If you’ve spent any time with deception, you know creating a hyper realistic decoy and deception environment requires some thought. Luring sophisticated cyber adversaries begins with defining your core threat intelligence goals. Only then can you engineer a digital twin capable of deceiving them. To maintain credibility under close inspection, every layer of the deception environment must hold together. So you need a realistic org chart, believable personas, a coherent network topology, department structures, and enough contextual depth throughout to fool an adversary who is actively trying to figure out whether what they’re poking at is real.
And you have to build that before you can run a campaign.
Now….by the time you read this, we’ve built an entire fake organization: org chart, company name, logo, domain, email patterns, department structures, personas. Designed to look irresistible to a specific APT group. Under a minute.
That’s AI-powered organization profiling, the headliner in Platform 4.5, the version of The Platform that has just been released. It’s the first of four AI features we’re releasing through 2026, each building on the last. The underlying principle is simple enough to put on a wall: know yourself, and know your adversary. Both halves require intelligence. This is where it starts.
How it works
Now, you can create organizations in under a minute. An Organization, in our platform, is the simulated entity your deception campaign is built around. Think of it as the fake company (or department, or government agency) you’re presenting to an adversary as a target. The more believable that organization, the longer an adversary stays engaged, and the more intelligence you extract.
You describe what you want. Select a threat actor. The AI generates the rest: hierarchies, department structures, employee personas, network topology, name, logo, domain, email patterns, brand identity. A complete organizational context for your campaigns, ready in minutes.
Building for the adversary, not just the defender
When you select a threat actor during setup, the AI doesn’t produce a generic financial services org. It produces one shaped around that group’s known targeting patterns: the departments they typically pursue, the kinds of infrastructure they look for, what makes a target look worth their time.
The goal of deception has always been to build environments adversaries can’t resist. This is AI doing that work at a level of specificity that wasn’t practical before.
Organization profiling handles both sides of the equation: defenders define the organization they’re protecting or simulating, and the AI shapes it to be irresistible to a specific adversary’s targeting logic. Know yourself. Know your adversary.
This is step one of four
The organization profiling in 4.5 lays the foundation. In 4.6, coming at the end of July, we’re shipping AI-powered campaign designer agent: a conversational designer built into the attack tree that creates campaigns from your goals and builds the full attack tree for you. Completely focused on extracting the threat intelligence you set on your goals. In Q4, persona simulation goes live, meaning the personas generated during organization profiling will start actively interacting within your campaigns. By the end of the year, the intelligence hunter ties it all together, reading adversary activity and generating reports automatically.
Each pillar builds on the last. Organizations without campaigns are context. Campaigns without personas are static. Personas without intelligence analysis are just activity. The full picture is an AI that builds, runs, and learns from your deception operations end to end.
Also in 4.5
Alongside organization profiling, 4.5 ships several improvements customers asked for and some infrastructure upgrades that matter for production deployments:
- Rocky Linux 8, 9, and 10 support within the Deception Agent, closing gaps for organizations transitioning to modern Linux environments
- Microsoft Server 2025 compatibility for deploying and managing campaigns on the latest Windows Server release
- The Platform SDK, an official Python SDK with full typing and Pydantic models for the CounterCraft Tenant API
- Native RHEL EUS and SAP kernel support, meaning all RHEL Extended Update Support kernels are now discovered, supported, and maintained the same way as standard kernels
- Password security and compliance updates, including automated rotation, credential recycling prevention, and tighter account lockout thresholds
- Secure malware sample export, letting analysts download detected malicious binaries in password-protected encrypted ZIP format directly from the management console
What’s coming next
Platform 4.6 campaign design is heading into beta in June, and we’ll be reaching out to beta testers soon. If you want to be among the first to try a conversational AI designer that builds your attack tree from a plain-language description of your goals, keep an eye out for that.
Organization profiling is available now with Platform 4.5. Go build something an adversary can’t resist.
