CISA Releases Guidance on Cyber Decoy Strategies

Best practices for detecting and distracting adversaries, as well as collecting threat intelligence.

Insider Threat Leo Wolfert
istock.com/LeoWolfert

Earlier this week the Cybersecurity and Infrastructure Security Agency (CISA) released the Using Cyber Decoys to Strengthen Detection and Response guidance. It helps defensive teams across critical infrastructure organizations incorporate decoy capabilities into broader cyber defense planning to detect and disrupt malicious activity early in the intrusion lifecycle.

Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). 

For robust cyber defense planning, organizations should incorporate cyber decoys within a Zero Trust model that assumes no user, device, application, or network segment is inherently trustworthy and requires continuous verification. Because cyber decoy capabilities operate under the expectation that an adversary may gain some level of access to the environment, they can help defenders detect post-compromise behavior earlier, collect CTI, and reduce time to detection.

This guidance introduces cyber decoy concepts and explains how organizations can use the MITRE Engage™ framework and MITRE ATT&CK® knowledge base to plan decoy operations around adversary tactics, techniques, and procedures (TTPs), organizational risk, and existing security controls, regardless of their cybersecurity maturity level.

Organizations can use the guidance to:

  • Understand how cyber decoys complement Zero Trust principles.
  • Start with lower-complexity techniques, such as tripwires and honeytokens.
  • Design decoys based on cyber threat information and likely adversary behavior.
  • Integrate decoy alerts with existing monitoring and incident response processes.
  • Test and refine decoy operations through threat emulation, red teaming, or purple teaming.

Read the full guidance to learn more. For additional information, visit CISA’s Best Practices for MITRE ATT&CK Mapping.

More in Cybersecurity