4 ms·
Internet facing honeypots have a place in detecting threat actors in the "pre-attack" phase (see MITRE), but you need a more sophisticated methodology to filter
by entropyie 3y ago
Internet facing honeypots have a place in detecting threat actors in the "pre-attack" phase (see MITRE), but you need a more sophisticated methodology to filter out all the background noise from script kiddies. You may find that threat actor's OpSec is less disciplined in the pre attack phase also, meaning you get more chances for real attribution.