Posts

Showing posts with the label Deception

Honeytokens Explained: Deception Detection for CySA+ and Security+

A honeytoken is a piece of fake data planted somewhere it has no legitimate reason to be used. Nobody should ever touch it. So the moment it is touched, you know something is wrong — and you know it with near-perfect confidence. A honeytoken has no false positives by design. Legitimate activity never triggers it, because legitimate activity has no reason to. That property is what makes honeytokens unusually valuable in a world of noisy detection. A SIEM correlation rule fires a hundred times a week and ninety-eight of those are nothing. A honeytoken alert is, almost by definition, real. What a Honeytoken Can Be Fake credentials. An account named something inviting — svc_backup_admin , sql_sa_old — that is never used by anything. Any authentication attempt is an intruder who found it during enumeration. Canary tokens in files. A document that phones home when opened, embedded in a share named "Executive Compensation" or "Passwords". Fake database reco...