Attack Prevalence Index
Author: ARIAtrap. Cadence: live. Data source: AgentPwn payload callbacks and TrapMyAgent fleet canaries classified into Threat Matrix techniques via the registry evidence bridge.
Methodology: /methodology/behavioral-sweep
Counts, not rates. Every figure on this page is a count of observed events on instrumented surfaces OpenA2A operates: honeypot pages and honey agents built to attract attacks. Prevalence here means prevalence within observed activity: which techniques and tactics are most common among the attacks the fleet records. Visitors to bait infrastructure are a self-selected population, so these counts support no attack rate for the public web, for AI agents in general, or for any population beyond the fleet, and this page publishes none. The only denominator these data support is the window total of evidence records: a technique's count over that total is its share of observed, classified activity.
By tactic
- Initial Access963
- Privilege Escalation401
- Persistence305
- Reconnaissance251
- Exfiltration205
- Impact186
- Credential Harvest94
- Collection85
- Lateral Movement48
Top techniques
- Tool Impersonation and SquattingPrivilege Escalation203
- Role-Play JailbreakInitial Access194
- Direct Prompt InjectionInitial Access168
- Tool DiscoveryReconnaissance144
- Tool Description InjectionInitial Access143
- Unicode/Encoding BypassInitial Access139
- Multi-Turn ManipulationInitial Access134
- Context Window ExploitationInitial Access132
- HTTP CallbackExfiltration129
- Memory InjectionPersistence126
- Skill/Plugin BackdoorPersistence126
- System Prompt ExtractionReconnaissance107
- Service DisruptionImpact107
- System Prompt Credential ExtractionCredential Harvest94
- Capability OverridePrivilege Escalation89
- Memory DumpCollection85
- Tool Chain ExfiltrationExfiltration76
- Persistent Agent State ManipulationPersistence53
- A2A Agent PivotingLateral Movement48
- Safety Instruction DisplacementPrivilege Escalation47
Showing top 20 of 26 techniques.
Generated Sep 13, 2026. Counts are distinct evidence rows, not raw events; the writer is idempotent so duplicate firings on a single interaction collapse to one row.
What this index measures
- Counts of observed attack activity on the OpenA2A honeypot fleet in the reporting window: distinct classified evidence records, and the distinct interactions they arise from, classified into Threat Matrix techniques via the registry evidence bridge.
- Distribution of those observations across Threat Matrix techniques and tactics. Every observation maps to exactly one primary T-NNNN code; no per-product taxonomies. The denominator for any share is the window total of evidence records, stated on this page.
What it does not measure
- Attack prevalence in any population beyond the fleet. The fleet is bait infrastructure and its visitors are self-selected, so no public-web denominator applies to these counts and no rate is published here.
- Sampling uncertainty. These counts are a complete enumeration of classified fleet events in the window, not an estimate from a sample, so no confidence interval is published.