Two allowed actions can still be an attack.
A static allowlist catches a bad tool. It misses a bad sequence (two individually permitted actions that together are theft) and a bad data flow. NOCTRYS watches history, provenance, and a per-agent behavioral baseline to catch what rules alone cannot.
The classic example
An agent is allowed to read the customer database. It is also allowed to send email. Neither is suspicious alone. But db.read customers immediately followed by email.send to an outside address is exfiltration, and a static allowlist waves it straight through. NOCTRYS sees the sequence and blocks it, while still allowing the same read followed by an internal notification.
The failure mode NOCTRYS was built for: every individual action is allowed, and the combination is theft. Detection over history, provenance, and per-agent baselines closes that gap deterministically, with an explainable reason on every verdict.
What it catches
| Signal | What it means |
|---|---|
| Exfiltration sequence | A sensitive read followed by an external send. |
| Prompt injection | Hijacked instructions smuggled into tool arguments. |
| Indirect injection | Malicious instructions returned in a tool’s output, aimed at the model. |
| Information-flow control | Untrusted data (web, email, other agents) reaching a sensitive action, tracked by provenance. |
| Behavioral drift | Actions that break no rule but are abnormal for this specific agent, versus its learned baseline. |
| Memory poisoning | Untrusted content being written into the agent’s long-term memory to steer it later. |
| Tool-drift / rug-pull | An MCP tool whose definition changed after it was approved. |
| Tool-shadowing | A rogue server claiming a trusted tool’s name to intercept its calls. |
| Probing & velocity | Repeated denied attempts (reconnaissance) and abnormal bursts of activity. |
Detection you can trust in an audit
These are not opaque model scores. Each signal is a defined, explainable rule over observable history, so when NOCTRYS flags or blocks, it can say exactly why, and that reason goes into the tamper-evident record. Detection and enforcement share one deterministic, auditable pipeline.
Be one of our first five design partners
Free pilot. A two-week, self-hosted integration. You keep the tamper-evident audit and the AI Act compliance report.
Request a pilot →