Rouxii: Exploiting Honeypots with Deception-Aware AI Pentesters
Rouxii finds deception-aware LLM pentesters identify honeypots far more often and can abuse them.
Researchers introduce Rouxii, an autonomous penetration-testing framework that recognizes honeypot fingerprints and pivots from detection to exploitation. Across three reasoning models, eleven network setups, and 1,544 attack reports, a counter-deception prompt raised correct honeypot identification from 19% to 97%, and from 11% to 97% on OT services, with a 0.7% false-alarm rate on real services. Deception-unaware PentestGPT and HackingBuddy baselines failed similarly. White-box analysis found a detected Conpot could be disabled by denial of service without tripping liveness monitoring, and a GasPot's reported intelligence could be corrupted.