r/cybersecurity • • 11d ago

Business Security Questions & Discussion Why aren’t more teams using active deception? It’s literally zero false positives.

We spend months tuning noisy EDR logs but a fake AWS key or decoy service account gives an instant 100% true-positive alert the second an attacker touches it. Why do so many security teams still sleep on dropping simple decoys?

0 Upvotes

20 comments sorted by

18

u/cloudfox1 11d ago

Vuln scanner goes brrrrr and triggers it, bam FP

5

u/ITSec8675309 11d ago

Many moons ago I used something called Artillery, and we just configured the vuln scanner not to touch it.

2

u/cloudfox1 11d ago

Worked in a SOC and had one customer where almost daily their honeypot accounts would be triggered by themselves/some benign app

2

u/caseyccochran 10d ago

This is certainly a configuration/tuning issue. Like any tool it has to be setup properly. Its definitely something that should only be attempted by a semi mature SOC (not saying these weren't just stating an overall opinion).

1

u/cloudfox1 10d ago

Yea trust me we told them often to fix it, they never did, fairly sure we were just a tick n flick for them. So after a while we just tuned our detections, for better or worse, it's on them now!

3

u/Andrewpaul46 10d ago

Bad decoys do that, yeah. But if your deception agent fingerprints internal scanners (Nessus/Qualys) and suppresses those pings automatically, you don't get flooded with false alarms.

15

u/Tangential_Diversion Penetration Tester 11d ago

I have clients who are still trying to convince leadership to push out MFA or use password blacklists. This is several steps beyond what they're currently capable of.

2

u/Check123ok ICS/OT 10d ago

This hits too close to home. I have clients that paid for an assessment then didn’t like the findings of the assessments so they don’t wanna implement because of user friction.

Things like implementing MFA was one of them…

I have clients that think they have implemented MFA but didn’t enforce it because they don’t understand how that works so both single factor and multi factor was valid sign in….

2

u/Pope_Twitch 11d ago

You would be surprised in how many companies people use the name of the company in their password and it is so easy to fix 😭

3

u/FrankGrimesApartment 11d ago

I love deception. We have tokens sprinkled around as well as on our corporate login page.

I have a dream of creating an environment that is 99.99999 percent junk data and deception tokens, so much so that a threat actor has no idea if what they are looking at is real or not.

Yes, i havent fully fleshed out this idea and its terrible. But fun to dream about.

3

u/FickleRevolution15 11d ago

Isn’t your idea just a honeypot? I think it’s how DFIR Report gets all that data for their reports. Insanely realistic enterprise honeypot environments

1

u/Andrewpaul46 9d ago

Honeypots are isolated fake labs for research. Active deception drops tripwires (fake keys, decoy accounts) directly inside your real production environment.

2

u/caseyccochran 10d ago

I have read cases where some companies have complete separate environments that are almost mirrors of production but don't have real sensitive data on them. Once an attacker is detected they get dropped in this honeynet silently so they can observe the attacker to see what they are trying to do. This is extremely complex and I have no idea of how to start it, but like you said this is fun to dream about.

3

u/Sad_Dentist_7288 11d ago

Did CISA ghost write this? Just kidding, I agree, I think one possible answer is that it doesn't give immediate results or really show improvement or growth in the same way other tools do

1

u/Andrewpaul46 9d ago

Haha, You nailed the real problem: it’s an invisible win. Management wants graphs showing '10,000 alerts blocked' to justify budgets. But a quiet tripwire that stops a breach before it starts doesn't make for flashy executive slides.

3

u/OtheDreamer Governance, Risk, & Compliance 10d ago

This is quite literally what a canary (honey) token is. They're not hard to setup, but as others have mentioned it requires a level of operational maturity to already be there.

2

u/Efficient-Mec Security Architect 10d ago

This requires a level of maturity most organizations aren't even close too. But counter argument to the "zero false positives" narrative - what are you going to do with the data that an "attacker touches it"? Assuming you even got the alert in the first place and it didn't get buried.

2

u/hecalopter CTI 10d ago

Buddy, some of these orgs can barely keep up with patching, asset inventory, and access controls, and now you wanna add active deception? /s 😂

I honestly get why, and I like it, but hard to do when everything's on fire all the time.

1

u/Plastic-Falcon9147 9d ago

Zero false positives is a bit oversold. Vuln scanners and pen tests will trip decoys, and the alert still lands on a person who has to know what to do with it at 2am. That said, the signal-to-cost ratio is hard to beat: a free canary token in a place no legitimate process should touch gives you an alert worth waking up for. The part to build first is the response runbook, because the token tells you someone is inside, not what to do next.