Using Cyber Decoys to Strengthen Detection and Response
CISA released guidance on cyber decoys—tripwires, breadcrumbs, honeytokens—to help defenders detect adversaries using valid credentials and living-off-the-land techniques.
CISA published guidance to help defensive teams of varying maturity plan and implement cyber decoys—assets that mimic legitimate systems, accounts, or data, such as tripwires, breadcrumbs, and honeytokens—to detect adversaries using legitimate credentials and living-off-the-land techniques. The guidance frames decoys as complementing Zero Trust by producing high-fidelity alerts, reducing alert fatigue, and exposing post-compromise activity like discovery, lateral movement, and data access. It maps decoy operations to the MITRE Engage and MITRE ATT&CK frameworks with low-complexity implementation steps.
- Guidance covers decoy concepts: tripwires, breadcrumbs, and honeytokens
- Decoys complement Zero Trust with high-fidelity alerts and reduced alert fatigue
- Uses MITRE Engage and MITRE ATT&CK frameworks for low-complexity decoy planning
- Targets defenders facing adversaries using valid credentials and LOTL techniques
Full article283 words · extracted from cisa.gov · click to collapse
CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly.
Cyber decoys complement Zero Trust by:
- Supporting continuous monitoring and verification,
- Creating high-fidelity alerts for suspicious activity,
- Reducing alert fatigue, and
- Helping defenders detect post-compromise activity, including adversary LOTL techniques.
This guidance introduces decoy concepts—including tripwires, breadcrumbs, and honeytokens—and uses the MITRE Engage™ and MITRE ATT&CK® frameworks to provide practical, low-complexity steps for planning, implementing, and refining decoy operations. For additional information, visit CISA’s Best Practices for MITRE ATT&CK Mapping.
Note: CISA is committed to providing access to our web pages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within this document interferes with your ability to access the information, as defined in the Rehabilitation Act, please email [email protected]. To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material. CISA will update Using Cyber Decoys to Strengthen Detection and Response when the 508 compliance has been completed.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response