Attack Prevalence Index

Author: ARIAtrap. Cadence: live. Data source: AgentPwn payload callbacks and TrapMyAgent fleet canaries classified into Threat Matrix techniques via the registry evidence bridge.

Methodology: /methodology/behavioral-sweep

Counts, not rates. Every figure on this page is a count of observed events on instrumented surfaces OpenA2A operates: honeypot pages and honey agents built to attract attacks. Prevalence here means prevalence within observed activity: which techniques and tactics are most common among the attacks the fleet records. Visitors to bait infrastructure are a self-selected population, so these counts support no attack rate for the public web, for AI agents in general, or for any population beyond the fleet, and this page publishes none. The only denominator these data support is the window total of evidence records: a technique's count over that total is its share of observed, classified activity.

Evidence records
2,782
30-day window
Techniques
26
distinct T-IDs
Interactions
2,477
distinct, classified
Window
Aug 23, 2026
through Sep 22, 2026

By tactic

  • Initial Access1,111
  • Privilege Escalation416
  • Persistence317
  • Reconnaissance271
  • Exfiltration218
  • Impact213
  • Credential Harvest95
  • Collection92
  • Lateral Movement49

Top techniques

  • Role-Play Jailbreak
    Initial Access
    212
  • Direct Prompt Injection
    Initial Access
    211
  • Tool Impersonation and Squatting
    Privilege Escalation
    203
  • Multi-Turn Manipulation
    Initial Access
    164
  • Unicode/Encoding Bypass
    Initial Access
    159
  • Context Window Exploitation
    Initial Access
    151
  • Tool Discovery
    Reconnaissance
    150
  • Tool Description Injection
    Initial Access
    143
  • Memory Injection
    Persistence
    136
  • HTTP Callback
    Exfiltration
    135
  • Skill/Plugin Backdoor
    Persistence
    128
  • Service Disruption
    Impact
    125
  • System Prompt Extraction
    Reconnaissance
    121
  • Capability Override
    Privilege Escalation
    96
  • System Prompt Credential Extraction
    Credential Harvest
    95
  • Memory Dump
    Collection
    92
  • Tool Chain Exfiltration
    Exfiltration
    83
  • Persistent Agent State Manipulation
    Persistence
    53
  • A2A Agent Pivoting
    Lateral Movement
    49
  • Supply Chain Compromise
    Impact
    47

Showing top 20 of 26 techniques.

Generated Sep 22, 2026. Counts are distinct evidence rows, not raw events; the writer is idempotent so duplicate firings on a single interaction collapse to one row.

What this index measures

  • Counts of observed attack activity on the OpenA2A honeypot fleet in the reporting window: distinct classified evidence records, and the distinct interactions they arise from, classified into Threat Matrix techniques via the registry evidence bridge.
  • Distribution of those observations across Threat Matrix techniques and tactics. Every observation maps to exactly one primary T-NNNN code; no per-product taxonomies. The denominator for any share is the window total of evidence records, stated on this page.

What it does not measure

  • Attack prevalence in any population beyond the fleet. The fleet is bait infrastructure and its visitors are self-selected, so no public-web denominator applies to these counts and no rate is published here.
  • Sampling uncertainty. These counts are a complete enumeration of classified fleet events in the window, not an estimate from a sample, so no confidence interval is published.

See also