Skip to content

Honeypots & deception

Deception technology plants traps that no legitimate user should ever touch: any interaction is, almost by definition, a high-fidelity signal. A well-placed honeypot detects the attacker who already evaded everything else, with almost no false positives.

Honeypot decoy system/service with no legitimate use -> touching it = malicious activity
Honeytoken fake credential/file/URL "seeded" -> its use triggers an alert
Honeynet an entire network of decoys to observe the attacker
Canary a token/service that "sings" when accessed (early warning)
Low interaction emulates services (ports/banners); safe and easy, less information
High interaction real monitored systems; more realism and intelligence, more risk
-> must be HEAVILY isolated: a compromised honeypot must lead nowhere
- fake credentials in managers/code/GPO -> if someone uses them, there's an intruder (see ad-creds)
- a "trap" AD account with no use -> any login/kerberoast against it = alert (see ad-kerberos)
- canary document/URL (e.g. canarytokens.org) -> warns when opened
- fake API keys/records in repos -> detect code/secret theft
Tools T-Pot (honeypot suite), Cowrie (SSH/Telnet), Canarytokens, OpenCanary
Placement in internal segments (detect lateral movement), not just the perimeter
Alerting integrate with the SIEM (def-siem): a honeypot hit is a priority alert
Realism credible names/locations so the attacker "bites"
  • Place decoys where an attacker would look (shares, AD, repos, credential managers).
  • Every interaction is high fidelity: prioritize and respond fast (almost no false positives).
  • Firmly isolate high-interaction honeypots; they must not be a springboard or expose real data.
  • Combine with detection (Detection & logging) and IR (dfir): deception warns, the process responds.
  • AD honeytokens (kerberoastable trap accounts) are a recommended practice to hunt ad-kerberos.
  • Canarytokens widely used to detect opening of stolen documents and repo access.
  • Teams detect ransomware/lateral movement early thanks to decoy shares and credentials.
  • Define what to detect (internal access, credential theft, lateral)
  • Deploy honeytokens (credentials, trap AD account, canary docs)
  • Honeypots in internal segments, not just the perimeter
  • Strict isolation of high-interaction ones
  • SIEM integration: hit = priority alert
  • Realism (credible names/locations)
  • Response runbook for a tripped decoy