Talos Takes
Every two weeks, host Amy Ciminnisi brings on a new guest from Talos or the broader Cisco Security world to break down a complicated security topic. We cover everything from breaking news to attacker trends and emerging threats.
Talos Takes
Honey, I Trapped the Adversary
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
It’s time to start having fun and messing with your attackers. For Cybersecurity Awareness Month, Martin Lee joins Amy to discuss the fine art of making life on your network a complete nightmare for adversaries. Simple, low-maintenance decoys — like fake credentials, empty honeypots, and ghost systems — can turn your infrastructure into a minefield that keeps attackers guessing and wastes their resources.
Join us to learn how to turn the tables, gain threat intel on who is trying to get into your network, and have a bit of a laugh at their expense. (And trust us, you don't want to miss Martin's Winston Churchill impression.)
Welcome to the Talos Takes podcast, where we discuss Talos' latest research and security news. This podcast is for everyone, from the C -suite to the front lines.
Amy CiminnisiHello and welcome to this special Cybersecurity Awareness Month episode of Talos Takes. Hope you've been having a lovely October. Here at Talos, we are spending this month studying the fine art of frustrating the adversary. We often discuss kind of this race between the defenders and the attackers through the lens of total prevention. So trying to construct a wall that the adversary can't climb over. But let's explore why we should be creating friction, making their life on your network a living hell as painful, as slow, as expensive as humanly possible. So Martin Lee is back to talk about how we can implement some of these strategies. And more importantly, how you can do it practically without creating this mountain of extra maintenance for your team.
Amy CiminnisiFor those in the know, Martin Lee is no longer with Talos. He's back in wider Cisco, but I managed to snag him for another episode. So welcome back, Martin.
Martin LeeThank you. Thank you so much.
Amy CiminnisiWell, there are so many ways to frustrate an adversary. You've talked about them multiple times before. Um, you know, from the simple canary tokens and honey credentials to more advanced things, AI honey pots, fake ID objects. Um when a team is kind of looking at all of these options in front of them, how do they decide where to start? It's kind of like you're trying to boil the ocean.
Martin LeeRight. I the place to start is to think about what actually is a cyber attack. So I'm afraid we'll have to go into a theoretical metaphorical conversation. Um, you know, cybercrime is an economic crime. This is this is where we start that the attacker believes that they're going to get value from their target in excess of the the value of the resources that they have to expend to get in there. So um it's clearest in um in a cybercrime attack, if someone's going into your systems to steal data, it's because they think that they can get money from reselling that data. And in fact, they're going to have um an easier and more profitable life by working as a as a hacker, hacking into systems than than they would flipping burgers or something or something similar. Fundamentally, that's what we're doing.
Martin LeeSame, uh very similar when it comes to a nation-state attack. The nation-state believes that the value that it can get from um getting inside a situation, uh, an organization or a system and achieving certain objectives is worth the cost that it takes of getting in there. So that involves, you know, hiring people, having infrastructure, investing time in developing malware or learning techniques. All of this costs.
Martin LeeSo if we want to frustrate the attacks, what we want to do is we want to make it as expensive as possible for the attacker to get inside um the organization and fulfill their objectives. So this for me is is where the uh honeypots and the honeypot approach really um applies. What we want to do is lay decoys. So decoy systems, things that that look like the type of juicy system that an attacker is going for, that in fact is is completely fake and is under your control. Um, these might be external to your environment or internal in your environment. But the important thing is they look and behave similar to what the attacker is expecting to find. Um, same with uh people, uh, create fake profiles, um, you know, create fake social media presence, create fake email addresses, um, or use expired domains um that you might have, or buy expired domains.
Martin LeeBut anything that looks like a nice juicy target for for the bad guy, firstly, it's going to chew up their time. It increases their their their expenses. This is this is our first benefit. Secondly, when the attacker interacts with your honeypot, they're telling something about themselves. At the very simplest, they're giving away the fact that they're actually conducting an attack. Um, and that you can see this. So already, this is this is an alert, this is threat intelligence. This is telling you something is happening here. How the attacker interacts with your honeypot also tells you um about how they are conducting the attack. So you get to know that there's an attack in progress, um, or at least being being prepared, you get to know how the attacker is um is attacking, and this you can use to boost your defenses.
Martin LeeSo um think about it in terms of slowing down the attacker, making life expensive for them in chewing up their time, and also in terms of generating threat intelligence for yourself that you can then use. And of course, don't forget threat intelligence is only any value if you actually put it to good use.
Amy CiminnisiYes. And I feel like part of this um decision that people have to make on, you know, what route to go down is like the ability to maintain it, right? Everyone is already overspent as it is with their resources. No one wants to spend their entire day like managing fake objects or things like that. Um, so how how do you approach these various impediments so that they're like actually practical and low maintenance and don't create more work for the security team than they do, you know, for the attacker who's the person we're trying to make more work for?
Martin LeeWell, the great thing about fake objects is they don't do anything. Um, you know, go create a fake, a fake executive, you know, put put put their profile on uh on LinkedIn, write a couple of blogs in their names. You know what? That fake executive doesn't have any expense reports, doesn't need travel uh organizing, isn't going to you know, create an HR incident or whatever. They don't do anything, they're just they're just fake, they just sit there.
Martin LeeUm, so in terms of things, um, certainly um fake profiles and fake individuals, you really don't need to do anything. It's a very low value investment um in time. Create a social media profile, create um uh a bit of engagement on social media, perhaps a blog, put their email address somewhere, and then just forget about it. And maybe in a year's time you might do something to make them look like they they've they've done something. But you the the the great thing is you don't need to do a lot. Um same thing goes for fake email addresses that you're that you're creating that um attackers might be looking or spidering. Um stick a an email address somewhere, maybe on your website, maybe on a post, it doesn't really matter, just stick it somewhere, wait for a bad guy to find it. Even better if um it it starts with A. So Aaron Aardvark is a very, very good um uh persona. Um, because if attackers are going through email addresses from A to Z, which they often do, that's the one that's going to get the attack first. Um, you know, maybe not as obvious as Aaron Aardvark, but if you wanted to create a um uh a fake persona whose first name and surname begin begins with A. Um and put that somewhere. Yeah, have fun with it. And then wait, you know, just set up automatic uh monitoring of their of their email address. Um and any emails that come through, because you know that this is a fake employee that doesn't do anything, they can't subscribe to email lists, they can't email contacts, sales, partners, customers, whatever. Anything that comes through, you know, is spam or is malicious in some format. And if it's come through your your email filters, you know you need to update your email filters, you need you need to um to to to block something. Now, this can become a time-saving um process because if you're collecting the phishing attacks first and you're updating your spam filters to say, oh dear, this this shouldn't have come through. I'll block that. And tell you what, any of these emails that have actually gone through to an inbox, I need to remove, you're then reducing the possibility of your of your users clicking on that phishing attack, engaging it with it, leaking with credentials, which is then gonna require you to respond to an incident, change their change their their login credentials, kick them off, you know, log them out of their sessions, etc. etc., which is time consuming. Just a little tiny bit um of investment up front makes your life easier. It's not gonna attract every single phishing attack or everything which is coming through, but it'll attracts some and it gives you that heads up.
Martin LeeVery, very similar um issue when it comes to fake systems. If you're setting them up, you know, create a fake document um server. Nobody uses it. This is the whole point. As soon as someone engages with it, you know that it's bad. Um, kick the device off the network, quarantine it because you know that something that shouldn't have happened has happened. So you're saving yourself time by detecting things early. Um, other things, you know, seed some API keys for a you know very low-value honey pot cloud environment. So if somebody steals those, again, you know that you've got an incursion. You've know that you've got a problem. And it's giving you a heads up and a head start on resolving um an incident and stopping that incident becoming worse. Because the the the later you discover an incident, the more mess there is, the more cleanup, the more timing that it's going to be.
Amy CiminnisiYeah. Um, and you have specifically written about AI honeypots before. So talk to me a little bit about this. In in this time when so many adversaries are trying to use AI to speed up their own operations or to automate them. Um, how does it help us stay ahead?
Martin LeeWell, we're using the attacker's tools against them. Um, you know, if an attacker is using AI to um crawl across your networks and systems and discover them, well, great. Let's just use AI to create fake systems for their fake aid, for their AI agent to discover and engage with. And we're just chewing up those resources um of the attacker. So there, for a long time, there's been all sorts of software projects about creating honeypots. So these are systems that that look like genuine systems to a bad guy, um, but in fact are used for collection of threat intelligence um by by defenders and also for chewing up the the time of the uh of the attacker. The difficulty is um uh honeypots aren't real. You know, if you know what you're doing and you engage with a honeypot, it doesn't take you enormously long time to work out that there's something not right here. It's kind of like engaging with uh with a fake AI customer service agent, you know, uh only a few minutes before you realizing, hang on, you're a robot, aren't you?
Amy CiminnisiYep.
Martin LeeSo if you have a skilled individual, a human, maybe it's gonna take them three minutes, five minutes tops to discover that they're that they're engaging with with something which isn't quite right. AI agents don't have this awareness. So we can use those capabilities uh or that lack of capability and lack of awareness against the AI agents. Um, like you can have a fake customer talking to a fake customer service agent and they'll just ping-pong between each other, you know, forever, neither of them aware that they're that they're engaging with a with a robot.
Martin LeeSo software projects that create honeypots and like like genuine honeypots, um uh are a thing. They're really, really good. However, as with any software development, it takes a while to develop the software to something which looks um um reasonable, behaves reasonably. Great thing about AI is that speed of development. If you're creating a mission critical application, you know, like maybe AI development vibe coding isn't necessarily what you want, you know, that there's two schools of thought on this.
Martin LeeBut when you're creating a honeypot, it doesn't really matter. Um, and we can actually, in the same way that you can, I mean, sometimes I don't know about you, but um sometimes when I procrastinate, I ask an AI agent, you know, be Gandalf and give me um you know wisdom to to encourage me on my quest. And it and it talks to me in the guise of Gandalf. Um, or something like Winston Churchill is another one, it'll give me a long speech about don't you don't waste a second, young man of your precious life. You know, and it goes and it goes on like that. And it and it's great fun. But in the same way, we can also get the AI to say, pretend that you're a Linux kernel and talk to it using Linux commands. Um or as I wrote in the blog, pretend to be a smart fridge. And um it'll spin up a file system that looks like a smart fridge.
Martin LeeIt's not going to fool anyone who knows what they're what they're doing or what they're looking for for longer than two minutes, but it will fool an AI agent, and that's what you've got to do. Ties up the attacker's resources, tells you that there's someone in your environment looking for something, and tells you what they're doing, how they're doing it, and what their IP address is.
Amy CiminnisiYeah, I mean, that's pretty fantastic for, I would say, relatively little work other than the upfront cost of setting it up. Yeah. That's fantastic.
Martin LeeAnd the great, the great thing, you know, approach approach these things as disposable. Um, it's something you can run up in a morning. Um, you know, don't think of it as as a long-term thing that's really absolutely going to protect your um you know, your your precious AI-enabled fridges or if alarm and or make it you know look like a nuclear power station. Um that's not what it's for. It's about giving you an early heads up. Yeah, something's wrong, something's engaging with my honeypot that superficially looks like a key system. Um, that should ring alarm bells. We we need to um set off our instant response um procedure here because we can we can detect it early.
Amy CiminnisiYeah, and I'm sure for people it is kind of hard to quantify like how much time an attacker didn't spend on our network because of a tar pit or honey credentials. So, like, how should teams be thinking about like measuring the success of these things? Is it, you know, the information that you are able to get from an adversary interacting with it? Is it the lack thereof? Um, what what are your thoughts?
Martin LeeI would justify it to management that every interaction you get with a threat actor with your honeypot is an interaction that wasn't made with a key system. And if you can frame it in that way, is we we, you know, this attacker was looking for an executive, or this attacker was looking for part of our critical national infrastructure. Instead, they found a fake profile, they found a fake system. So that attack was actually thwarted. Um and and that that's the real benefit. And when you start framing things in those ways, um, if you know the average cost of um resolving an incident when it's affected your key system or when it's got access to the company bank account, um, and you can point out, well, actually, we saved you this. That's that's where you really start demonstrating return on investment for these things.
Amy CiminnisiWow. Any any final words of wisdom, things that you'd like to say?
Martin LeeI think most importantly, have fun. It's a laugh. I love setting breadcrumbs like like this. Um, and I think in you know, in a world, and I think we're moving to that eventually, where where all the attackers are agentic AI, yeah, if we're using AI to create a world full of fake systems, the whole premise of cyber attacks falls down because if you've got you know 100 systems and only one of those is genuine, you never go, you know. It's like you've got a 99% chance of not getting it right, of one in a one in a hundred chance of of connecting to the right system. Suddenly, yeah, cyber attacks become untenable because all you're doing is interacting with um uh with fake systems. Um, you know, it's a lot of social media now is also fake uh profiles saying fake things, and you can spend your life, you know, arguing politics with a fake uh um AI uh propaganda bot. I mean, why, why, why bother? Just set up another fake um AI propaganda bot and happily each other.
Amy CiminnisiThank God I'm not like 14, 15, or 16 in this time when like I used to spend so much time arguing on the internet.
Martin LeeYeah, yeah, yeah, absolutely. Um yeah, why? Don't don't don't even bother. But but we can tie up the resources of those who who who are doing that, make it a less lucrative um attack for them. Um and yeah, and have fun.
Amy CiminnisiYeah.
Martin LeeHave fun. Be alive.
Amy CiminnisiHow often do you get to mess around with attackers like this? Come on.
Martin LeeDo you know what I think it's like people take AI seriously and think AI is like this fountain of wisdom, you know, giving them information. We need to be reverential to it and polite because it's going to take over the world. It's like, no, get into this stupid stuff, you know. Train the AI to be a fridge, train it, you know, train it to be a fake nuclear power station, um, you know, a fake pump, uh a dam, you know, whatever. Um, or or a fake executive, um, a fake uh executive assistant who has budgetful budgetary control. Um, yeah, create create use use AI for laying traps for the bad guys.
Amy CiminnisiMartin, thank you so much for joining me today. We miss you so much, but it was great to have you back.
Martin LeeOh, it's lovely talking to you. Yeah, it's great.
Amy CiminnisiYeah. Well, listeners, we have so much planned for this month. We have a blog with contributions and advice from different researchers out, including Martin. I'll put the link to that in the notes. Um, we have several videos, podcasts, and at the end of the month, we also have the IR quarterly trends report coming out. So stay tuned. A lot of useful info is coming your way. Thanks for listening and stay safe out there.