GlossarySOC and monitoring

Honeypot

Short answer

A honeypot is a decoy system, service or piece of data designed to attract attackers and alert defenders when it is touched. Because no legitimate user should ever interact with it, any activity on a honeypot is a strong signal of an intrusion.

Why it works

Most detection tools have to separate malicious activity from huge volumes of normal activity, which produces false positives. A honeypot has no legitimate use, so an alert from it is almost always worth investigating. It is particularly good at catching attackers moving laterally inside a network after the initial compromise.

Types

Decoy servers or devices that imitate a file server, a database or an industrial controller. Honeytokens or canary tokens: fake credentials, API keys, documents or database records placed where an attacker would find them, which trigger an alert when used or opened. Research honeypots, run on the internet by security companies and researchers to study attacker behaviour and feed threat intelligence.

Using them in a company

For most organisations, the practical option is lightweight deception: a few canary tokens and decoy credentials in places attackers search, such as file shares, password stores and code repositories, connected to the SIEM or the SOC. They complement, but do not replace, EDR and log management.

Precautions

A honeypot must be isolated so that it cannot be used as a stepping stone into real systems, and it must not contain real data. Alerts must reach someone who will act on them; an unmonitored honeypot adds risk without any benefit.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, SOC operations, detection engineering and incident handling.

Go to the topic hub