CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoysnew
CISA released guidance, "Using Cyber Decoys to Strengthen Detection and Response," helping resource-constrained teams deploy honeytokens and honeypots with existing tools.
CISA's guidance targets critical infrastructure organizations and smaller teams that struggle to detect adversaries using legitimate credentials, built-in utilities, and living-off-the-land techniques. It recommends honeytokens, honeypots, breadcrumbs, and tripwires deployed by repurposing existing EDR, IAM, and DLP tools plus open-source options rather than new purchases. Tactics are organized around MITRE Engage's Expose, Affect, and Elicit goals and include a worked water and wastewater scenario using MITRE ATT&CK mapping.