About
Claymore Labs
We build deception technology for Active Directory, the system attackers target first and defenders find hardest to monitor.
Our Mission
Detection on the first move, not the last
Active Directory decides who can access what across most organizations, which makes it the first thing an attacker goes after and the most damaging thing to lose. The techniques used against it are well documented and widely automated.
Conventional tooling struggles here. These attacks look almost identical to ordinary administrative activity, so detections either produce more alerts than a team can review or miss the activity altogether. Either way, the attacker is found late.
Directory Decoy takes a different approach. Instead of trying to tell an attack apart from normal activity, it places decoys that have no normal activity at all. Anyone who interacts with one has already identified themselves.
C
Claymore Labs
Our Values
How we build
Deception as a core layer
Deception belongs alongside your existing monitoring, not bolted on at the end. It catches what signature and behavior-based tools are structurally unable to see.
Built around real techniques
Every decoy is designed against a documented attack technique. We track how those techniques change and update the detections that cover them.
Understandable by default
Security tools should not require a specialist to interpret. Every alert says plainly what was attempted, what it means, and what to do next.
Contact
Get in touch
For product questions, deployment planning, or anything specific to your environment, we would rather answer directly.
General inquiries: contact@claymorelabs.io
Sales: sales@claymorelabs.io
Support: support@claymorelabs.io
Stop tuning and start detecting.
Deploy Directory Decoy across your domain controllers and certificate authority. Priced by the identities you protect, with every detection included.