cisaregulatorNewsThe Broadside2 min read

CISA Publishes Cyber Decoy Guidance for Post-Compromise Detection

Zero Trust architectures move the threat model inside the perimeter, and CISA's answer is decoys, not because they're clever, but because signature-based detection stops working when adversaries use legitimate credentials.


TL;DR

CISA released formal guidance on planning and implementing cyber decoy strategies (tripwires, breadcrumbs, honeytokens) mapped to the MITRE Engage and MITRE ATT&CK frameworks. The guidance is aimed at organizations that struggle to detect adversaries using legitimate credentials, native tools, and living-off-the-land techniques. It frames decoys as a complement to Zero Trust architectures, generating high-fidelity alerts that don't depend on anomaly baselines. The guidance does not specify staffing, infrastructure, or cost requirements for standing up and maintaining decoy operations across maturity levels.

CISA's new decoy guidance addresses a detection problem the agency has been documenting for years. In its 2024 SILENTSHIELD assessment of an FCEB organization, the red team remained undetected throughout, exploiting an unpatched web server in one enclave, phishing into another, and pivoting freely across the Windows domain using unsecured administrator credentials. The organization never saw it. A 2024 critical infrastructure assessment produced the same result: the red team used a leftover web shell from a prior security test, moved through the DMZ, and fully compromised the domain because the organization relied too heavily on endpoint detection and lacked sufficient network-layer controls.

The pattern recurs in CISA's August 2026 "Tale of Two SOCs" advisory. Organization A never detected the red team. Organization B spotted initial access and forced the team into an assume-breach model, but only because its SOC had tuned its baselines and broken down the silos that elsewhere let authenticated lateral movement blend into background noise.

The decoy guidance is the tactical response to those findings. Tripwires expire quietly when touched. Breadcrumbs plant artifacts that draw an adversary toward a monitored asset. Honeytokens are credentials or data that trigger an alert on any use, no anomaly baseline required. The high-fidelity alert is the point. An adversary using legitimate credentials and native Windows tooling generates no signature mismatch. But reaching for a planted service account or a fake database record does, and that alert isn't a false positive.

The guidance deliberately keeps the conceptual barrier low: it walks through MITRE Engage goals (deceive, detect, collect) and maps them to ATT&CK techniques so a team can reason about which adversary behaviors they're trying to surface. But CISA doesn't answer the resource question. Credible decoys distributed across network segments need maintenance, refresh, and integration into SOC workflows. That's detection engineering. Organizations without that capacity (and plenty of state and municipal shops fall into that category) get a framework without the staffing model to operate it.

What the guidance doesn't say is whether CISA intends to follow up with reference architectures or shared-service models that would make decoy operations feasible for teams below the federal tier. Until that happens, the gap between the concept and the Monday-morning reality remains unfilled.


Published ·Deep Fathom