ProductsDirectory Decoy

What’s included

There is one Directory Decoy and it ships whole. Every detection, every integration, and CertGuard blocking are in every account — the only thing that changes with size is the rate per protected identity.

Capabilities included with Directory Decoy
Detection
Kerberoasting detectionIncluded
AS-REP Roasting detectionIncluded
DCSync target detectionIncluded
Pre-2000 machine account detectionIncluded
Shadow Credentials detectionIncluded
RBCD detectionIncluded
ADCS abuse detectionESC1, 2, 3, 4, 9, and 13
Honey files, shares, and foldersIncluded
Response
CertGuard active blockingDenies the certificate request as it alerts
Guided decoy deployment and verificationIncluded
Alert triage, assignment, and notesIncluded
Integrations
Email alertsIncluded
Webhook integrationsIncluded
SIEM integrationSplunk HEC, Microsoft Sentinel, CEF, and LEEF
Slack notificationsIncluded
PSA integrationConnectWise
Full API accessIncluded
Platform
AgentsUnlimited
DecoysUnlimited
Event retention1 year
Multi-org support for MSPs and MSSPsIncluded
Role-based access controlIncluded

On-premise deployment, service-level agreements, and dedicated support are arranged per contract rather than bundled — they depend on your environment, not your size. Talk to sales if you need any of them.

Requirements

What you need to run it

One self-contained executable per server. No runtime to install, no kernel drivers, and nothing on your endpoints.

Operating system
Windows Server 2016 or later, x64
Installer
PowerShell 5.1 or later
Privileges
Administrator rights to install; the agent then runs as a Windows service (ClaymoreAgent)
Network
Outbound HTTPS (TCP 443) only — to the Claymore API, and to install.claymorelabs.io during installation. Nothing listens for inbound connections.

Deployment

Agent roles

You pick a role at install time. It determines what the agent watches for, so install on the servers that matter: your domain controllers, and your certificate authority if you want certificate services coverage.

Domain Controller

domain_controller

Detects
Kerberoasting, AS-REP Roasting, DCSync, Pre-2000 machine accounts, Shadow Credentials, and RBCD
Notes
Install on each domain controller in the domain. Directory Decoy coordinates between them, so a decoy shared across the domain is verified once rather than repeatedly, and ordinary traffic between your own controllers never raises an alert.

Certificate Authority

certificate_authority

Detects
ADCS certificate template abuse: ESC1, ESC2, ESC3, ESC4, ESC9, and ESC13
Notes
Requires Claymore CertGuard on the certificate authority. CertGuard denies any request made against a decoy template, so the certificate is never issued — the attempt is alerted rather than fulfilled.

Stop tuning and start detecting.

Deploy Directory Decoy across your domain controllers and certificate authority. Priced by the identities you protect, with every detection included.