Layer 02 · Detect

Two allowed actions can still be an attack.

A static allowlist catches a bad tool. It misses a bad sequence (two individually permitted actions that together are theft) and a bad data flow. NOCTRYS watches history, provenance, and a per-agent behavioral baseline to catch what rules alone cannot.

exfiltrationprompt + indirect injectioninformation-flowbehavioral driftmemory poisoningtool rug-pull

The classic example

An agent is allowed to read the customer database. It is also allowed to send email. Neither is suspicious alone. But db.read customers immediately followed by email.send to an outside address is exfiltration, and a static allowlist waves it straight through. NOCTRYS sees the sequence and blocks it, while still allowing the same read followed by an internal notification.

The failure mode NOCTRYS was built for: every individual action is allowed, and the combination is theft. Detection over history, provenance, and per-agent baselines closes that gap deterministically, with an explainable reason on every verdict.

What it catches

SignalWhat it means
Exfiltration sequenceA sensitive read followed by an external send.
Prompt injectionHijacked instructions smuggled into tool arguments.
Indirect injectionMalicious instructions returned in a tool’s output, aimed at the model.
Information-flow controlUntrusted data (web, email, other agents) reaching a sensitive action, tracked by provenance.
Behavioral driftActions that break no rule but are abnormal for this specific agent, versus its learned baseline.
Memory poisoningUntrusted content being written into the agent’s long-term memory to steer it later.
Tool-drift / rug-pullAn MCP tool whose definition changed after it was approved.
Tool-shadowingA rogue server claiming a trusted tool’s name to intercept its calls.
Probing & velocityRepeated denied attempts (reconnaissance) and abnormal bursts of activity.

Detection you can trust in an audit

These are not opaque model scores. Each signal is a defined, explainable rule over observable history, so when NOCTRYS flags or blocks, it can say exactly why, and that reason goes into the tamper-evident record. Detection and enforcement share one deterministic, auditable pipeline.

Be one of our first five design partners

Free pilot. A two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.

Request a pilot →