Using Cyber Decoys to Strengthen Detection and Response
Official websites use .gov A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS A lock ( ) or https:// means you’ve safely connected to the .gov website. sensitive information only on official, secure websites.
CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly.
Cyber decoys complement Zero Trust by:
Supporting continuous monitoring and verification,
Creating high-fidelity alerts for suspicious activity,
Reducing alert fatigue, and
Helping defenders detect post-compromise activity, including adversary LOTL techniques.
This guidance introduces decoy concepts—including tripwires, breadcrumbs, and honeytokens—and uses the MITRE Engage™ and MITRE ATT&CK® frameworks to provide practical, low-complexity steps for planning, implementing, and refining decoy operations. For additional information, visit CISA’s Best Practices for MITRE ATT&CK Mapping .
Note: CISA is committed to providing access to our web pages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within this document interferes with your ability to access the information, as defined in the Rehabilitation Act, please email @cisa.dhs.gov . To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material. CISA will update Using Cyber Decoys to Strengthen Detection and Response when the 508 compliance has been completed.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
