--===============7930280733395567782==
Content-Type: multipart/alternative; boundary="===============3761696486986181898=="
MIME-Version: 1.0
--===============3761696486986181898==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Cybersecurity and Infrastructure Security Agency (CISA)
You are subscribed to Cybersecurity Advisories for Cybersecurity and Infras= tructure Security Agency. This information has recently been updated and is=
now available.
CISA Releases Guidance on Cyber Decoy Strategies [
https://www.cisa.gov/res= ources-tools/resources/using-cyber-decoys-strengthen-detection-and-response= ?utm_source=3D&utm_medium=3DGovDelivery ] 09/16/2026 12:00 PM EDT=20
Today, the Cybersecurity and Infrastructure Security Agency (CISA) released=
Using Cyber Decoys to Strengthen Detection and Response. [
https://www.cis= a.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and= -response?utm_source=3D&utm_medium=3DGovDelivery ] The guidance helps defen= sive teams across critical infrastructure organizations incorporate decoy c= apabilities into broader cyber defense planning to detect and disrupt malic= ious activity early in the intrusion lifecycle.
Many organizations struggle to detect adversaries who use legitimate creden= tials, native tools, and living off the land [
https://www.cisa.gov/resourc= es-tools/resources/identifying-and-mitigating-living-land-techniques ] tech= niques to conduct discovery, move laterally, and access data. Cyber decoys = are assets that appear to be legitimate systems, accounts, or data, but are=
designed to distract adversaries, detect their presence, or facilitate col= lection of cyber threat intelligence (CTI). For robust cyber defense planni= ng, organizations should incorporate cyber decoys within a Zero Trust [ htt= ps://www.cisa.gov/topics/cybersecurity-best-practices/zero-trust ] model th=
at assumes no user, device, application, or network segment is inherently t= rustworthy and requires continuous verification. Because cyber decoy capabi= lities operate under the expectation that an adversary may gain some level =
of access to the environment, they can help defenders detect post-compromis=
e behavior earlier, collect CTI, and reduce time to detection.
This guidance introduces cyber decoy concepts and explains how organization=
s can use the MITRE Engage=E2=84=A2 [
https://engage.mitre.org/starter-kit/=
] framework and MITRE ATT&CK=C2=AE [
https://attack.mitre.org/resources/ ]=
knowledge base to plan decoy operations around adversary tactics, techniqu= es, and procedures (TTPs), organizational risk, and existing security contr= ols, regardless of their cybersecurity maturity level.
Organizations can use the guidance to:
* Understand how cyber decoys complement Zero Trust [
https://www.cisa.go= v/topics/cybersecurity-best-practices/zero-trust ] principles.=20
* Start with lower-complexity techniques, such as tripwires and honeytoke= ns.=20
* Design decoys based on cyber threat information and likely adversary be= havior.=20
* Integrate decoy alerts with existing monitoring and incident response p= rocesses.=20
* Test and refine decoy operations through threat emulation, red teaming,=
or purple teaming.=20
Read the full guidance [
https://www.cisa.gov/resources-tools/resources/usi= ng-cyber-decoys-strengthen-detection-and-response?utm_source=3D&utm_medium= =3DGovDelivery ] to learn more. For additional information, visit CISA=E2= =80=99s Best Practices for MITRE ATT&CK Mapping [
https://www.cisa.gov/news= -events/news/best-practices-mitre-attckr-mapping ].
Please share your thoughts with us through this anonymous survey [
https://= cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?Source=3DGovDeliv= eryCyberDecoysStrengthenDetectionResponse ]. We appreciate your feedback.
This product is provided subject to this Notification [
https://www.cisa.go= v/notification ] and this Privacy & Use [
https://www.cisa.gov/privacy-poli=
cy ] policy.
body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight=
: normal; font-style: normal; color: #333333; }=20
Having trouble viewing this message?=C2=A0View it as a webpage [
https://co= ntent.govdelivery.com/accounts/USDHSCISA/bulletins/42aff90 ].=C2=A0 [ https= ://content.govdelivery.com/accounts/USDHS/bulletins/292141e ]
You are subscribed to updates from the Cybersecurity and Infrastructure Sec= urity Agency [
https://www.cisa.gov ] (CISA)
Manage Subscriptions [
https://public.govdelivery.com/accounts/USDHSCISA/su= bscriber/edit?preferences=3Dtrue#tab1 ]=C2=A0=C2=A0|=C2=A0=C2=A0Privacy Pol= icy [
https://www.cisa.gov/privacy-policy ]=C2=A0=C2=A0|=C2=A0 Help [ https= ://subscriberhelp.granicus.com/s/article/Subscriber-Help-Center ] [ https:/= /insights.govdelivery.com/Communications/Subscriber_Help_Center ]
Connect with CISA:=20
Facebook [
https://www.facebook.com/CISA ]=C2=A0 |=C2=A0 Twitter [
https://= twitter.com/CISAgov ]=C2=A0 |=C2=A0 Instagram [
https://Instagram.com/cisag=
ov ]=C2=A0 |=C2=A0 LinkedIn [
https://www.linkedin.com/company/cybersecurit= y-and-infrastructure-security-agency ]=C2=A0 |=C2=A0=C2=A0 YouTube [ https:= //www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A ]
________________________________________________________________________
This email was sent to
cisa@toolazy.synchro.net using Granicus Communicatio=
ns Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency = =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202 Granicus Communicati= ons logo [
https://granicus.com/solution/digital-communication-engagement/ = ]=20
body .abe-column-block { min-height: 5px; } table.gd_combo_table img {margi= n-left:10px; margin-right:10px;} table.gd_combo_table div.govd_image_displa=
y img, table.gd_combo_table td.gd_combo_image_cell img {margin-left:0px; ma= rgin-right:0px;}
--===============3761696486986181898==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"
http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns=3D"
http://www.w3.org/1999/xhtml" xml:lang=3D"en" lang=3D"en"> <head>
<title> CISA Releases Guidance on Cyber Decoy Strategies
</title>
</head>
<body style=3D"">
<table width=3D"700" border=3D"0" cellspacing=3D"0" cellpadding=3D"0"=
align=3D"center">
<tr>
<td>
<!--[if (gte mso 9)|(IE)]>
<table style=3D"display:none"><tr><td><a name=3D"gd_top" id=3D"gd_top"></= a></td></tr></table>
<![endif]-->
<a name=3D"gd_top" id=3D"gd_top"></a>
=20
<p><img src=3D"
https://content.govdelivery.com/attachments/fancy_images/U= SDHSCISA/2020/06/3486054/05152023-gov-delivery-banner-copy_original.png" al= t=3D"Cybersecurity and Infrastructure Security Agency (CISA)" title=3D"" wi= dth=3D"600" height=3D"100"></p>
<p>You are subscribed to Cybersecurity Advisories for Cybersecurity and I= nfrastructure Security Agency. This information has recently been updated a=
nd is now available.</p>
<div class=3D"rss_item" style=3D"margin-bottom: 2em;">
<div class=3D"rss_title" style=3D"font-weight: bold; font-size: 120%; margi=
n: 0 0 0.3em; padding: 0;"><a href=3D"
https://www.cisa.gov/resources-tools/= resources/using-cyber-decoys-strengthen-detection-and-response?utm_source= =3D&utm_medium=3DGovDelivery" target=3D"_blank" title=3D"CISA Releases Guid= ance on Cyber Decoy Strategies" rel=3D"noopener">CISA Releases Guidance on = Cyber Decoy Strategies</a></div>
<div class=3D"rss_pub_date" style=3D"font-size: 90%; font-style: italic; co= lor: #666666; margin: 0 0 0.3em; padding: 0;">09/16/2026 12:00 PM EDT</div> <div class=3D"l-page-section l-page-section--rich-text csaf-imported">
<div class=3D"l-constrain">
<div class=3D"l-page-section__content">
<p>Today, the Cybersecurity and Infrastructure Security Agency (CISA) relea= sed <a href=3D"
https://www.cisa.gov/resources-tools/resources/using-cyber-d= ecoys-strengthen-detection-and-response?utm_source=3D&utm_medium=3DGovDeliv= ery" target=3D"_blank" rel=3D"noopener">Using Cyber Decoys to Strengthen De= tection and Response.</a> The guidance helps defensive teams across critica=
l infrastructure organizations incorporate decoy capabilities into broader = cyber defense planning to detect and disrupt malicious activity early in th=
e intrusion lifecycle.</p>
<p>Many organizations struggle to detect adversaries who use legitimate cre= dentials, native tools, and <a href=3D"
https://www.cisa.gov/resources-tools= /resources/identifying-and-mitigating-living-land-techniques" target=3D"_bl= ank" rel=3D"noopener">living off the land</a> techniques to conduct discove= ry, move laterally, and access data. Cyber decoys are assets that appear to=
be legitimate systems, accounts, or data, but are designed to distract adv= ersaries, detect their presence, or facilitate collection of cyber threat i= ntelligence (CTI). For robust cyber defense planning, organizations should = incorporate cyber decoys within a <a href=3D"
https://www.cisa.gov/topics/cy= bersecurity-best-practices/zero-trust" target=3D"_blank" rel=3D"noopener">Z= ero Trust</a> model that assumes no user, device, application, or network s= egment is inherently trustworthy and requires continuous verification. Beca= use cyber decoy capabilities operate under the expectation that an adversar=
y may gain some level of access to the environment, they can help defenders=
detect post-compromise behavior earlier, collect CTI, and reduce time to d= etection.</p>
<p>This guidance introduces cyber decoy concepts and explains how organizat= ions can use the <a href=3D"
https://engage.mitre.org/starter-kit/" target= =3D"_blank" rel=3D"noopener">MITRE Engage=E2=84=A2</a> framework and <a hre= f=3D"
https://attack.mitre.org/resources/" target=3D"_blank" rel=3D"noopener= ">MITRE ATT&CK=C2=AE</a> knowledge base to plan decoy operations around=
adversary tactics, techniques, and procedures (TTPs), organizational risk,=
and existing security controls, regardless of their cybersecurity maturity=
level.</p>
<p>Organizations can use the guidance to:</p>
<li>Understand how cyber decoys complement <a href=3D"
https://www.cisa.gov/= topics/cybersecurity-best-practices/zero-trust" target=3D"_blank" rel=3D"no= opener">Zero Trust</a> principles.</li>
<li>Start with lower-complexity techniques, such as tripwires and honeytoke= ns.</li>
<li>Design decoys based on cyber threat information and likely adversary be= havior.</li>
<li>Integrate decoy alerts with existing monitoring and incident response p= rocesses.</li>
<li>Test and refine decoy operations through threat emulation, red teaming,=
or purple teaming.</li>
</ul>
<p>Read the <a href=3D"
https://www.cisa.gov/resources-tools/resources/using= -cyber-decoys-strengthen-detection-and-response?utm_source=3D&utm_medium=3D= GovDelivery" target=3D"_blank" rel=3D"noopener">full guidance</a> to learn = more. For additional information, visit <a href=3D"
https://www.cisa.gov/new= s-events/news/best-practices-mitre-attckr-mapping" target=3D"_blank" rel=3D= "noopener">CISA=E2=80=99s Best Practices for MITRE ATT&CK Mapping</a>.<=
<p>Please share your thoughts with us through this <a href=3D"
https://cisas= urvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?Source=3DGovDeliveryCy= berDecoysStrengthenDetectionResponse" target=3D"_blank" rel=3D"noopener">an= onymous survey</a>. We appreciate your feedback.</p>
<p>This product is provided subject to this <span><span style=3D"color: #46= 7886;"><a href=3D"
https://www.cisa.gov/notification" target=3D"_blank" titl= e=3D"Notification" rel=3D"noopener">Notification</a></span></span> and this=
<span><span style=3D"color: #467886;"><a href=3D"
https://www.cisa.gov/priv= acy-policy" target=3D"_blank" title=3D"Privacy & Use" rel=3D"noopener">= Privacy & Use</a></span></span> policy.<span style=3D"font-size: 11.0pt= ;"></span></p>
</div>
</div>
</div>
</div>
<style>body {
font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: norma=
l; font-style: normal; color: #333333;
}
</style>
=20
<div id=3D"mail_footer">
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; colo=
r: #757575;">Having trouble viewing this message?=C2=A0</span><a href=3D"ht= tps://content.govdelivery.com/accounts/USDHSCISA/bulletins/42aff90" target= =3D"_blank" rel=3D"noopener">View it as a webpage</a>.=C2=A0<a href=3D"http= s://content.govdelivery.com/accounts/USDHS/bulletins/292141e" target=3D"_bl= ank" rel=3D"noopener"></a><span style=3D"font-size: 10.0pt; color: #757575;= "></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">You are subscribed to updates from the </span><a href=3D"
https://w= ww.cisa.gov"><span style=3D"font-size: 10.0pt;">Cybersecurity and Infrastru= cture Security Agency</span></a><span style=3D"font-size: 10.0pt; color: #7= 57575;"> (CISA)<br></span><a href=3D"
https://public.govdelivery.com/account= s/USDHSCISA/subscriber/edit?preferences=3Dtrue#tab1" target=3D"_blank" rel= =3D"noopener"><span style=3D"font-size: 10.0pt; color: #00568c;">Manage Sub= scriptions</span></a>=C2=A0=C2=A0<span style=3D"font-size: 10.0pt; color: #= 757575;">|=C2=A0=C2=A0</span><a href=3D"
https://www.cisa.gov/privacy-policy=
" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; colo=
r: #00568c;">Privacy Policy</span></a><span style=3D"font-size: 10.0pt; col= or: #757575;">=C2=A0=C2=A0|=C2=A0 <a href=3D"
https://subscriberhelp.granicu= s.com/s/article/Subscriber-Help-Center" target=3D"_blank" rel=3D"noopener">= Help</a><a href=3D"
https://insights.govdelivery.com/Communications/Subscrib= er_Help_Center" target=3D"_blank" rel=3D"noopener"></a></span><span style= =3D"font-size: 10.0pt; color: #757575;"></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">Connect with CISA: <br></span><a href=3D"
https://www.facebook.com/= CISA" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; = color: #00568c;">Facebook</span></a><span style=3D"font-size: 10.0pt; color=
: #757575;">=C2=A0 |=C2=A0 </span><a href=3D"
https://twitter.com/CISAgov" t= arget=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: = #00568c;">Twitter</span></a><span style=3D"font-size: 10.0pt; color: #75757= 5;">=C2=A0 |=C2=A0 </span><a href=3D"
https://Instagram.com/cisagov" target= =3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: #0056= 8c;">Instagram</span></a><span style=3D"font-size: 10.0pt; color: #757575;"= >=C2=A0 |=C2=A0 </span><a href=3D"
https://www.linkedin.com/company/cybersec= urity-and-infrastructure-security-agency" target=3D"_blank" rel=3D"noopener= "><span style=3D"font-size: 10.0pt; color: #00568c;">LinkedIn</span></a><sp=
an style=3D"font-size: 10.0pt; color: #757575;">=C2=A0 |=C2=A0=C2=A0 </span= ><a href=3D"
https://www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A" targe= t=3D"_self"><span style=3D"font-size: 10.0pt; color: #00568c;">YouTube</spa= n></a><span style=3D"font-size: 10.0pt; color: #757575;"></span></p>
</div>
<div id=3D"tagline">
<hr>
<table style=3D"width: 100%;" border=3D"0" cellspacing=3D"0" cellpadding=3D=
<tbody>
<td style=3D"color: #757575; font-size: 10px; font-family: Arial;" width=3D= "89%">This email was sent to
cisa@toolazy.synchro.net using Granicus Commun= ications Cloud, on behalf of: Cybersecurity and Infrastructure Security Age= ncy =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202</td>
<td align=3D"right" width=3D"11%"><a href=3D"
https://granicus.com/solution/= digital-communication-engagement/" target=3D"_blank" rel=3D"noopener"><img = src=3D"
https://content.govdelivery.com/images/govd-logo-dark.png" border=3D= "0" alt=3D"Granicus Communications logo" width=3D"115"></a></td>
</tr>
</tbody>
</table>
<style type=3D"text/css">body .abe-column-block { min-height: 5px; } table.= gd_combo_table img {margin-left:10px; margin-right:10px;} table.gd_combo_ta= ble div.govd_image_display img, table.gd_combo_table td.gd_combo_image_cell=
img {margin-left:0px; margin-right:0px;}</style>
</div>
</td>
</tr>
</table>
<img alt=3D"" src=3D"
https://links-2.govdelivery.com/CI0/010101a0aaf3b541-0= e02cba8-cdd6-485b-b06b-30eb29d394e8-000000/rrGTmH4ewXvcEY1o4uydo3aTAAvBt-sM= HSiY7DONZaQ=3D452" style=3D"display: none; width: 1px; height: 1px;">
</body>
</html>
--===============3761696486986181898==--
--===============7930280733395567782==--