ProductsDirectory Decoy

Why Directory Decoy

See why Directory Decoy is necessary to defend against modern threats.

Where it fits

It runs alongside existing services

Directory Decoy is an additive control. It is not an endpoint product, and not a replacement for the tools already protecting your network. It occupies the one layer those tools don't protect well: identity-based attacks.

The distinction that matters is the kind of evidence it produces. Everything else in a security stack works by inference: it observes ordinary activity and decides how likely it is to be an attack. That is necessary work, and it is why those tools need constant tuning and still produce alerts that need adjudicating. A decoy produces a different kind of evidence entirely. It has no legitimate use, so there is nothing to infer. The interaction event itself is the conclusion.

Directory Decoy compliments existing security infrastructure, catching modern attacks that are incredibly difficult to tune with traditional tools. It is the one source in your environment that is never ambiguous, waiting for an attacker to fall for its traps.

Where Directory Decoy sits in an existing stack

The only purpose-built deception for certificate services

ADCS escalation is the most reliable path to domain dominance in a modern network and the least covered by anything else. Directory Decoy was built around it rather than extended to reach it.

See the ADCS detections
Decoy templates for the escalation paths that matter
Templates that appear vulnerable to ESC1, ESC2, ESC3, ESC4, ESC9, and ESC13 are published into your certificate authority alongside the real ones. An attacker enumerating templates for a way to impersonate a domain administrator finds them.
The request is denied as it alerts
A policy module on the certificate authority enforces every decoy template. The certificate is never issued — not held for review, not issued and revoked, never issued. The attempt raises an alert and returns the attacker nothing.
Safe by construction
Because the decoy templates cannot issue, a decoy that is misconfigured or forgotten is not a liability sitting in your certificate authority. The failure mode of this control is that it stops detecting, not that it becomes the vulnerability it imitates.
Coverage where there is otherwise no signal at all
Certificate issuance is ordinary activity, so exploitation of a genuinely misconfigured template produces logs that look exactly like a certificate authority working. A decoy template is the difference between an event and an answer.

Every major Active Directory attack path

Decoys cover the most well-known and lucrative attack paths, making them irresistable to attackers.

See the credential theft detections
Kerberoasting and AS-REP Roasting
Attackers target service accounts for offline password cracking. Once they attempt this attack against a decoy, you will be notified immediately.
DCSync
Replication requested by anything that is not a domain controller is the step immediately before a full credential dump. Directory Decoy alerts when a decoy account is named, or when the request comes from an account with no reason to sync passwords.
Shadow credentials and resource-based delegation
Both are quiet privilege escalations that leave a legitimate-looking directory change behind. Directory Decoy catches the change on a decoy object, then reverses it and disables the account automatically.
Pre-Windows 2000 machine accounts
Legacy computer accounts whose password is derivable from the account name. Widely exploited, barely covered by anything, and trivially decoyed.
Files, shares, and credentials
Honey files, folders, shares, and planted credentials extend the same idea past the directory to the places an attacker looks next.

Alerts in seconds, with nothing to tune

Traditional detection is based on distinguishing normal behavior from malicious behavior. Directory Decoy inverts the process, providing high fidelity alerts.

See how alerting works
Deterministic, not probabilistic
A decoy is not touched by employees, applications, or scheduled jobs. There is no baseline period, no learning mode, no threshold, and no score. An interaction is not evidence that an attack MAY be underway, it IS the attack.
Every alert is worth opening
The expensive part of a noisy tool is not the alerts, it is the deliberation. Removing the ambiguity removes the queue, and removes the habit of assuming the next one is nothing.
Attribution arrives with the alert
The account responsible, the address it came from, the object targeted, and the MITRE ATT&CK technique are all in the detection. Triage starts with the answer instead of a search.
Containment without waiting for a human
For the techniques where the attacker has already changed something, the agent reverses the change and disables the account, then records what it did. Response time stops depending on who is awake.

Deployed in an afternoon, not a quarter

Most security tooling fails at the install rather than the detection. A control that is still half-rolled-out protects nothing.

See what deployment involves
Nothing on your endpoints
One self-contained executable on your domain controllers, and on your certificate authority if you want certificate coverage. No workstation agent, no appliance, and no network tap.
One single install script
The agent installs, registers itself, and pulls its configuration automatically. Agents are ready to monitor for decoys immediately.
Stays correct as environments change
Agents continuously re-verify every decoy against the environment and report their status. If settings and accounts are changed, you will be notified in the dashboard, and provided with a solution to fix it.

Priced for the organizations who need protection

Enterprise security tooling can be prohibitively expensive and still requires an entire team to operate it.

See pricing
One product, no feature tiers
Every detection, ADCS abuse blocking, every integration, and the full API ship to every account at every size. Companies of all sizes can benefit from state-of-the-art deception.
Billed per protected identity
Agents and decoys are unlimited, deploy hundreds across as many servers as you like. You are only billed for the number of total identities protected.
No infrastructure required
There is no appliance to buy, and no log volume to pay for downstream. The operating cost stops at the licenses.
Negligible overhead on the servers it runs on
The agent is a lightweight Windows service that monitors for decoy interactions.

Built for those protecting others

Multi-tenancy is native to the deception platform. Monitor an ever-growing number of organizations at a glance.

See multi-tenant capabilities
One console across every client
Manage all client tenants from a single dashboard with aggregated views, rather than juggling endless logins.
Guaranteed Isolation
Client organizations are isolated in their own tenants, but available for MSPs and MSSPs to manage at once.
Independent client roles
Each client keeps its own notification channels and destinations, and your staff hold roles scoped to the clients they actually work on.

Against the alternatives

How it compares

Every one of these is a real product doing a real job. The question is not which is better, it is which of them is watching the identity layer — and for most of them, the answer is that it is not what they are for.

Against traditional honeypots
Network-layer deception services deploy decoy hosts, services, and segments. However, it does not operate at the identity layer, so popular attacks like Kerberoasting, DCSync, and certificate template abuse pass it entirely.
Against endpoint detection
EDR watches processes on machines. The techniques here are legitimate directory and certificate requests made over the network by a valid account, and mostly do not involve running anything unusual on a host at all.
Against a SIEM
A SIEM can see these events, provided the right sources are collected, the right rules are written, and someone maintains both. Directory Decoy is the source that makes the answer unambiguous before correlation, and it ships its detections into your SIEM rather than competing with it.
Against Microsoft Defender for Identity
MDI is a reasonable baseline for Active Directory and part of a licence many organizations already hold. It does not create and maintain honeypot objects for you, has no certificate services deception, and has no multi-tenant model for a provider running it across clients.
Against doing nothing here
The realistic alternative for most organizations is not another product. It is the assumption that the existing stack happens to catch identity attacks, which is the assumption every one of these intrusions was built on.
Directory Decoy against the alternatives

Objections

What’s holding you back

The five we hear most often, answered without pretending the alternatives are bad products.

We already have Microsoft Defender for Identity with our E5 licence.
Keep it. MDI is a sensible baseline and the two are complementary. What it does not do is create and maintain decoy objects for you, cover certificate services abuse, or give a provider a multi-tenant console across clients. Directory Decoy adds the deterministic layer underneath: MDI infers an attack from behaviour, a decoy interaction simply is one.
We already use Canary or another deception product.
Network-layer deception and identity-layer deception solve different problems, and most environments that are serious about this end up with both. Decoy hosts and services do not detect Kerberoasting, DCSync, shadow credentials, or ADCS template abuse, because none of those involve touching a decoy host.
How does this sit with our existing EDR, SIEM, and XDR?
Alongside them, not in place of them. Directory Decoy runs independently and ships its detections outward — OCSF JSON, CEF, LEEF, Splunk HEC, Microsoft Sentinel, ConnectWise, Slack, email, or any webhook. It is a high-confidence source for the tools you already run, and it does not need them to work.
Can an attacker just avoid the decoys?
Only by not looking. The decoys are the objects that enumeration is specifically designed to surface — the service account with the attractive attributes, the template that appears to allow an arbitrary subject, the machine account that looks unmanaged. They carry realistic names, ages, and metadata and sit among genuine objects, so an attacker cannot distinguish them from the real weaknesses they came to find. Skipping them means skipping the technique.
Directory Decoy is new. How do we know it works?
The detection concepts are not new — decoy directory objects and certificate templates are established practice, and the attacks they catch are thoroughly documented. What is new is packaging them so a two-person IT team or a managed provider can run them, with the certificate services coverage that the existing products leave out. Every claim on this page is testable in a fourteen-day trial in your own environment, which is the only evidence that should convince you.

Practical questions about trials, billing, and what counts as a protected identity are on the FAQ tab.

Before and after

The same intrusion, told twice

Without

The intrusion runs to completion

An attacker gains a foothold and starts enumerating the directory. Your tools produce alerts, but nothing is certain: this could be a misconfiguration, a service account behaving oddly, an administrator doing their job. Someone works through the queue deciding which is which. Meanwhile the attacker moves — a service account credential cracked offline, a certificate template that issues as anyone, replication requested from a host that is not a domain controller. By the time the pattern is correlated, they hold domain administrator, and every control you would use to remove them runs with their permission.

With

The intrusion ends at the first decoy

The same attacker enumerates the same directory and finds a service account that looks worth taking, or a template that looks exploitable. It is a decoy, and nothing legitimate has ever touched it. Within seconds your team has an alert naming the account, the source address, the object, and the technique — with no ambiguity to resolve, because there is no innocent explanation for the event. The certificate is denied, or the directory change is reversed and the account disabled, before anyone has opened the notification. The intrusion ends at the reconnaissance step, which is the only cheap place to end one.

The same intrusion, with and without a tripwire

Stop tuning and start detecting.

Deploy Directory Decoy across your domain controllers and certificate authority. Priced by the identities you protect, with every detection included.