Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ddiinn2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
ddiinn2
10y ago
There are two main advancements beyond "classic" honeypots: 1. Honeypots are easy to fingerprint (see our blackhat talk, https://www.youtube.com/watch?v=Pjvr25lMKSY ) 2. Most honeypots just "sit on the networ
2.
▲
by
ddiinn2
10y ago
Any questions, we'd be happy to answer
3.
▲
by
ddiinn2
11y ago
The trick is to make the breadcrumbs the type of data that an attacker is interested in, but a regular user will never be aware of. For example in windows there is a cache of used credentials along with passwords, it is a known infection sp
4.
▲
by
ddiinn2
11y ago
Like was said before, you have to attack the decoy to recognize it and that enables catching the attack traffic. Also the mere fact that they recount every single action 10 times over before acting is a huge value in and of itself. On anoth
5.
▲
by
ddiinn2
11y ago
When you get one alert that you realize isn't false and has the forensic data tied to it, you can use it as a harness against the loads of information from all the other sensors (firewall, endpoints, sandboxes etc) to give you a defin
6.
▲
by
ddiinn2
11y ago
- What is alerted on (or "attack") is configurable and can range from code being executed (which is the true positive alert) to connecting to ports(which has more noise) - It needs to look like the machine an attacker will be afte
7.
▲
by
ddiinn2
11y ago
Each decoy is configured to look exactly the way that makes sense for the network it's in. An example is a git server with interesting code or an employees pc that shares files that are crafted to draw attackers to that decoy. The deco
8.
▲
by
ddiinn2
11y ago
Hi, dean here (Cymmetria CTO). Two great questions: 1. The concept being that from looking at the machine on the network we don't do anything different then regular machines, so the goal is to prevent fingerprinting. 2. If the attacker