Honeytokens: Detection by Bait

Honeytokens trigger alerts when accessed.

Idea

Honeytokens are one of the simplest and most effective security controls available. The idea is to plant fake but realistic-looking credentials, files, or data in places attackers would search. The bait has no legitimate business reason to be accessed; access to the bait is therefore unambiguous evidence of compromise. The signal-to-noise ratio is among the highest in the security toolkit.

What honeytokens actually are:

Honeytokens are cheap to deploy and high-value when they fire. The discipline is placing them deliberately in the spots attackers would actually look.

Placement

The placement of honeytokens determines their detection coverage. Random placement produces alerts on random compromises; deliberate placement focused on attacker-attractive surfaces produces alerts on the compromises that actually matter.

The placement is the most important design decision. Honeytokens placed in inactive systems detect inactive attackers; honeytokens placed in active surfaces detect active attackers.

Alert

The alert is the output of the honeytoken practice. When a honeytoken is used, the alert fires immediately and routes to the security team's highest priority queue. The alert is reliable; false positives are rare; response should be aggressive.

Honeytokens are one of the highest leverage detection controls available, and one of the cheapest to deploy. Nova AI Ops integrates with honeytoken platforms, surfaces honeytoken alerts as top-priority incidents, and tracks honeytoken-fired investigations from detection through resolution so the security team has a structured workflow for the highest-fidelity signals they receive.