What Directory Decoy is
Directory Decoy plants accounts and certificate templates across Active Directory that look exactly like the assets attackers hunt for. Nothing legitimate has any reason to touch them, so the first thing that does has already told you it is an intruder.
The problem
Active Directory is the target, and the least watched thing you own
Almost every organization runs on Active Directory. It decides who a user is, what they can reach, and which machines trust which. That makes it the thing an intruder pivots to immediately after their first foothold, because control of it is control of everything downstream.
It is also, in most environments, the least monitored system. Endpoints have detection software, the perimeter has inspection, but common attacks in Active Directory often go unnoticed.
So the techniques that matter here are not exotic. They are well-documented, and they are in every offensive playbook. Most networks, even sophisticated well-run networks, often fall to misconfigurations documented in these playbooks. Directory Decoy is purpose-built to stop these attacks before they even happen.

Five gaps
Why it goes unseen
These are not failures of any one product. They are structural, and each one is a reason an intrusion in the directory runs longer than it should.
- Certificate services abuse leaves almost nothing behind
- Active Directory Certificate Services can issue a certificate that authenticates as any account in the domain. Requesting one is ordinary activity, so a misconfigured template being exploited looks like a certificate being issued — which is what a certificate authority is for. Most security stacks have no coverage here at all.
- An intrusion does not take one path
- Kerberoasting, AS-REP Roasting, DCSync, shadow credentials, resource-based delegation, and legacy machine accounts are all routes to the same place. Closing one moves the attacker to the next. Coverage that watches two or three of them tells you which route was taken, not whether one was.
- Volume defers the decision
- Tools that infer attacks from ordinary behaviour must be tuned, and tuned tools still produce alerts that could go either way. The cost is not the alert, it is the deliberation: someone has to decide whether this one is real, and while they decide, the intrusion continues.
- Weight stalls the rollout
- Identity deception has existed for years. What has kept it out of most environments is what it takes to stand up — appliances, collectors, agents on every endpoint, and a project plan to match. A control that is never finished protects nothing.
- Price puts it out of reach
- The platforms that do this well are priced for organizations with a security team to run them. Everyone else — including the managed providers protecting hundreds of smaller companies — has been left to hope their existing tools happen to catch it.
The result
What follows
The attacker reaches domain administrator
From that point every control you own runs with their permission, including the ones you would use to remove them.
The evidence exists but nobody read it in time
The events were almost always collected. They sat in a log alongside everything else that looked similar, and were correlated after the fact.
Dwell time is measured in months
Not because the intrusion was sophisticated, but because nothing in the environment was built to be touched only by an intruder.
Introducing
Directory Decoy
Directory Decoy is identity deception for Active Directory. It places decoys into your directory — service accounts that look worth stealing, computer accounts that look misconfigured, certificate templates that look exploitable — and then watches for anyone touching them.
The decoys are built to be found. A service account carries the attributes that make Kerberoasting worthwhile. A certificate template appears to allow an enrollee to name whatever subject they like. A legacy computer account looks like it still has its default, guessable password. They sit in the directory alongside real objects with plausible names, ages, and metadata, so an attacker enumerating for exactly these weaknesses finds them among the genuine ones and cannot tell which is which.
None of them are used by anything real. No employee signs into them, no application authenticates against them, no scheduled job reads them. That is the entire mechanism: there is no normal activity to separate an attack from, so there is no baseline to establish, no threshold to set, and no tuning period before the product is worth listening to. One interaction is the detection.
When one is touched, an agent on the domain controller or certificate authority sees the underlying Windows event and raises an alert naming the account responsible, where the request came from, what was targeted, and which technique was used. It reaches Slack, email, your SIEM, your PSA, or any webhook within seconds. For shadow credential, resource-based delegation, and pre-2000 attacks the agent also reverses the change and disables the account before anyone has read the alert — and records what it did alongside the detection.
For certificate templates it goes further: the decoy template is enforced by a policy module on the certificate authority, so the request that trips the alert is denied in the same moment. The attacker learns nothing and receives nothing. You learn everything.
Diagram pending
Credibility
Who builds it
Deception is only as good as the model of the attacker behind it. Ours comes from doing the attacking.
Built by people who do this for a living
Directory Decoy is built by offensive security practitioners whose day job is compromising enterprise environments under contract. The decoys are modelled on the paths that actually work in those engagements, not on a threat catalogue.
Engineering leadership behind it
The team has held senior engineering and security leadership roles at large technology and security manufacturers, and has run hundreds of engagements against organizations from small businesses to the Fortune 500.
Deliberately narrow
Directory Decoy does one layer: identity, in Active Directory and the certificate services attached to it. It is the layer attackers pivot to first and the layer instrumented last, and covering it properly is a bigger job than covering everything shallowly.
Keep reading
Five reasons to consider Directory Decoy
Each of these is argued in full on the next tab. Follow one straight to it, or read them in order.
- Purpose-built certificate services deceptionDecoy templates for the escalation paths that carry no signal anywhere else — and the request is denied as it alerts, so nothing is ever issued.
- Every major Active Directory path, not a sampleKerberoasting, AS-REP Roasting, DCSync, pre-2000 machine accounts, shadow credentials, and resource-based delegation.
- Seconds to alert, nothing to tuneA decoy has no legitimate use, so an interaction is not evidence of an attack — it is the attack. There is no baseline and no threshold.
- Deployed in an afternoonOne executable on your domain controllers and certificate authority. No endpoint agents, no appliance, no inbound firewall rule.
- Priced for the organizations that are actually targetedOne product with no feature tiers, billed per protected identity, at a fraction of what enterprise identity deception costs.
Stop tuning and start detecting.
Deploy Directory Decoy across your domain controllers and certificate authority. Priced by the identities you protect, with every detection included.