ProductsDirectory Decoy

What Directory Decoy is

Directory Decoy plants accounts and certificate templates across Active Directory that look exactly like the assets attackers hunt for. Nothing legitimate has any reason to touch them, so the first thing that does has already told you it is an intruder.

The problem

Active Directory is the target, and the least watched thing you own

Almost every organization runs on Active Directory. It decides who a user is, what they can reach, and which machines trust which. That makes it the thing an intruder pivots to immediately after their first foothold, because control of it is control of everything downstream.

It is also, in most environments, the least monitored system. Endpoints have detection software, the perimeter has inspection, but common attacks in Active Directory often go unnoticed.

So the techniques that matter here are not exotic. They are well-documented, and they are in every offensive playbook. Most networks, even sophisticated well-run networks, often fall to misconfigurations documented in these playbooks. Directory Decoy is purpose-built to stop these attacks before they even happen.

Where the decoys sit on an attacker’s path
Diagram of an Active Directory intrusion path from initial foothold to domain dominance, with Directory Decoy lures placed at each stage an attacker enumerates

Five gaps

Why it goes unseen

These are not failures of any one product. They are structural, and each one is a reason an intrusion in the directory runs longer than it should.

Certificate services abuse leaves almost nothing behind
Active Directory Certificate Services can issue a certificate that authenticates as any account in the domain. Requesting one is ordinary activity, so a misconfigured template being exploited looks like a certificate being issued — which is what a certificate authority is for. Most security stacks have no coverage here at all.
An intrusion does not take one path
Kerberoasting, AS-REP Roasting, DCSync, shadow credentials, resource-based delegation, and legacy machine accounts are all routes to the same place. Closing one moves the attacker to the next. Coverage that watches two or three of them tells you which route was taken, not whether one was.
Volume defers the decision
Tools that infer attacks from ordinary behaviour must be tuned, and tuned tools still produce alerts that could go either way. The cost is not the alert, it is the deliberation: someone has to decide whether this one is real, and while they decide, the intrusion continues.
Weight stalls the rollout
Identity deception has existed for years. What has kept it out of most environments is what it takes to stand up — appliances, collectors, agents on every endpoint, and a project plan to match. A control that is never finished protects nothing.
Price puts it out of reach
The platforms that do this well are priced for organizations with a security team to run them. Everyone else — including the managed providers protecting hundreds of smaller companies — has been left to hope their existing tools happen to catch it.

The result

What follows

  1. The attacker reaches domain administrator

    From that point every control you own runs with their permission, including the ones you would use to remove them.

  2. The evidence exists but nobody read it in time

    The events were almost always collected. They sat in a log alongside everything else that looked similar, and were correlated after the fact.

  3. Dwell time is measured in months

    Not because the intrusion was sophisticated, but because nothing in the environment was built to be touched only by an intruder.

Introducing

Directory Decoy

Directory Decoy is identity deception for Active Directory. It places decoys into your directory — service accounts that look worth stealing, computer accounts that look misconfigured, certificate templates that look exploitable — and then watches for anyone touching them.

The decoys are built to be found. A service account carries the attributes that make Kerberoasting worthwhile. A certificate template appears to allow an enrollee to name whatever subject they like. A legacy computer account looks like it still has its default, guessable password. They sit in the directory alongside real objects with plausible names, ages, and metadata, so an attacker enumerating for exactly these weaknesses finds them among the genuine ones and cannot tell which is which.

None of them are used by anything real. No employee signs into them, no application authenticates against them, no scheduled job reads them. That is the entire mechanism: there is no normal activity to separate an attack from, so there is no baseline to establish, no threshold to set, and no tuning period before the product is worth listening to. One interaction is the detection.

When one is touched, an agent on the domain controller or certificate authority sees the underlying Windows event and raises an alert naming the account responsible, where the request came from, what was targeted, and which technique was used. It reaches Slack, email, your SIEM, your PSA, or any webhook within seconds. For shadow credential, resource-based delegation, and pre-2000 attacks the agent also reverses the change and disables the account before anyone has read the alert — and records what it did alongside the detection.

For certificate templates it goes further: the decoy template is enforced by a policy module on the certificate authority, so the request that trips the alert is denied in the same moment. The attacker learns nothing and receives nothing. You learn everything.

What one detection tells you

Credibility

Who builds it

Deception is only as good as the model of the attacker behind it. Ours comes from doing the attacking.

Built by people who do this for a living

Directory Decoy is built by offensive security practitioners whose day job is compromising enterprise environments under contract. The decoys are modelled on the paths that actually work in those engagements, not on a threat catalogue.

Engineering leadership behind it

The team has held senior engineering and security leadership roles at large technology and security manufacturers, and has run hundreds of engagements against organizations from small businesses to the Fortune 500.

Deliberately narrow

Directory Decoy does one layer: identity, in Active Directory and the certificate services attached to it. It is the layer attackers pivot to first and the layer instrumented last, and covering it properly is a bigger job than covering everything shallowly.

Stop tuning and start detecting.

Deploy Directory Decoy across your domain controllers and certificate authority. Priced by the identities you protect, with every detection included.