Get started in seconds
Install the agent, create your decoys, and Directory Decoy runs quietly in the background, alerting you whenever a decoy is tripped.
- 01
Install the agent
Run a single setup script on your domain controllers and certificate authorities. The agent registers itself automatically.
- 02
Create your decoys
Set up decoy accounts and certificate templates from the dashboard. Directory Decoy performs routine checks to confirm it is still in place and operational.
- 03
Get alerted
Any interaction with a decoy reaches your team within seconds, carrying the account involved, where it came from, and the technique used.
What a detection looks like
One interaction is all it takes
A decoy has no legitimate reason to be touched. No employee signs into it, no application authenticates against it, no scheduled job reads it. That is what makes it useful: there is no normal activity to separate an attack from, so there is nothing to tune and nothing to filter.
When someone asks for a decoy account's credentials, requests a certificate from a decoy template, or modifies a decoy computer, the agent sees the event and raises an alert naming the account responsible, where the request came from, and what was targeted.
That alert reaches Slack, your SIEM, PSA, email, or any webhook endpoint within seconds. For shadow credential, RBCD, and pre-2000 attacks the agent also undoes the change and disables the account, then records what it did alongside the detection.
Decoys are also routinely monitored to ensure they remain operational. Environments are constantly changing and Directory Decoy will verify that all required configurations are in place long after installation.
Stop tuning and start detecting.
Deploy Directory Decoy across your domain controllers and certificate authority. Priced by the identities you protect, with every detection included.