
CISA Releases Guidance on Using Cyber Decoys to Strengthen Detection and Response
CISAcritical infrastructuredeceptionguidehoneypotsSMBscybersecuritydetectionresponse
CISA released new guidance titled 'Using Cyber Decoys to Strengthen Detection and Response' aimed at critical infrastructure organizations and smaller security teams. The guidance addresses the problem that many organizations cannot detect adversaries who use legitimate credentials, built-in administrative utilities, and living-off-the-land (LOTL) techniques. CISA is attempting to expand the use of cyber deception and honeypots beyond well-resourced security teams to a broader range of organizations.