logo

Detection via Deception — Using your SIEM as a Free Deception Platform

ID: aea87d1e-9160-5910-8786-711ed3f101d3

STIX ID: report--aea87d1e-9160-5910-8786-711ed3f101d3

Feed Name: Detect FYI

Date Published: 2026-03-15

Date Updated: 2026-04-19

Author: Rcegan

...
...

This article explains how to use an existing SIEM as a free deception platform by creating honeytokens (fake user accounts, resources, and watchlists) to detect adversary activity, provides design considerations aligned with MITRE Engage, and includes a sample Microsoft Sentinel KQL query and operational recommendations (suppressions, tailoring lures to threat models).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.