Performing Deception Technology Deployment
Overview
Cybersecurity skill for performing deception technology deployment. Follows industry best practices and security standards.
When to Use
Trigger phrases:
- "performing deception technology deployment"
- "SOC teams need high-fidelity detection of post-compromise lateral movement with"
- "Existing detection tools miss advanced attackers who avoid triggering threshold-"
- "The organization wants to detect credential abuse by planting fake credentials a"
Use this skill when:
- SOC teams need high-fidelity detection of post-compromise lateral movement with near-zero false positives
- Existing detection tools miss advanced attackers who avoid triggering threshold-based alerts
- The organization wants to detect credential abuse by planting fake credentials as honeytokens
- Network segmentation gaps need compensating detection controls
Do not use as a replacement for fundamental security controls (patching, EDR, network segmentation) — deception is a detection layer, not a prevention mechanism.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Network segments identified for honeypot/decoy deployment (server VLANs, DMZ, OT networks)
- Deception platform (Thinkst Canary, Attivo/SentinelOne Hologram, or open-source alternatives)
- SIEM integration for deception alerts (any interaction with deception assets is suspicious)
- Active Directory access for honeytoken account and credential creation
- Network team coordination for IP allocation and traffic routing
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Plan Operations — Define objectives, scope, and success criteria for deception technology deployment operations.
- Prepare Environment — Set up tools, access, and data sources required for deception technology deployment.
- Execute Core Workflow — Perform the deception technology deployment operations following established procedures.
- Validate Results — Verify that results meet quality standards and objectives.
- Report Findings — Document results, observations, and recommendations.
- Follow Up — Track remediation actions and verify fixes where applicable.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Design — Define interface, identify patterns, plan implementation
- Implement — Write code following existing conventions, add tests
- Verify — Run tests, check integration, validate behavior
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: performing-deception-technology-deployment3description: Use when deploys deception technology including honeypots, honeytokens, and decoy systems to detect attackers who have bypassed perimeter defenses, providing high-fidelity alerts with near-zero false positive rates. Use when SOC teams need early warning of lateral movement, credential abuse, or internal reconnaissance by deploying convincing traps across the network.4license: Apache-2.05---67# Performing Deception Technology Deployment89## Overview1011Cybersecurity skill for performing deception technology deployment. Follows industry best practices and security standards.1213## When to Use1415**Trigger phrases:**16- "performing deception technology deployment"17- "SOC teams need high-fidelity detection of post-compromise lateral movement with"18- "Existing detection tools miss advanced attackers who avoid triggering threshold-"19- "The organization wants to detect credential abuse by planting fake credentials a"202122Use this skill when:23- SOC teams need high-fidelity detection of post-compromise lateral movement with near-zero false positives24- Existing detection tools miss advanced attackers who avoid triggering threshold-based alerts25- The organization wants to detect credential abuse by planting fake credentials as honeytokens26- Network segmentation gaps need compensating detection controls2728**Do not use** as a replacement for fundamental security controls (patching, EDR, network segmentation) — deception is a detection layer, not a prevention mechanism.293031## When NOT to Use3233- When you lack proper authorization for testing34- For production systems without change management35- When the task requires legal or compliance expertise beyond technical scope363738## Prerequisites3940- Network segments identified for honeypot/decoy deployment (server VLANs, DMZ, OT networks)41- Deception platform (Thinkst Canary, Attivo/SentinelOne Hologram, or open-source alternatives)42- SIEM integration for deception alerts (any interaction with deception assets is suspicious)43- Active Directory access for honeytoken account and credential creation44- Network team coordination for IP allocation and traffic routing4546## Workflow4748```python49# Example: IOC detection50import re5152IOC_PATTERNS = {53 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",54 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",55 "hash_md5": r"\b[a-f0-9]{32}\b",56 "hash_sha256": r"\b[a-f0-9]{64}\b",57}5859def extract_iocs(text: str) -> dict:60 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}61```62631. **Plan Operations** — Define objectives, scope, and success criteria for deception technology deployment operations.642. **Prepare Environment** — Set up tools, access, and data sources required for deception technology deployment.653. **Execute Core Workflow** — Perform the deception technology deployment operations following established procedures.664. **Validate Results** — Verify that results meet quality standards and objectives.675. **Report Findings** — Document results, observations, and recommendations.686. **Follow Up** — Track remediation actions and verify fixes where applicable.6970## Tools7172- **Analysis Platform** — Data processing and visualization73- **Collaboration Tools** — Team coordination and knowledge sharing747576## Process77781. **Design** — Define interface, identify patterns, plan implementation791. **Implement** — Write code following existing conventions, add tests801. **Verify** — Run tests, check integration, validate behavior8182## Verification8384- [ ] All deception technology deployment procedures executed completely and documented85- [ ] Findings validated against multiple data sources86- [ ] False positives identified and filtered87- [ ] Results documented with evidence and timestamps88- [ ] Recommendations provided with risk-based prioritization8990## Anti-Rationalization Table9192| Rationalization | Reality |93|---|---|94| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |95| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |96| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |