CISA Urges Organizations to Deploy Cyber Decoys to Detect Hackers Inside Networksnew
CISA's new guidance urges organizations to deploy cyber decoys like honeytokens and tripwires to detect attackers using valid credentials and living-off-the-land techniques.
CISA published 'Using Cyber Decoys to Strengthen Detection and Response' on September 16, 2026, advising decoy assets that appear legitimate but generate high-confidence alerts when accessed. It describes tripwires, breadcrumbs, and honeytokens such as fake usernames, passwords, API keys, and cloud access tokens, and recommends starting with low-complexity deployments like nonfunctional Active Directory accounts, decoy file shares, and isolated mimic hosts. The agency warns decoys must be segmented and nonfunctional to prevent attackers pivoting to real systems, and aligns decoy planning with MITRE Engage and ATT&CK.