Attack Prevalence Index

Author: ARIAtrap. Cadence: live. Data source: AgentPwn payload callbacks and TrapMyAgent fleet canaries classified into Threat Matrix techniques via the registry evidence bridge.

Methodology: /methodology/behavioral-sweep

Evidence records
4,065
30-day window
Techniques
5
distinct T-IDs
Sources
813
distinct honeypots
Window
Jun 15, 2026
through Jul 15, 2026

By tactic

  • Initial Access3,252
  • Exfiltration813

Top techniques

  • Direct Prompt Injection
    Initial Access
    813
  • Indirect Prompt Injection
    Initial Access
    813
  • Role-Play Jailbreak
    Initial Access
    813
  • Context Window Exploitation
    Initial Access
    813
  • HTTP Callback
    Exfiltration
    813

Generated Jul 15, 2026. Counts are distinct evidence rows, not raw events; the writer is idempotent so duplicate firings on a single interaction collapse to one row.

What this index measures

  • Total observed attack sessions per reporting window with a ninety-five-percent confidence interval.
  • Distribution of observations across Threat Matrix techniques. Every observation maps to exactly one primary T-NNNN code; no per-product taxonomies.
  • Partition by fleet coverage class (baseline, authenticated, dynamic, social) so the Common-Crawl-gap delta is visible.
  • Cross-property correlation rate, sessions where the same fingerprint appears on multiple fleet properties within the attribution window. Cross-property reasoning events are the highest-signal class.

See also