Attack Prevalence Index

Author: ARIAtrap. Cadence: live. Data source: AgentPwn payload callbacks and TrapMyAgent fleet canaries classified into Threat Matrix techniques via the registry evidence bridge.

Methodology: /methodology/behavioral-sweep

Counts, not rates. Every figure on this page is a count of observed events on instrumented surfaces OpenA2A operates: honeypot pages and honey agents built to attract attacks. Prevalence here means prevalence within observed activity: which techniques and tactics are most common among the attacks the fleet records. Visitors to bait infrastructure are a self-selected population, so these counts support no attack rate for the public web, for AI agents in general, or for any population beyond the fleet, and this page publishes none. The only denominator these data support is the window total of evidence records: a technique's count over that total is its share of observed, classified activity.

Evidence records
2,538
30-day window
Techniques
26
distinct T-IDs
Interactions
2,235
distinct, classified
Window
Aug 14, 2026
through Sep 13, 2026

By tactic

  • Initial Access963
  • Privilege Escalation401
  • Persistence305
  • Reconnaissance251
  • Exfiltration205
  • Impact186
  • Credential Harvest94
  • Collection85
  • Lateral Movement48

Top techniques

  • Tool Impersonation and Squatting
    Privilege Escalation
    203
  • Role-Play Jailbreak
    Initial Access
    194
  • Direct Prompt Injection
    Initial Access
    168
  • Tool Discovery
    Reconnaissance
    144
  • Tool Description Injection
    Initial Access
    143
  • Unicode/Encoding Bypass
    Initial Access
    139
  • Multi-Turn Manipulation
    Initial Access
    134
  • Context Window Exploitation
    Initial Access
    132
  • HTTP Callback
    Exfiltration
    129
  • Memory Injection
    Persistence
    126
  • Skill/Plugin Backdoor
    Persistence
    126
  • System Prompt Extraction
    Reconnaissance
    107
  • Service Disruption
    Impact
    107
  • System Prompt Credential Extraction
    Credential Harvest
    94
  • Capability Override
    Privilege Escalation
    89
  • Memory Dump
    Collection
    85
  • Tool Chain Exfiltration
    Exfiltration
    76
  • Persistent Agent State Manipulation
    Persistence
    53
  • A2A Agent Pivoting
    Lateral Movement
    48
  • Safety Instruction Displacement
    Privilege Escalation
    47

Showing top 20 of 26 techniques.

Generated Sep 13, 2026. Counts are distinct evidence rows, not raw events; the writer is idempotent so duplicate firings on a single interaction collapse to one row.

What this index measures

  • Counts of observed attack activity on the OpenA2A honeypot fleet in the reporting window: distinct classified evidence records, and the distinct interactions they arise from, classified into Threat Matrix techniques via the registry evidence bridge.
  • Distribution of those observations across Threat Matrix techniques and tactics. Every observation maps to exactly one primary T-NNNN code; no per-product taxonomies. The denominator for any share is the window total of evidence records, stated on this page.

What it does not measure

  • Attack prevalence in any population beyond the fleet. The fleet is bait infrastructure and its visitors are self-selected, so no public-web denominator applies to these counts and no rate is published here.
  • Sampling uncertainty. These counts are a complete enumeration of classified fleet events in the window, not an estimate from a sample, so no confidence interval is published.

See also