Contact
All solution areasSolutions

Deception

What this is

Deception is the practice of placing systems, services and accounts in the network that exist only to be touched. They carry no work, no user has a reason to open them, and to anything scanning the network they are indistinguishable from the systems that do carry work.

Why it matters

Every other detection source produces a probability. An endpoint agent decides whether a process looks malicious. A network sensor decides whether traffic looks unusual. A SIEM correlates both and produces something an analyst still has to judge.

A decoy produces a different kind of event. It has no legitimate users, no service depending on it and no reason to be reached, so an interaction with one is not evidence of an intrusion. It is the intrusion. That is what makes it useful to a team that is already behind on its alert queue. It is one source that costs nothing to triage.

It is also one of the few detection methods that works where an agent cannot be installed, which is the ordinary condition of an OT or production network.

What it solves

  • Lateral movement that looks unremarkable on every individual host it touches
  • Alert queues where a true positive is indistinguishable from the volume around it
  • Ransomware seen at the reconnaissance step rather than at the encryption step
  • Segments where no agent can be deployed and no traffic can be mirrored

In our portfolio

GuardPotDecoy systems, services and accounts, with the attacker's behaviour recorded from the first interaction.

Next to this

Identity security is where a decoy earns most of its keep. A decoy account is one of the few ways to see an attacker who has already reached the directory.

Read more on this

An alert with nothing left to judgeEvery other detection source produces a probability an analyst has to assess. What a source costs to triage matters as much as what it finds.
Talk to us