cid scoping for Flight Control child tenants. Each module probes its API scope with a lightweight limit=1 query before running to ensure your credentials have the right permissions.

ModuleWhat It SyncsCrowdStrike APIs
HostsEndpoint inventory → PGP assets/devices/queries/devices-scroll/v1 (scrolls device IDs, filtered to non-Workstation devices seen in the last 7 days) → /devices/entities/devices/v2 (hydrates in batches of 100)
SpotlightOpen CVEs → PGP risks/spotlight/queries/vulnerabilities/v1 (paginates open vulns, non-Workstation, updated in last 7 days) → /spotlight/entities/vulnerabilities/v2 (hydrates in batches of 100)
ShieldSaaS security posture (coming soon)/saas-security/queries/saas-resources/v1 (scope validation only — full sync coming in a future release)
Flight ControlChild CID discovery → per-tenant syncs/mssp/queries/children/v1 (paginates all child CIDs under the master)

Concurrency & Rate Limits

PGP caps concurrent API requests at 10 parallel calls during device hydration and vulnerability fetching. CrowdStrike enforces its own API rate limits on the Falcon side. If you're running into rate limiting issues with large environments, reach out to your Praetorian team and we'll work with you to tune throughput.

ImprovedFeature

Earlier updates