Directory Decoy · Active Directory Deception

Detect attackers
before they succeed

Directory Decoy places fake misconfigurations across your Active Directory environment. They look like the vulnerable assets attackers hunt for, but instead of granting an attacker access to your infrastructure, they get shut out and you get an instant alert.

12+

Attack techniques

~1s

Alerts

0

False positives

Why It Works

Detection without the tuning

Conventional tools try to separate attacks from normal activity, which is why they need constant tuning and still produce noise. A decoy has no normal activity to separate out. Anyone who interacts with one has already given themselves away.

Modeled on real attacks

Each decoy is built to match what attackers actually go looking for, and configured to match your environment. To anyone scanning your directory, it is indistinguishable from a genuine target.

Placed where attackers look first

Attackers follow predictable routes toward administrative access, mapping your directory to find the shortest one. Directory Decoy puts its decoys directly on those routes.

Contained automatically

For shadow credential, RBCD, and pre-2000 attacks, the agent does not just alert. It reverses the change the attacker made, disables the account, and records the action alongside the detection.

Detection

What it catches

See all capabilities
Credential theft in Active Directory
6 techniques attackers use to steal and reuse account credentials, including Kerberoasting, AS-REP Roasting, DCSync, Shadow Credentials, and RBCD.
Certificate services abuse
Attackers issue themselves certificates to impersonate privileged accounts. CertGuard denies the request as it alerts you.
Near-Zero false positives
Nothing legitimate touches a decoy, so there is no baseline to tune and nothing to filter out.
Alerts where you work
Slack, Splunk, Microsoft Sentinel, email, or any webhook endpoint.

How It Works

Running in an afternoon

  1. 01Install the agent
  2. 02Create your decoys
  3. 03Get alerted

About

Why we build this

Claymore Labs builds deception technology for Active Directory. We study how intrusions actually unfold, then build detections that fire on the attacker's first move rather than their last.

About Claymore Labs

Stop tuning and start detecting.

Deploy Directory Decoy across your domain controllers and certificate authority. Priced by the identities you protect, with every detection included.