What’s included
There is one Directory Decoy and it ships whole. Every detection, every integration, and CertGuard blocking are in every account — the only thing that changes with size is the rate per protected identity.
| Detection | |
|---|---|
| Kerberoasting detection | Included |
| AS-REP Roasting detection | Included |
| DCSync target detection | Included |
| Pre-2000 machine account detection | Included |
| Shadow Credentials detection | Included |
| RBCD detection | Included |
| ADCS abuse detection | ESC1, 2, 3, 4, 9, and 13 |
| Honey files, shares, and folders | Included |
| Response | |
| CertGuard active blocking | Denies the certificate request as it alerts |
| Guided decoy deployment and verification | Included |
| Alert triage, assignment, and notes | Included |
| Integrations | |
| Email alerts | Included |
| Webhook integrations | Included |
| SIEM integration | Splunk HEC, Microsoft Sentinel, CEF, and LEEF |
| Slack notifications | Included |
| PSA integration | ConnectWise |
| Full API access | Included |
| Platform | |
| Agents | Unlimited |
| Decoys | Unlimited |
| Event retention | 1 year |
| Multi-org support for MSPs and MSSPs | Included |
| Role-based access control | Included |
On-premise deployment, service-level agreements, and dedicated support are arranged per contract rather than bundled — they depend on your environment, not your size. Talk to sales if you need any of them.
Requirements
What you need to run it
One self-contained executable per server. No runtime to install, no kernel drivers, and nothing on your endpoints.
- Operating system
- Windows Server 2016 or later, x64
- Installer
- PowerShell 5.1 or later
- Privileges
- Administrator rights to install; the agent then runs as a Windows service (ClaymoreAgent)
- Network
- Outbound HTTPS (TCP 443) only — to the Claymore API, and to install.claymorelabs.io during installation. Nothing listens for inbound connections.
Deployment
Agent roles
You pick a role at install time. It determines what the agent watches for, so install on the servers that matter: your domain controllers, and your certificate authority if you want certificate services coverage.
Domain Controller
domain_controller
- Detects
- Kerberoasting, AS-REP Roasting, DCSync, Pre-2000 machine accounts, Shadow Credentials, and RBCD
- Notes
- Install on each domain controller in the domain. Directory Decoy coordinates between them, so a decoy shared across the domain is verified once rather than repeatedly, and ordinary traffic between your own controllers never raises an alert.
Certificate Authority
certificate_authority
- Detects
- ADCS certificate template abuse: ESC1, ESC2, ESC3, ESC4, ESC9, and ESC13
- Notes
- Requires Claymore CertGuard on the certificate authority. CertGuard denies any request made against a decoy template, so the certificate is never issued — the attempt is alerted rather than fulfilled.
Stop tuning and start detecting.
Deploy Directory Decoy across your domain controllers and certificate authority. Priced by the identities you protect, with every detection included.