.zip bundle of pre-baited files, all wired to the same key. Drop the extracted folder on a shared drive; any file inside that gets opened, double-clicked, or cat’d fires the mantis.
Note: this does not fire automatically when someone browses the folder in Finder/Explorer — that requires DNS infrastructure (a future stage). What it does give you is high-surface honeypot detection: a curious user spelunking the directory will open at least one of those files, and any of them triggers the alert.
Fake credentials in
passwords.txt / database-credentials.txt use AWS’s and Stripe’s documented example keys (AKIAIOSFODNN7EXAMPLE, sk_live_4eC39HqLyjWDarjtT1zdp7dc) — publicly known fakes, not real credentials anywhere.