No weighing required
A decoy has no operational use. Whoever uses it is looking for something that is not theirs. That spares the discussion every ordinary alert brings with it.
An alert with no harmless explanation
Most security alerts mainly cost time on one question: does this mean anything? Was it the administrator, a backup run, a new tool? Deception reverses that order: a decoy has no operational purpose. Nobody has a reason to sign in with stored credentials that belong to no real system. The module runs decoy hosts with emulated services, scatters breadcrumbs across real workstations, from RDP shortcuts through saved sessions to configuration files with credentials, and creates honeytoken accounts in the directory. Every connection attempt and every use raises an early warning that says which decoy, and from which machine.
A decoy has no operational use. Whoever uses it is looking for something that is not theirs. That spares the discussion every ordinary alert brings with it.
Every breadcrumb carries a unique marker. A warning therefore names the decoy and the machine it was placed on, that is, the workstation presumably taken over.
Your own vulnerability scanner and a commissioned penetration test will trigger too. Time-limited or permanent exceptions handle that. The hit stays visible nonetheless; it simply raises no alarm.
The services run as emulations on dedicated hosts, not as opened ports on production servers. A decoy holds no data that could be lost.
An alert that comes rarely and then means something: someone is moving through the network who does not know the way.
Schedule a no-obligation demo – we will show you the module with your own use cases.