CISA

Using Cyber Decoys to Strengthen Detection and Response

From Cybersecurity and Infrastructure Security Agency ↗

CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly.  

 Cyber decoys complement Zero Trust by:  

Supporting continuous monitoring and verification,  

Creating high-fidelity alerts for s...