ProductsDirectory Decoy

Features and what they get you

Every capability below states two things: what it does, and what you get out of it. The first half is for the person who has to run it, the second for the person deciding whether it is worth running.

Active Directory & Kerberos · 6 techniques

Credential theft

Most Active Directory intrusions start by stealing an account's credentials and reusing them somewhere more privileged. Directory Decoy adds accounts built to look like the most attractive targets, so an attacker searching for one finds it first.

Kerberoasting Detection

T1558.003

Attackers request the encrypted credentials of service accounts, then crack the passwords offline. Directory Decoy adds an account built to look like a high-value target, but triggers an alert when touched.

Benefit

You learn that service account credentials are being harvested while the attacker is still cracking them, rather than when a cracked password is used against you.

AS-REP Roasting Detection

T1558.004

Certain account settings let anyone request crackable credential material without signing in first. Directory Decoy creates an account with exactly that weakness, so attackers target it first.

Benefit

The most attractive account in the domain is the one you planted, so the attempt costs the attacker their position instead of costing you an account.

DCSync Target Detection

T1003.006

With enough privilege, an attacker can impersonate a domain controller and ask for stored password data. Directory Decoy alerts the moment that request names a decoy account, or is triggered by an unauthorized user.

Benefit

Replication requested by something that is not a domain controller is the step before a full credential dump. You get it as it happens, not in the breach report.

Pre-Windows 2000 Detection

Legacy computer accounts are created with passwords guessable from the account name alone. Directory Decoy adds one and alerts when attackers go looking for it.

Benefit

A technique most tooling does not look for at all becomes a named alert with the account attached, and the decoy account is disabled automatically.

Shadow Credentials Detection

Attackers can attach their own certificate to an account and sign in as it, with no password required. Directory Decoy catches the attempt on a decoy computer and reverses it automatically.

Benefit

The attacker’s certificate is stripped and the account disabled without waiting for anyone to read the alert first.

RBCD Detection

Attackers grant themselves permission to act on behalf of other users, then use it to take over a server. Directory Decoy exposes a decoy host that appears to allow it, and reverts the change.

Benefit

The delegation right is revoked as soon as it is granted, so the server takeover it was set up to enable never happens.

ADCS · ESC1, 2, 3, 4, 9, and 13

Certificate services abuse

Your certificate authority can issue credentials that log in as any account. Attackers look for templates misconfigured to let them do exactly that. Directory Decoy publishes templates that look misconfigured but can never be issued — the request is denied as you are alerted.

ESC1 - Enrollee Supplies Subject

ESC1

A misconfigured template lets attackers impersonate any user, including a domain administrator. Directory Decoy publishes a decoy with that flaw and denies every request to it.

Benefit

You find out your certificate authority is being probed for privilege escalation, and no certificate is issued in the process of finding out.

ESC2 - Any Purpose EKU

ESC2

Some templates issue certificates valid for any purpose, including signing in as another user. Directory Decoy offers one and alerts when someone attempts to enroll.

Benefit

Template enumeration, which normally leaves nothing behind to investigate, becomes a single attributable event.

ESC3 - Enrollment Agent

ESC3

Enrollment agent templates let one account request certificates on behalf of others. Directory Decoy publishes a decoy agent template and reports anyone who tries to use it.

Benefit

You see an attacker reaching for the ability to impersonate any user in the domain, while they still do not have it.

ESC4 - Vulnerable ACLs

ESC4

Weak permissions on a template let an attacker rewrite it into something exploitable. Directory Decoy watches a decoy template for exactly those edits.

Benefit

A template permission change — usually invisible until something is exploited through it — arrives as an event with an owner attached.

ESC9 - No Security Extension

ESC9

A template missing its security extension lets an attacker map a certificate onto a different account. Directory Decoy publishes one and denies the requests it attracts.

Benefit

Certificate mapping abuse is caught at the request, which is the last point where stopping it is still free.

ESC13 - Issuance Policy

ESC13

Issuance policies can tie a certificate to membership in a privileged group. Directory Decoy exposes a template that appears to grant that, and alerts on every attempt.

Benefit

Escalation into a privileged group through a certificate is reported the first time it is attempted, rather than found in an access review months later.

Deployment

Getting it running

Deception only helps if it is actually deployed, and most identity security projects stall at the install rather than at the detection. Directory Decoy is built to be live on your domain controllers the same afternoon you decide to try it.

Single self-contained agent

One executable per server, running as a Windows service. No separate runtime to install, no kernel drivers, and nothing deployed to your endpoints.

Benefit

There is no estate-wide rollout to plan. The install touches only the servers you already treat as sensitive.

One line to install

A single PowerShell command per agent role. The agent registers itself, then pulls its decoy configuration from the API rather than from a local file.

Benefit

A domain controller goes from bare to monitored without a packaging exercise, and its configuration is corrected centrally afterwards.

Outbound HTTPS only

Agents make outbound connections on TCP 443 and nothing else. No port is opened, and nothing listens for inbound connections.

Benefit

No new firewall rule and no new listening service on a domain controller — the two things that usually stall a security install.

Agents update themselves

Installed agents upgrade in place as new detection coverage ships, without a reinstall or a manual push.

Benefit

Coverage for newly published techniques arrives without you scheduling a maintenance window for it.

The full platform, privilege, and network requirements are on the What’s Included tab.

Day-two operations

Keeping it working

A decoy that was verified at install and quietly broke six months later is worse than no decoy, because you stopped watching that path on the strength of it. Directory Decoy is built on the assumption that your environment will change underneath it.

Continuous decoy verification

Agents re-check each decoy against the live system and report per-check results. A decoy is unverified until it is confirmed in place, and moves to failed if it stops being so.

Benefit

Coverage that quietly decayed as the environment changed shows up as a state on a dashboard, not as a discovery you make during an incident.

Agent health at a glance

Every agent reports in continuously. The console shows each one with its role, the domain it serves, and when it was last heard from.

Benefit

A domain controller that stopped reporting is visible the same day, instead of being assumed covered until someone checks.

Automatic containment and rollback

For shadow credential, RBCD, and pre-2000 attacks the agent reverses the attacker’s change and disables the account, then records exactly what it did alongside the detection.

Benefit

The attack is undone at machine speed, so how fast you respond stops depending on who happens to be awake.

Immutable detection history

Detections are stored as the agent produced them and cannot be edited. Triage lives beside them, not on top of them: status, assignee, notes, and resolution are tracked separately.

Benefit

The record you hand an auditor, an insurer, or an incident responder is the record the agent wrote, with the investigation attached rather than merged in.

Response

Alerting and integrations

A detection is only worth what it costs to act on. Every alert arrives already answering who, from where, against what, and by which technique — and arrives in whichever system your team already works out of.

Alerts in seconds, with nothing to tune

A decoy interaction reaches your team within seconds of the Windows event that caused it. Legitimate users and services have no reason to touch a decoy, so there is no baseline to establish and no tuning period.

Benefit

Every alert is worth opening. There is no backlog of maybes to work through before you reach the real one.

Attribution on every alert

Each detection names the account responsible, the address the request came from, the decoy that was targeted, and the technique used.

Benefit

Triage opens with the answer rather than with a search, which is most of the time an investigation actually costs.

MITRE ATT&CK mapping

Every detection carries its ATT&CK technique ID and tactic, so alerts line up with the threat intelligence and reporting you already use.

Benefit

Detections drop straight into existing coverage reporting without anyone hand-mapping them first.

Alerts where you already work

Route detections to Slack, email, or any webhook endpoint, which covers Teams and PagerDuty among others.

Benefit

Nobody has to remember to check another console for the one alert that matters.

SIEM, PSA, and API delivery

Ship detections to Splunk HEC, Microsoft Sentinel, or any collector taking OCSF JSON, CEF, or LEEF. ConnectWise PSA and full API access are included.

Benefit

Detections land in the systems your process already runs on, in the format those systems expect, so no glue code is yours to maintain.

MSPs and MSSPs

Running it for other people

Multi-tenancy is not a plan tier here. The same product that protects one domain protects fifty belonging to different companies, with the separation between them enforced where it cannot be bypassed by a missed filter.

One console, every client

Manage every client tenant from a single dashboard, with aggregated views across the ones you operate.

Benefit

Adding a client is an onboarding step rather than another console, another login, and another place to miss an alert.

Isolation enforced in the database

Each client tenant is isolated by the storage layer itself rather than by application-side filtering, and putting a tenant under a management account does not relax that.

Benefit

One client’s incident data cannot surface in another’s console, and that holds because of where the rule lives, not because every query remembered to filter.

Per-tenant alert routing

Every client tenant configures its own notification channels and destinations independently of the others.

Benefit

One deployment does not force one notification policy across clients who escalate differently.

Role-based access control

Owner, admin, analyst, and viewer roles apply per tenant, and at partner scope for staff who work across several.

Benefit

A technician sees the clients they are on without also being able to change how those clients are billed or configured.

Stop tuning and start detecting.

Deploy Directory Decoy across your domain controllers and certificate authority. Priced by the identities you protect, with every detection included.