CISA urges business to deploy decoys, lures, and honeypots to catch hackers in the act
The US cybersecurity agency CISA released recommendations for deploying cyber decoys—honeypots, lures, and honeytokens—to detect intrusions. The decoys complement the Zero Trust model by identifying attacker activity that uses legitimate credentials and living-off-the-land (LOTL) techniques.
- CISA released recommendations on cyber decoys for organizations of any size
- Decoys complement Zero Trust and provide high-fidelity intrusion alerts
- Document describes tripwires, honeytokens, and steps for MITRE ATT&CK/Engage
- Decoys are inexpensive and deploy without major architecture changes
Read next
Security