What problem does it solve?
SOC teams often miss attackers who bypass perimeter defenses and move laterally inside the network, because threshold-based detection tools generate noise or fail to trigger. This Skill deploys deception technology — honeypots, honeytokens, and canary files — that produces high-fidelity alerts with near-zero false positives, since no legitimate user should ever touch a decoy asset.
Core Features & Use Cases
- Decoy Deployment Planning: Maps network segments (server VLANs, DMZ, OT, cloud VPCs) to appropriate decoy types such as fake file servers, database servers, and PLC/HMI decoys.
- Honeytoken Creation: Creates fake Active Directory service accounts, cached credentials, AWS canary keys, and tracked Word documents that alert on any use.
- SIEM/SOAR Integration: Wires deception alerts into Splunk notable events and automated SOAR responses including host isolation, firewall blocking, and P1 incident creation.
- Use Case: An attacker dumps credentials with Mimikatz and finds a planted honeytoken account; the moment they attempt to use it, a critical alert fires and the source workstation is automatically isolated.
Quick Start
Ask the AI to plan and deploy deception decoys and honeytokens across your network segments with SIEM alerting and automated isolation response.