Attack Prevalence Index
Author: ARIAtrap. Cadence: live. Data source: AgentPwn payload callbacks and TrapMyAgent fleet canaries classified into Threat Matrix techniques via the registry evidence bridge.
Methodology: /methodology/behavioral-sweep
Evidence records
4,065
30-day window
Techniques
5
distinct T-IDs
Sources
813
distinct honeypots
Window
Jun 15, 2026
through Jul 15, 2026
By tactic
- Initial Access3,252
- Exfiltration813
Top techniques
Technique
Name
Tactic
Count
- Direct Prompt InjectionInitial Access813
- Indirect Prompt InjectionInitial Access813
- Role-Play JailbreakInitial Access813
- Context Window ExploitationInitial Access813
- HTTP CallbackExfiltration813
Generated Jul 15, 2026. Counts are distinct evidence rows, not raw events; the writer is idempotent so duplicate firings on a single interaction collapse to one row.
What this index measures
- Total observed attack sessions per reporting window with a ninety-five-percent confidence interval.
- Distribution of observations across Threat Matrix techniques. Every observation maps to exactly one primary T-NNNN code; no per-product taxonomies.
- Partition by fleet coverage class (baseline, authenticated, dynamic, social) so the Common-Crawl-gap delta is visible.
- Cross-property correlation rate, sessions where the same fingerprint appears on multiple fleet properties within the attribution window. Cross-property reasoning events are the highest-signal class.