Honeypots & deception
Deception technology plants traps that no legitimate user should ever touch: any interaction is, almost by definition, a high-fidelity signal. A well-placed honeypot detects the attacker who already evaded everything else, with almost no false positives.
Concepts
Section titled “Concepts”Honeypot decoy system/service with no legitimate use -> touching it = malicious activityHoneytoken fake credential/file/URL "seeded" -> its use triggers an alertHoneynet an entire network of decoys to observe the attackerCanary a token/service that "sings" when accessed (early warning)Types by interaction
Section titled “Types by interaction”Low interaction emulates services (ports/banners); safe and easy, less informationHigh interaction real monitored systems; more realism and intelligence, more risk -> must be HEAVILY isolated: a compromised honeypot must lead nowhereHoneytokens (very high value, low cost)
Section titled “Honeytokens (very high value, low cost)”- fake credentials in managers/code/GPO -> if someone uses them, there's an intruder (see ad-creds)- a "trap" AD account with no use -> any login/kerberoast against it = alert (see ad-kerberos)- canary document/URL (e.g. canarytokens.org) -> warns when opened- fake API keys/records in repos -> detect code/secret theftDeployment
Section titled “Deployment”Tools T-Pot (honeypot suite), Cowrie (SSH/Telnet), Canarytokens, OpenCanaryPlacement in internal segments (detect lateral movement), not just the perimeterAlerting integrate with the SIEM (def-siem): a honeypot hit is a priority alertRealism credible names/locations so the attacker "bites"Blue Team / operation
Section titled “Blue Team / operation”- Place decoys where an attacker would look (shares, AD, repos, credential managers).
- Every interaction is high fidelity: prioritize and respond fast (almost no false positives).
- Firmly isolate high-interaction honeypots; they must not be a springboard or expose real data.
- Combine with detection (Detection & logging) and IR (dfir): deception warns, the process responds.
Real-world cases
Section titled “Real-world cases”- AD honeytokens (kerberoastable trap accounts) are a recommended practice to hunt ad-kerberos.
- Canarytokens widely used to detect opening of stolen documents and repo access.
- Teams detect ransomware/lateral movement early thanks to decoy shares and credentials.
Testing checklist
Section titled “Testing checklist”- Define what to detect (internal access, credential theft, lateral)
- Deploy honeytokens (credentials, trap AD account, canary docs)
- Honeypots in internal segments, not just the perimeter
- Strict isolation of high-interaction ones
- SIEM integration: hit = priority alert
- Realism (credible names/locations)
- Response runbook for a tripped decoy