Security Operations

Deception – Early Warning

An alert with no harmless explanation

Most security alerts mainly cost time on one question: does this mean anything? Was it the administrator, a backup run, a new tool? Deception reverses that order: a decoy has no operational purpose. Nobody has a reason to sign in with stored credentials that belong to no real system. The module runs decoy hosts with emulated services, scatters breadcrumbs across real workstations, from RDP shortcuts through saved sessions to configuration files with credentials, and creates honeytoken accounts in the directory. Every connection attempt and every use raises an early warning that says which decoy, and from which machine.

ISO 27001NIS2
Features

Your benefits

1

No weighing required

A decoy has no operational use. Whoever uses it is looking for something that is not theirs. That spares the discussion every ordinary alert brings with it.

2

Not just that, but from where

Every breadcrumb carries a unique marker. A warning therefore names the decoy and the machine it was placed on, that is, the workstation presumably taken over.

3

Expected triggers are marked, not discarded

Your own vulnerability scanner and a commissioned penetration test will trigger too. Time-limited or permanent exceptions handle that. The hit stays visible nonetheless; it simply raises no alarm.

4

Decoys instead of production systems

The services run as emulations on dedicated hosts, not as opened ports on production servers. A decoy holds no data that could be lost.

Capabilities

All capabilities at a glance

  • Decoy hosts with emulated services (RDP, SSH, SMB, HTTP)
  • Breadcrumb catalog: RDP shortcut, PuTTY and WinSCP session
  • Windows credentials and mapped-drive shortcuts as breadcrumbs
  • Configuration files with decoy credentials
  • Honeytoken accounts in Active Directory with a dedicated watch
  • Deployment via the agent, as PowerShell or registry package
  • Unique marker per breadcrumb to map it to its host
  • Early warning with triage workflow and processing status
  • Exceptions for scanners and penetration tests, time-limited or permanent
  • Repeated hits aggregated instead of an alert flood
  • Forwarding to the SIEM where available
  • File decoys on shares and in user profiles that report the moment they are touched
  • Alert with actor and process via the Windows security log (event 4663)
  • Office decoys additionally report on opening, backdated and without a hidden attribute
  • Covers DET.4.10 “host-based decoys” of the BSI IT-Grundschutz successor
Result

An alert that comes rarely and then means something: someone is moving through the network who does not know the way.

Experience Deception – Early Warning live

Schedule a no-obligation demo – we will show you the module with your own use cases.