Recognizing Deception

Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with them, and handle a suspected decoy without burning the engagement. Use when a target is unexpectedly easy, when credentials or a service appear in an implausible place, when a privileged account has no logon history, when a file or bucket looks like bait, or when deciding whether to use credentials of unknown provenance.

trilwu 2e1ae4a 10.4 KB Updated

File contents

trilwu/secskills/tree/main/secskills-offense/skills/recognizing-deception commit 2e1ae4a43a

Frequently asked questions

npx skillmds add trilwu/recognizing-deception