Sundew deploys realistic-looking services that attract autonomous AI agents, then fingerprints and classifies their behavior. Each deployment is unique, powered by a persona engine that generates coherent identities, making every instance indistinguishable from a real service.Named after the sundew plant, a carnivorous plant with sticky tentacles that glisten like dewdrops. Insects are attracted, land, and cannot escape.
Autonomous AI agents are the next frontier in offensive security. They browse the web, call APIs, connect to MCP servers, and execute multi-step attack chains, all without human guidance. Thirty years of honeypot research has focused on human attackers. Almost nothing exists for AI agents.Sundew fills that gap. It exposes the surfaces AI agents actually interact with (MCP servers, OpenAPI specs, AI plugin manifests) and uses behavioral fingerprinting to classify whether visitors are human, automated scanners, AI-assisted tools, or fully autonomous agents.The core innovation is the persona engine. When an AI agent learns what one honeypot looks like, it can avoid all identical deployments. Sundew solves this by generating a unique identity for every instance: different company names, API structures, response formats, timing profiles, and data themes.