An AI agent researches each person and writes a lure just for them, the way attackers now work. Your security team scopes and approves every run.












Real attackers don’t reuse templates. They research one person and write one email. A library lure measures recognition, not exposure.
click-through on fully AI-written spear phishing, the same as human experts. Generic phishing got 12%.
Heiding et al., 2024, 101 participantsIllustrative example. Names and domains are fictional.
The agent scopes, researches, writes, sends and measures, then hands every lure and source back to your security team.
Nothing runs until your security team approves it.
Public sources only: web, LinkedIn, news and code search. 3 of 14 shown.
| Person | What the agent found | Sources |
|---|---|---|
| Dana R.Accounts payable | Runs vendor payments. Named Corvane Supply in a case study. | 3 |
| Omar K.Payments systems | Maintains the invoicing tool. Mentions it in a public repo. | 2 |
| Priya S.Finance operations | Spoke about quarter-end close at a conference. | 4 |
Two to three per person, reviewed by your team before anything sends.
Hi Dana, following our Q4 remittance call, payments now go through our new supplier portal. Please log in before Friday so the next run isn't delayed.
Nothing sends until the security team has read and approved it.
Every event timestamped, per person. No password is ever kept. 4 of 14 shown.
| Person | Lure | Event |
|---|---|---|
| Dana R. | Vendor remittance | Submitted 09:43Clicked 09:42 · no password kept |
| Leo M. | Colleague file share | Submitted 11:18no password kept |
| Omar K. | Tool access share | Replied 10:05 |
| Priya S. | Colleague budget review | No action |
Handed back with every lure and the sources behind it.
Following our Q4 remittance call, payments now go through our new supplier portal. Please log in before Friday.
A teammate shared the invoicing workspace with you. Reply to confirm access before the change freeze.
Can you look at the updated close budget before our 3pm review? Sending from my personal inbox, laptop's being fixed.
Your security team approves every step and can stop a run at any time.
Yes. Every run is scoped and approved with your security team first. You set targets, timing and tone, and can stop it at any time.
Simulation replays attacks Aegis caught in your tenant. The red team agent researches each person and writes a new lure, the way an attacker would.
No. The agent records that a submit happened on the lure page. Passwords and secrets are never collected.
It comes from public sources and is handed back to you in the report, with every lure.
Only the domain, teams, roles or named people you approve.
Scope a run with your security team and get per-person evidence back.
Connect a tenant, run in monitoring mode, and compare against what your current stack delivered.