Skip to content

Use cases / Human-layer honeypots

Let the attack
come to us.

Place synthetic identities where social-engineering attacks begin, creating controlled opportunities to study unsolicited contact and adversary behavior.

Built forSecurity teamsThreat intelligenceSecurity engineeringFraud teamsCISOsRisk leaders

01 / Phishing

Look beyond the message.

Traditional controls inspect the email. A synthetic persona can create an opportunity to observe what the attacker does next—without placing a real employee in the conversation.

Account verificationCredential solicitationMalicious linksInvoice fraudExecutive impersonationFake support

Possible intelligence

SenderDomainLinkClaimed identityRequested actionConversation behavior

02 / Vishing

Hear the pretext evolve.

A controlled voice interaction could expose more than caller ID: the claim, request, language, and behavioral changes that emerge when a story is challenged.

stickysweet is building toward safe, governed voice engagement. This scenario illustrates the intelligence model—not a claim of autonomous production call answering.

Extracted intelligence

Phone numberClaimed identityRequested actionLanguagePretextBehavioral patternPossible campaign
VOICE CONCEPTILLUSTRATIVE
INBOUND / UNKNOWN+1 (312) 555-0184
Illustrative

ClaimCaller claims to be IT Support.

RequestRequests approval of an MFA prompt.

BehaviorChanges story after being challenged.

ArtifactProvides a callback number.

03 / Smishing

Follow the thread.

A synthetic mobile identity is designed to help teams study malicious links, fake invoices, account alerts, delivery scams, credential requests, and follow-up behavior. The exchange shown is illustrative, not an automated SMS claim.

Malicious linksFake invoicesAccount alertsDelivery scamsCredential requestsFollow-up behavior
9:415G
NS
Northstar AlertsUnknown sender

Northstar: Your payroll account has been restricted. Confirm your details: nstar-secure.co/r/82a

Illustrative response: Which account is affected?

Your employee deposit profile. Complete verification within 30 minutes to avoid suspension.

Message

04 / Social engineering

Identity context changes the signal.

A message is only part of the story. The persona's role, relationships, public footprint, and channel history help explain why that particular synthetic person was targeted.

DIRECT MESSAGELINKEDIN / 11:22
DR
Daniel RossSenior Recruiter · Meridian Search
Hi Michael—your infrastructure background stood out. I'm supporting a confidential cloud migration role. Could you review the technical brief and sign in with your work account?
Technical briefmeridian-careers.co
Illustrative scenario · Target fit: IT administrator / cloud access

05 / Executive & finance targeting

Attackers choose people, not inboxes.

Attackers select people based on role, authority, access, and organizational relationships. stickysweet builds coherent synthetic identities around the roles they seek.

SC

Sarah Chen

Finance Manager

WHY TARGETEDFinancial access
InvoicesVendor paymentsBanking workflows
EP

Emily Parker

Executive Assistant

WHY TARGETEDOrganizational relationships
Executive calendarTrusted contactsApproval pathways
MT

Michael Torres

IT Administrator

WHY TARGETEDSystem access
Cloud systemsAuthenticationHelpdesk workflows

06 / Agentic threats

When the attacker isn't human.

Autonomous systems can increasingly discover identities, enumerate contact channels, initiate outreach, probe workflows, manipulate authentication, perform social engineering, and interact with defensive agents.

stickysweet is deception infrastructure designed for an environment where the entity approaching a synthetic employee might itself be an AI agent.

This is the threat model and product direction—not a claim that every capability shown is available today.

UNKNOWN ENTITYAutonomous agentBehavior under observation
01Discover identity
02Enumerate channels
03Initiate outreach
04Probe workflows
05Manipulate authentication
06Social engineer
07Meet defensive agents

Campaign intelligence

These are not three independent alerts.

Three alerts can be one adversary. The stickysweet intelligence model brings interactions together around the people approached, shared infrastructure, actors, and campaigns.

SC

Sarah Chen

Finance Manager

VoiceClaimed IT supportMFA request
MT

Michael Torres

IT Administrator

SMSAccount verificationLink sent
EP

Emily Parker

Executive Assistant

EmailSecurity alertCredential reset request
Actor 81AC · Active campaign

Microsoft Helpdesk Impersonation

High confidence
7Targeted personas
19Interactions
Voice · SMS · EmailChannels
Aug 11First observed

Fictional test data · Conceptual intelligence model, not automatic correlation

From interaction to intelligence

Every conversation
reveals something.

01Contact
02Intent
03Tactic
04Infrastructure
05Actor
06Campaign