CISA has published Using Cyber Decoys to Strengthen Detection and Response, a guide to using deception to detect intruders, disrupt their progress, and learn from their behavior. Published on 16 September, it places decoys alongside Zero Trust and gives security teams a framework for putting them to work.
At Tracebit, we welcome that. Helping teams put "assume breach" into practice is why we built our canary platform. We also want to make sure teams reading the guidance see an opportunity they can act on today. Your first useful deployment can be one canary, in one place, with an alert your team knows how to handle.
Canaries help put Zero Trust's "assume breach" principle into practice. If (or rather when) an attacker gets past your defenses, you need a way to detect them inside your environment. A canary credential looks useful to an attacker but has no legitimate business use, so an attempt to use it gives your team a clear signal to investigate.
CISA's Guidance on Cyber Decoys
CISA's guidance on decoy detection makes several points that will be familiar to teams already using canaries:
- Clearer alerts can mean faster detection. The report identifies reducing mean time to detection through high-fidelity alerts as a core benefit. Placement matters: decoys should sit where legitimate users rarely or never interact with them.
- Decoys help expose attackers using ordinary tools. CISA highlights their value against living off the land, where attackers use native tools and legitimate credentials that can be difficult to distinguish from everyday activity.
- Honeytokens provide a strong signal. These are decoy credentials, files, or other assets with no legitimate business use. In CISA's words, "Any interaction strongly suggests malicious or otherwise unauthorized activity." At Tracebit we call these canarytokens.
- Adoption can be incremental. The report describes decoy techniques as cost-effective and scalable, and says organizations can introduce them without major architectural changes.
Together, these points explain why canaries are useful even when an attacker arrives through a route you did not anticipate. Attempting to use a credential that has no business purpose deserves attention, whichever tool made the attempt.
The guide covers a broad range of activities, from straightforward tripwires to controlled environments for studying adversaries. There is room to grow into that framework. CISA itself recommends establishing basic detection capabilities first, and its comparison of honeytokens and honeypots identifies honeytokens as a low-complexity option.
Cyber decoys as psychological traps
There is another benefit we would give more attention: what deception does to an attacker's confidence.
CISA already recognizes the value of making attacks more expensive. Under its "Affect" category, it describes diverting adversaries towards decoy assets, misleading reconnaissance and consuming attackers' time and resources. That creates more opportunities for detection and more time for defenders to respond.
The psychological impact can extend beyond the decoy itself. A human attacker who knows canaries may be present has another question to resolve before using a credential or opening a promising resource: will this help me, or give me away? That uncertainty can affect decisions across the environment. Checking takes time, and proceeding without checking risks an alert. And this psychological effect extends to the AI models, that are essentially trained on human behaviors.
We have seen a practical example at Cresta. During a planned assessment, the security team told the red team that Tracebit was deployed to test the psychological effect of deception. Cresta reported that the red team doubled the length of its engagement. It is a useful illustration of how awareness of canaries can change an attacker's approach.
For malicious AI agents, the corresponding effect is wasted work and uncertainty in choosing the next action. An agent following a convincing false lead may spend additional tool calls, processing time, and tokens investigating resources that offer no route to real data. If it instead spends effort checking for deception, that also has a cost. In our own research, we discovered that when we informed the AI agents attacking our AWS Cyber Range that decoys were present, it drastically reduced their effectiveness in compromising accounts.
Our view is that both effects matter. For an opportunistic attacker seeking a quick win, added time and cost can make a target less attractive. For defenders, time spent investigating decoys is another opportunity to detect and respond. The value of deception includes the work it forces an adversary to do.
AI also helps on the defensive side. Keeping decoys plausible as an environment changes is an ongoing task: names, resources, and apparent business context all need to fit. At Tracebit, we use AI within controlled templates to help adapt canaries to their surroundings, alongside automation that supports deployment and change over time. This makes it practical to maintain convincing deception across a growing environment. We explain that approach in Canaries in the Era of Generative AI.
Acting on this guidance in a single afternoon
For a team getting started, the immediate objective can be small: detect someone trying to use credentials taken from a developer workstation. That gives you a specific place to deploy, an interaction to monitor, and an alert to test. Broader coverage can follow.
You can begin with a much smaller commitment. As we explain in Getting started with your first canary, a first workstation canary can be live in an afternoon. A useful starting sequence is:
- Choose one concern. For example, an attacker harvesting credentials from a managed developer laptop.
- Place one canary. Deploy a canary credential to a pilot device using your existing device management tooling, where an attacker might find it and ordinary work should not use it. It should grant no access to production data.
- Test the complete alert path. Make a controlled attempt to use the credential and confirm that the alert reaches the right person with enough context to investigate. Account for expected interactions from approved tools.
- Agree on the response and then expand. Decide who owns the alert and how they will investigate the affected device. Use what you learn to extend coverage to the next relevant location.
CISA's guidance gives teams a welcome reason to prioritize deception. A working canary gives you a concrete first step. Start with one today, for free, prove the alert works and build from there.

