Skip to content

Deception, explained

What a honeypot is,and how to choose one.

A short guide: what a honeypot does, where it fits in your security, and the questions worth asking any provider before you sign. Including us.

A system nobody should ever touch.

A honeypot is a decoy: it looks like a real, valuable machine on your network, but has no legitimate purpose. No employee, application or backup job has a reason to reach it. So whatever does is a threat.

ws-14ws-15ws-16erp-01fs-01backup-01compromiseddecoy
Alert: ws-14 touched backup-01. Nothing legitimate ever does.
  • Near-zero false positives

    Intent isn't inferred, it is self-declared. No tuning, no baselines, no guessing.

  • Catches what already got in

    Threats rarely go straight for the prize. They probe and move from machine to machine, and that is where they meet a decoy.

  • Buys you time

    A convincing decoy keeps a threat busy on something worthless while you respond.

Why now:the window is closing.

  1. 01

    Outside, the odds favour the threat.

    You can spot a phishing email today, and tomorrow. But every time? Every colleague? A threat only needs one mistake, and the risk adds up.

  2. 02

    Inside, the table turns.

    After the breach comes the delicate part for the threat: moving between machines, escalating privileges, getting data out. That time is called dwell time, and industry reports put it at around ten days. Ten days in which the defender has the advantage, and the threat can't afford a mistake.

  3. 03

    And that window is shrinking.

    AI is finding vulnerabilities, new zero-days included, faster than they can be patched, and the gap between disclosure and exploitation keeps closing. Detection that takes days to sort through arrives too late.

Until recently

Initial accessAccessLateral movementMovementDamageDamage

With AI

Initial accessAccessLateral movementMovementDamageDamage

With decoys

Initial accessAccessBusy on the decoyOn the decoy

Why those days favour the defender: The strategic importance of layered defense

Its role: the layer that tells you something got through, while keeping it busy.

A honeypot doesn't replace what you already have. It tells you when that wasn't enough.

  1. 01

    Keep them out

    Firewalls, email filtering, endpoint protection, patching

    Prevention. Necessary, and never perfect.

  2. 02

    Notice when they're in

    Honeypots

    Detection of what got past, with alerts you can act on without an analyst.

  3. 03

    Respond

    Your team, your MSSP, your provider

    Act on a confirmed threat, with time bought by the decoy.

It's good to have emergency braking on your car, but it's not a good reason to stop using your foot.
Use endpoint protection, just don't rely on it alone: The weakness of Endpoint Detection

Two kinds, one trade-off.Safe or effective. Pick one.

Low interaction

Emulated services

A script that answers a few protocol requests: a banner, a login prompt.

  • Cheap and quick to deploy
  • Little risk if attacked
  • Easy to recognise for a threat that looks twice
  • Says little beyond "someone crossed a line"

Full interaction

Complete systems

A real machine that can actually be broken into, with something plausible inside.

  • Convincing, even after the break-in
  • Shows who the threat is and what it does
  • Keeps a threat busy
  • If taken over, a foothold inside your network
  • Costly to contain and to watch

Some designs remove this trade-off. Ours is one of them. See how Hoxey removes it

The questions to ask

How to choose a deception provider.

Five questions worth asking any vendor, us included. Not every one needs a positive answer: consistency is what's being tested.

Accept drawbacks consciously. Refuse inconsistencies, because your security is at stake.

  1. 01

    Do you update the decoys? How do the updates reach them?

    The easy answer
    "We don't, they are meant to be vulnerable."
    Why it matters
    A decoy that hands over root in minutes ends the deception early, and stale software is easy to fingerprint. On a fully interactive decoy it also weakens containment: an unpatched system is the easiest one to break out of. Decoys need updating. But updating one that sits in your network means someone has a path into your network.
    Listen for
    How the updates are curated. Patching everything automatically would also fix the services meant to lure a threat, so a vendor who knows the field will explain what is updated by hand and what is deliberately left exposed.
  2. 02

    How do you contain a compromised decoy?

    The easy answer
    "It's isolated."
    Why it matters
    Containment decides whether a honeypot is an asset or a liability. Virtual machines, containers (which share the host's kernel) and non-interactive decoys (safe because there is nothing to break into, and for the same reason poor at deceiving) carry very different risks.
    Listen for
    Technical detail your own team can evaluate: what isolates the decoy, where containment happens, and what happens if it fails.
  3. 03

    How effective is your decoy at keeping a threat busy?

    The easy answer
    "It's fully interactive."
    Why it matters
    A few standard services with a generic shell behind them detect well, but a threat sees through them quickly. Deceiving takes a complete, coherent system that still holds up after the break-in and gives the threat something real to look for.
    Listen for
    A demonstration of what a threat finds after it gets a shell, shown rather than described.
  4. 04

    What access do you have to my company, and what supply-chain risk do you carry?

    The easy answer
    "None. Honeypots reach out."
    Why it matters
    Reaching out is not the same as no access. Anything on your network that pulls updates is a route in: a malicious or compromised update is a shell on the box. "No access" and "automatic updates" cannot coexist if the decoy lives in your network.
    Listen for
    Who can push code to what, in which direction connections are opened, and whether you can audit what runs on your side.
  5. 05

    Once a decoy has been compromised, how is it reset?

    The easy answer
    "We reimage it."
    Why it matters
    A decoy will be compromised: that is its job. Afterwards the threat may still be on it, so it has to come back clean and credible, quickly. If it lives in your network, reimaging it takes either remote access to your network or someone on site. And the credential the decoy uses to report to the vendor's backend has been sitting on a machine the threat controlled: it must be assumed stolen.
    Listen for
    How a clean image reaches the decoy, how long the reset takes, and how the decoy's credential is rotated with it. Ask what that credential can reach in the meantime.

Our answers to questions 2 and 4 are public: the Hoxey security model.

Red flags worth knowing

  • AI-generated command answers

    A real command answers in milliseconds; model inference takes seconds. That delay gives the decoy away almost at once, and generated output stops being consistent as soon as a threat looks around.

  • Several IPs per decoy

    It sounds like more coverage, but the addresses share one fingerprint. A basic scan, an SSH banner or TCP behaviour, gives them away before any meaningful interaction.

Deception seems easy. It isn't.

Ask us these questions.

We'll answer every one on a technical call, including the ones we're still working on.

Prefer writing?

Join The Hive

Threat intel from our own decoys, first-hand. Not another newsletter.

  • Intel from our network. What our decoys catch: the credentials threats try, the tools they bring, the techniques that are new. First-hand, not recycled.
  • Alerts, when it matters. When something we see is worth acting on, you hear it from us, with what to do.
  • Attack stories. The story behind the intel: a real attack, narrated step by step from the offensive side.

Low volume, high quality.

Plus occasional Hoxey news, and we remember your visits. Unsubscribe anytime.

Get in touch

Write to us here and we'll email you back.

We'll reply by email. Privacy policy Prefer a call? Book one