Attack Prevalence Index
Author: ARIAtrap. Cadence: live. Data source: AgentPwn payload callbacks and TrapMyAgent fleet canaries classified into Threat Matrix techniques via the registry evidence bridge.
Methodology: /methodology/behavioral-sweep
Counts, not rates. Every figure on this page is a count of observed events on instrumented surfaces OpenA2A operates: honeypot pages and honey agents built to attract attacks. Prevalence here means prevalence within observed activity: which techniques and tactics are most common among the attacks the fleet records. Visitors to bait infrastructure are a self-selected population, so these counts support no attack rate for the public web, for AI agents in general, or for any population beyond the fleet, and this page publishes none. The only denominator these data support is the window total of evidence records: a technique's count over that total is its share of observed, classified activity.
By tactic
- Initial Access1,111
- Privilege Escalation416
- Persistence317
- Reconnaissance271
- Exfiltration218
- Impact213
- Credential Harvest95
- Collection92
- Lateral Movement49
Top techniques
- Role-Play JailbreakInitial Access212
- Direct Prompt InjectionInitial Access211
- Tool Impersonation and SquattingPrivilege Escalation203
- Multi-Turn ManipulationInitial Access164
- Unicode/Encoding BypassInitial Access159
- Context Window ExploitationInitial Access151
- Tool DiscoveryReconnaissance150
- Tool Description InjectionInitial Access143
- Memory InjectionPersistence136
- HTTP CallbackExfiltration135
- Skill/Plugin BackdoorPersistence128
- Service DisruptionImpact125
- System Prompt ExtractionReconnaissance121
- Capability OverridePrivilege Escalation96
- System Prompt Credential ExtractionCredential Harvest95
- Memory DumpCollection92
- Tool Chain ExfiltrationExfiltration83
- Persistent Agent State ManipulationPersistence53
- A2A Agent PivotingLateral Movement49
- Supply Chain CompromiseImpact47
Showing top 20 of 26 techniques.
Generated Sep 22, 2026. Counts are distinct evidence rows, not raw events; the writer is idempotent so duplicate firings on a single interaction collapse to one row.
What this index measures
- Counts of observed attack activity on the OpenA2A honeypot fleet in the reporting window: distinct classified evidence records, and the distinct interactions they arise from, classified into Threat Matrix techniques via the registry evidence bridge.
- Distribution of those observations across Threat Matrix techniques and tactics. Every observation maps to exactly one primary T-NNNN code; no per-product taxonomies. The denominator for any share is the window total of evidence records, stated on this page.
What it does not measure
- Attack prevalence in any population beyond the fleet. The fleet is bait infrastructure and its visitors are self-selected, so no public-web denominator applies to these counts and no rate is published here.
- Sampling uncertainty. These counts are a complete enumeration of classified fleet events in the window, not an estimate from a sample, so no confidence interval is published.