In the red team at @srlabs@infosec.exchange we became increasingly frustrated with ineffective detection and response for the late stages of our hacking attacks.
The frustration became high enough to develop an internal honeypot / deception strategy that would be good enough to catch us.
It's finally ready and together with my colleague Niklas van Dornick, I'll be at @WEareTROOPERS@infosec.exchange next week to present it!
We'll tell you why expensive deception tooling is often a waste of money and how we developed an internal honeypot that looks too juicy to ignore for attackers.
PS: implementation is _almost_ done, see you next week :)