Detect attackers
before they succeed
Directory Decoy places fake misconfigurations across your Active Directory environment. They look like the vulnerable assets attackers hunt for, but instead of granting an attacker access to your infrastructure, they get shut out and you get an instant alert.
12+
Attack techniques
~1s
Alerts
0
False positives
Why It Works
Detection without the tuning
Conventional tools try to separate attacks from normal activity, which is why they need constant tuning and still produce noise. A decoy has no normal activity to separate out. Anyone who interacts with one has already given themselves away.
Modeled on real attacks
Each decoy is built to match what attackers actually go looking for, and configured to match your environment. To anyone scanning your directory, it is indistinguishable from a genuine target.
Placed where attackers look first
Attackers follow predictable routes toward administrative access, mapping your directory to find the shortest one. Directory Decoy puts its decoys directly on those routes.
Contained automatically
For shadow credential, RBCD, and pre-2000 attacks, the agent does not just alert. It reverses the change the attacker made, disables the account, and records the action alongside the detection.
Products
Built for Active Directory
- Credential theft in Active Directory
- 6 techniques attackers use to steal and reuse account credentials, including Kerberoasting, AS-REP Roasting, DCSync, Shadow Credentials, and RBCD.
- Certificate services abuse
- Attackers issue themselves certificates to impersonate privileged accounts. CertGuard denies the request as it alerts you.
- Near-Zero false positives
- Nothing legitimate touches a decoy, so there is no baseline to tune and nothing to filter out.
- Alerts where you work
- Slack, Splunk, Microsoft Sentinel, email, or any webhook endpoint.
How It Works
Running in an afternoon
- 01Install the agent
- 02Create your decoys
- 03Get alerted
About
Why we build this
Claymore Labs builds deception technology for Active Directory. We study how intrusions actually unfold, then build detections that fire on the attacker's first move rather than their last.
About Claymore LabsStop tuning and start detecting.
Deploy Directory Decoy across your domain controllers and certificate authority. Priced by the identities you protect, with every detection included.