Why Directory Decoy
See why Directory Decoy is necessary to defend against modern threats.
Directory Decoy is an additive control. It is not an endpoint product, and not a replacement for the tools already protecting your network. It occupies the one layer those tools don't protect well: identity-based attacks.
The distinction that matters is the kind of evidence it produces. Everything else in a security stack works by inference: it observes ordinary activity and decides how likely it is to be an attack. That is necessary work, and it is why those tools need constant tuning and still produce alerts that need adjudicating. A decoy produces a different kind of evidence entirely. It has no legitimate use, so there is nothing to infer. The interaction event itself is the conclusion.
Directory Decoy compliments existing security infrastructure, catching modern attacks that are incredibly difficult to tune with traditional tools. It is the one source in your environment that is never ambiguous, waiting for an attacker to fall for its traps.
Diagram pending
The only purpose-built deception for certificate services
ADCS escalation is the most reliable path to domain dominance in a modern network and the least covered by anything else. Directory Decoy was built around it rather than extended to reach it.
See the ADCS detections- Decoy templates for the escalation paths that matter
- Templates that appear vulnerable to ESC1, ESC2, ESC3, ESC4, ESC9, and ESC13 are published into your certificate authority alongside the real ones. An attacker enumerating templates for a way to impersonate a domain administrator finds them.
- The request is denied as it alerts
- A policy module on the certificate authority enforces every decoy template. The certificate is never issued — not held for review, not issued and revoked, never issued. The attempt raises an alert and returns the attacker nothing.
- Safe by construction
- Because the decoy templates cannot issue, a decoy that is misconfigured or forgotten is not a liability sitting in your certificate authority. The failure mode of this control is that it stops detecting, not that it becomes the vulnerability it imitates.
- Coverage where there is otherwise no signal at all
- Certificate issuance is ordinary activity, so exploitation of a genuinely misconfigured template produces logs that look exactly like a certificate authority working. A decoy template is the difference between an event and an answer.
Every major Active Directory attack path
Decoys cover the most well-known and lucrative attack paths, making them irresistable to attackers.
See the credential theft detections- Kerberoasting and AS-REP Roasting
- Attackers target service accounts for offline password cracking. Once they attempt this attack against a decoy, you will be notified immediately.
- DCSync
- Replication requested by anything that is not a domain controller is the step immediately before a full credential dump. Directory Decoy alerts when a decoy account is named, or when the request comes from an account with no reason to sync passwords.
- Shadow credentials and resource-based delegation
- Both are quiet privilege escalations that leave a legitimate-looking directory change behind. Directory Decoy catches the change on a decoy object, then reverses it and disables the account automatically.
- Pre-Windows 2000 machine accounts
- Legacy computer accounts whose password is derivable from the account name. Widely exploited, barely covered by anything, and trivially decoyed.
- Files, shares, and credentials
- Honey files, folders, shares, and planted credentials extend the same idea past the directory to the places an attacker looks next.
Alerts in seconds, with nothing to tune
Traditional detection is based on distinguishing normal behavior from malicious behavior. Directory Decoy inverts the process, providing high fidelity alerts.
See how alerting works- Deterministic, not probabilistic
- A decoy is not touched by employees, applications, or scheduled jobs. There is no baseline period, no learning mode, no threshold, and no score. An interaction is not evidence that an attack MAY be underway, it IS the attack.
- Every alert is worth opening
- The expensive part of a noisy tool is not the alerts, it is the deliberation. Removing the ambiguity removes the queue, and removes the habit of assuming the next one is nothing.
- Attribution arrives with the alert
- The account responsible, the address it came from, the object targeted, and the MITRE ATT&CK technique are all in the detection. Triage starts with the answer instead of a search.
- Containment without waiting for a human
- For the techniques where the attacker has already changed something, the agent reverses the change and disables the account, then records what it did. Response time stops depending on who is awake.
Deployed in an afternoon, not a quarter
Most security tooling fails at the install rather than the detection. A control that is still half-rolled-out protects nothing.
See what deployment involves- Nothing on your endpoints
- One self-contained executable on your domain controllers, and on your certificate authority if you want certificate coverage. No workstation agent, no appliance, and no network tap.
- One single install script
- The agent installs, registers itself, and pulls its configuration automatically. Agents are ready to monitor for decoys immediately.
- Stays correct as environments change
- Agents continuously re-verify every decoy against the environment and report their status. If settings and accounts are changed, you will be notified in the dashboard, and provided with a solution to fix it.
Priced for the organizations who need protection
Enterprise security tooling can be prohibitively expensive and still requires an entire team to operate it.
See pricing- One product, no feature tiers
- Every detection, ADCS abuse blocking, every integration, and the full API ship to every account at every size. Companies of all sizes can benefit from state-of-the-art deception.
- Billed per protected identity
- Agents and decoys are unlimited, deploy hundreds across as many servers as you like. You are only billed for the number of total identities protected.
- No infrastructure required
- There is no appliance to buy, and no log volume to pay for downstream. The operating cost stops at the licenses.
- Negligible overhead on the servers it runs on
- The agent is a lightweight Windows service that monitors for decoy interactions.
Built for those protecting others
Multi-tenancy is native to the deception platform. Monitor an ever-growing number of organizations at a glance.
See multi-tenant capabilities- One console across every client
- Manage all client tenants from a single dashboard with aggregated views, rather than juggling endless logins.
- Guaranteed Isolation
- Client organizations are isolated in their own tenants, but available for MSPs and MSSPs to manage at once.
- Independent client roles
- Each client keeps its own notification channels and destinations, and your staff hold roles scoped to the clients they actually work on.
Against the alternatives
How it compares
Every one of these is a real product doing a real job. The question is not which is better, it is which of them is watching the identity layer — and for most of them, the answer is that it is not what they are for.
- Against traditional honeypots
- Network-layer deception services deploy decoy hosts, services, and segments. However, it does not operate at the identity layer, so popular attacks like Kerberoasting, DCSync, and certificate template abuse pass it entirely.
- Against endpoint detection
- EDR watches processes on machines. The techniques here are legitimate directory and certificate requests made over the network by a valid account, and mostly do not involve running anything unusual on a host at all.
- Against a SIEM
- A SIEM can see these events, provided the right sources are collected, the right rules are written, and someone maintains both. Directory Decoy is the source that makes the answer unambiguous before correlation, and it ships its detections into your SIEM rather than competing with it.
- Against Microsoft Defender for Identity
- MDI is a reasonable baseline for Active Directory and part of a licence many organizations already hold. It does not create and maintain honeypot objects for you, has no certificate services deception, and has no multi-tenant model for a provider running it across clients.
- Against doing nothing here
- The realistic alternative for most organizations is not another product. It is the assumption that the existing stack happens to catch identity attacks, which is the assumption every one of these intrusions was built on.
Comparison matrix pending
Objections
What’s holding you back
The five we hear most often, answered without pretending the alternatives are bad products.
- We already have Microsoft Defender for Identity with our E5 licence.
- Keep it. MDI is a sensible baseline and the two are complementary. What it does not do is create and maintain decoy objects for you, cover certificate services abuse, or give a provider a multi-tenant console across clients. Directory Decoy adds the deterministic layer underneath: MDI infers an attack from behaviour, a decoy interaction simply is one.
- We already use Canary or another deception product.
- Network-layer deception and identity-layer deception solve different problems, and most environments that are serious about this end up with both. Decoy hosts and services do not detect Kerberoasting, DCSync, shadow credentials, or ADCS template abuse, because none of those involve touching a decoy host.
- How does this sit with our existing EDR, SIEM, and XDR?
- Alongside them, not in place of them. Directory Decoy runs independently and ships its detections outward — OCSF JSON, CEF, LEEF, Splunk HEC, Microsoft Sentinel, ConnectWise, Slack, email, or any webhook. It is a high-confidence source for the tools you already run, and it does not need them to work.
- Can an attacker just avoid the decoys?
- Only by not looking. The decoys are the objects that enumeration is specifically designed to surface — the service account with the attractive attributes, the template that appears to allow an arbitrary subject, the machine account that looks unmanaged. They carry realistic names, ages, and metadata and sit among genuine objects, so an attacker cannot distinguish them from the real weaknesses they came to find. Skipping them means skipping the technique.
- Directory Decoy is new. How do we know it works?
- The detection concepts are not new — decoy directory objects and certificate templates are established practice, and the attacks they catch are thoroughly documented. What is new is packaging them so a two-person IT team or a managed provider can run them, with the certificate services coverage that the existing products leave out. Every claim on this page is testable in a fourteen-day trial in your own environment, which is the only evidence that should convince you.
Practical questions about trials, billing, and what counts as a protected identity are on the FAQ tab.
Before and after
The same intrusion, told twice
Without
The intrusion runs to completion
An attacker gains a foothold and starts enumerating the directory. Your tools produce alerts, but nothing is certain: this could be a misconfiguration, a service account behaving oddly, an administrator doing their job. Someone works through the queue deciding which is which. Meanwhile the attacker moves — a service account credential cracked offline, a certificate template that issues as anyone, replication requested from a host that is not a domain controller. By the time the pattern is correlated, they hold domain administrator, and every control you would use to remove them runs with their permission.
With
The intrusion ends at the first decoy
The same attacker enumerates the same directory and finds a service account that looks worth taking, or a template that looks exploitable. It is a decoy, and nothing legitimate has ever touched it. Within seconds your team has an alert naming the account, the source address, the object, and the technique — with no ambiguity to resolve, because there is no innocent explanation for the event. The certificate is denied, or the directory change is reversed and the account disabled, before anyone has opened the notification. The intrusion ends at the reconnaissance step, which is the only cheap place to end one.
Diagram pending
Stop tuning and start detecting.
Deploy Directory Decoy across your domain controllers and certificate authority. Priced by the identities you protect, with every detection included.