Skip to main content
← Back to Schedule

Who Goes There? Actively Detecting Intruders With Cyber Deception Tools

to View on time.is

Sauganash Ballroom

About this session

The best time to detect an attacker is while they are still inside your environment, before stolen data, lateral movement, or privilege escalation turns a foothold into a breach. Unfortunately, many organizations still learn what happened only after the damage is done.
Attackers follow patterns, and one of the clearest is credential hunting. After gaining access, they search for hardcoded secrets, API keys, tokens, and other credentials that can help them expand control. That behavior creates an opportunity for defenders.
This talk explores honeytokens, lightweight deceptive assets designed to look like valuable credentials but exist only to alert defenders when an attacker interacts with them. Unlike full honeypot environments, honeytokens are easy to deploy, require minimal maintenance, and can be embedded where attackers are most likely to look.
Attendees will learn how honeytokens fit into a modern detection strategy, why they work so well against credential-driven attacks, and how to use them to create early-warning tripwires that surface intrusions before an attacker can do serious harm.

Takeaways:

  • Analysis of recent breaches for common attack behaviors
  • A history of cyber deception and the evolution of honeypots in defensive strategies.
  • Understanding how honeytokens work
  • Maximizing the impact of honeytokens

Presented by

  • Dwayne McDaniel

    Dwayne McDaniel

    Dwayne McDaniel is a Principal Developer Advocate who has been on a mission to "help people figure stuff out" for over a decade. At GitGuardian, he specializes in secrets security and non-human identity governance across cloud and DevOps environments. A frequent speaker at events like DevOpsDays and BSides, he helps security and engineering teams better understand complex issues.