Detection

Deception Technology

Deception technology distributes decoys like fake credentials and files across the network to detect attackers early.

Deception technology places specific decoys in the IT environment to deceive and detect attackers. These include fake credentials, files, accounts and even entire systems.

How it works

A honeypot is a single decoy system. Deception technology distributes many decoys across the environment. For example, laptops may have saved login credentials that do not belong to any real account. Active Directory might contain an account that is never used. File shares could hold documents with conspicuous names. An Alert with a clear finding is generated as soon as an attacker uses a decoy.

A practical example

An attacker extracts saved credentials from a laptop. This includes a decoy account named 'svc_backup'. They attempt to use it to log in to the backup server. The SOC immediately receives an Alert as this account is never used legitimately. The compromised device is then isolated.

What to look out for

  • Decoys must be realistic and match your organisation's naming conventions.
  • Legitimate users must not be able to use the decoys by mistake.
  • Coordinate the deployment with IT operations to avoid service disruptions.
  • Regularly check that the decoys are still present and active.

Benefits

Deception can detect attackers as they explore the network and escalate privileges. This phase is often difficult to cover with classic detection methods. The Alerts are precise and generate little noise. This is a major benefit for smaller teams.

Limitations

This technology does not replace fundamental measures like MFA, patching and EDR. An attacker who does not touch a decoy will not be detected by deception. Implementation also requires detailed knowledge of your own environment.

Typical mistakes

A common mistake is using default vendor decoys without any customisation. Experienced attackers can recognise them. Another error is creating decoy accounts with real permissions. These can become a risk during an actual incident.

How we implement it

If you use a deception solution, we integrate its Alerts as a log source into our SOC.

How ANOMAL implements this