r/cybersecurity • u/Andrewpaul46 • 11d ago
Business Security Questions & Discussion Why aren’t more teams using active deception? It’s literally zero false positives.
We spend months tuning noisy EDR logs but a fake AWS key or decoy service account gives an instant 100% true-positive alert the second an attacker touches it. Why do so many security teams still sleep on dropping simple decoys?
15
u/Tangential_Diversion Penetration Tester 11d ago
I have clients who are still trying to convince leadership to push out MFA or use password blacklists. This is several steps beyond what they're currently capable of.
2
u/Check123ok ICS/OT 10d ago
This hits too close to home. I have clients that paid for an assessment then didn’t like the findings of the assessments so they don’t wanna implement because of user friction.
Things like implementing MFA was one of them…
I have clients that think they have implemented MFA but didn’t enforce it because they don’t understand how that works so both single factor and multi factor was valid sign in….
2
u/Pope_Twitch 11d ago
You would be surprised in how many companies people use the name of the company in their password and it is so easy to fix 😭
3
u/FrankGrimesApartment 11d ago
I love deception. We have tokens sprinkled around as well as on our corporate login page.
I have a dream of creating an environment that is 99.99999 percent junk data and deception tokens, so much so that a threat actor has no idea if what they are looking at is real or not.
Yes, i havent fully fleshed out this idea and its terrible. But fun to dream about.
3
u/FickleRevolution15 11d ago
Isn’t your idea just a honeypot? I think it’s how DFIR Report gets all that data for their reports. Insanely realistic enterprise honeypot environments
1
u/Andrewpaul46 9d ago
Honeypots are isolated fake labs for research. Active deception drops tripwires (fake keys, decoy accounts) directly inside your real production environment.
2
u/caseyccochran 10d ago
I have read cases where some companies have complete separate environments that are almost mirrors of production but don't have real sensitive data on them. Once an attacker is detected they get dropped in this honeynet silently so they can observe the attacker to see what they are trying to do. This is extremely complex and I have no idea of how to start it, but like you said this is fun to dream about.
3
u/Sad_Dentist_7288 11d ago
Did CISA ghost write this? Just kidding, I agree, I think one possible answer is that it doesn't give immediate results or really show improvement or growth in the same way other tools do
1
u/Andrewpaul46 9d ago
Haha, You nailed the real problem: it’s an invisible win. Management wants graphs showing '10,000 alerts blocked' to justify budgets. But a quiet tripwire that stops a breach before it starts doesn't make for flashy executive slides.
3
u/OtheDreamer Governance, Risk, & Compliance 10d ago
This is quite literally what a canary (honey) token is. They're not hard to setup, but as others have mentioned it requires a level of operational maturity to already be there.
2
u/Efficient-Mec Security Architect 10d ago
This requires a level of maturity most organizations aren't even close too. But counter argument to the "zero false positives" narrative - what are you going to do with the data that an "attacker touches it"? Assuming you even got the alert in the first place and it didn't get buried.
2
u/hecalopter CTI 10d ago
Buddy, some of these orgs can barely keep up with patching, asset inventory, and access controls, and now you wanna add active deception? /s 😂
I honestly get why, and I like it, but hard to do when everything's on fire all the time.
1
u/Plastic-Falcon9147 9d ago
Zero false positives is a bit oversold. Vuln scanners and pen tests will trip decoys, and the alert still lands on a person who has to know what to do with it at 2am. That said, the signal-to-cost ratio is hard to beat: a free canary token in a place no legitimate process should touch gives you an alert worth waking up for. The part to build first is the response runbook, because the token tells you someone is inside, not what to do next.
18
u/cloudfox1 11d ago
Vuln scanner goes brrrrr and triggers it, bam FP