Imagine an intruder with a perfectly good password. The login works. The door opens. The security system has just watched somebody authenticate correctly, which is rather different from watching somebody behave honestly. Attivo Networks built its business in that awkward gap. It asked what defenders could learn by putting attractive, useless things in an attacker’s path.
- Plant believable decoys and credential lures inside the network.
- Expose reconnaissance, credential misuse and movement between systems.
- Connect the evidence to investigation and response. SentinelOne bought the company in 2022.
The ingenuity lies in who needs the bait. An employee has little reason to use a planted credential or visit a decoy server. An intruder looking for the next useful account might find both fascinating. A network full of ordinary activity suddenly contains a few places where activity deserves special attention. The burglar supplies the evidence by trying the handle.
The password that tells on its owner
Attivo’s historical ThreatDefend platform combined decoys, endpoint lures, forensic analysis and response integrations. Rather than waiting for a known malware signature, it could expose an attacker exploring the environment. Its expertise was making the bait fit: a convincing destination, a plausible service, a credential that appeared to lead somewhere worth visiting.
SentinelOne describes how deceptive credentials can sit in browsers, keychains and Windows Credential Manager. Its account of identity-based attack defenses explains how network decoys supply realistic destinations for those lures and record the resulting activity. This creates material for an investigation, including interactions on the network and within the decoy itself.
That approach addresses lateral movement: the journey from one compromised machine toward something more valuable. Active Directory makes the problem especially consequential. It helps organize accounts and permissions, so learning its structure can help an attacker discover privileged identities. Attivo’s identity defenses aimed to protect that information and interrupt the climb toward greater access.
“Achieving 100 percent security is not realistic.”Tushar Kothari, Attivo CEO, 2017
First, persuade the people with budgets
The objection was practical. Forgepoint Capital recalls doubting the category in 2015 and 2016: could deception be deployed and managed at scale, and would it produce useful results? In its investment retrospective, the firm says its view changed in early 2017 when customers started committing budgets. A fascinating conference conversation had become a purchasing decision.
Attivo was founded in 2011; its founders included Mano Murthy, Marc Feghali and B.J. Shanker. CEO Tushar Kothari joined the story as the company’s commercial leader. Forgepoint’s later case study describes customer education, product refinement and a reference program. Those activities offer a modest, copyable lesson: help the next buyer speak to someone who has already done the difficult installation.

The financing followed. Bain Capital Ventures led an $8 million Series A in April 2015. Attivo raised $15 million in Series B funding in May 2017, followed by $21 million in October’s Series C. That latter round supported product development and international expansion. Making deception useful across a large organization required considerably more than leaving one imaginary server in a corner.
The machines that cannot take another agent
Industrial environments offered another reason to care. In the March 2019 announcement of Energy Impact Partners’ investment, Kothari pointed to operational technology that cannot readily run antivirus software or be patched. Attivo described decoys resembling industrial control and SCADA systems. Detection could therefore operate through an attacker’s interaction with a convincing substitute.
This was enterprise security software for organizations with complicated estates: user devices, data centers, cloud systems and specialized equipment. SentinelOne reported more than 300 global enterprise customers when it announced the acquisition. Fortune 500 organizations were among them. The paying audience was the security team responsible for finding intruders before those intruders reached consequential assets.
A $616.5 million place in the portfolio
Cash and stock. A transaction figure, not a software price.
SentinelOne announced the deal in March 2022 and announced completion in May. For an endpoint security company, identity protection covered an adjacent problem: an attacker using legitimate credentials can be dangerous without looking like a conventional malicious executable. Attivo gave the broader Singularity platform another way to observe and interrupt that behavior.
The acquisition-era portfolio assigned distinct jobs to three names. Singularity Identity defended credentials and identity infrastructure. Ranger Active Directory Assessor examined directory exposures. Hologram supplied network deception and investigative telemetry. General Ranger network discovery was a separate capability; the similar names should not tempt buyers into treating inventory and directory assessment as interchangeable.
The business was B2B commercial software, with channel partners and integrations extending its reach. Inside SentinelOne, the identity offering belongs to a subscription platform. Buyers should establish the licensed capabilities, coverage and deployment work for their own environment. The acquisition’s price tag tells them what SentinelOne agreed to pay for the company, not what their security project will cost.
The decoy still needs someone to answer
Attivo competed in a deception market that included Acalvio, Illusive and TrapX. Its practical distinction was the combination of believable bait, identity protection and response integration. A 2021 Swimlane alliance connected deception-derived forensics to security automation. Catching somebody touching a trap is only the beginning of a useful security outcome.
The operational lesson follows from the mechanism. An attacker who never encounters the bait will not trigger that bait. Implausible decoys offer fewer reasons to engage. An unattended alert cannot contain anything. Teams evaluating this approach should test lure placement, investigate the resulting evidence and assign response ownership. Deception complements prevention, patching and access controls; it needs those surrounding disciplines to earn its keep.
The product history also matters. SentinelOne’s May 2025 earnings presentation reported Hologram’s end of sale. Its February 2026 Identity datasheet still describes deception within unified identity and endpoint protection. Attivo’s legacy survives in that distinction: a product can stop being sold while its underlying idea remains useful. The thief still has to decide which password to trust.