Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that. Why decoys, and why now The core problem CISA is attempting to address is that many organizations are incapable of detecting adversaries who use legitimate credentials, built-in administrative utilities, and living-off-the-land (LOTL) techniques. CISA’s new guidance argues that once you accept intruders will … More →
Read the original article:
