Why it works
Most detection tools have to separate malicious activity from huge volumes of normal activity, which produces false positives. A honeypot has no legitimate use, so an alert from it is almost always worth investigating. It is particularly good at catching attackers moving laterally inside a network after the initial compromise.
Types
Decoy servers or devices that imitate a file server, a database or an industrial controller. Honeytokens or canary tokens: fake credentials, API keys, documents or database records placed where an attacker would find them, which trigger an alert when used or opened. Research honeypots, run on the internet by security companies and researchers to study attacker behaviour and feed threat intelligence.
Using them in a company
For most organisations, the practical option is lightweight deception: a few canary tokens and decoy credentials in places attackers search, such as file shares, password stores and code repositories, connected to the SIEM or the SOC. They complement, but do not replace, EDR and log management.
Precautions
A honeypot must be isolated so that it cannot be used as a stepping stone into real systems, and it must not contain real data. Alerts must reach someone who will act on them; an unmonitored honeypot adds risk without any benefit.




