{"id":8530,"date":"2026-06-18T17:56:08","date_gmt":"2026-06-18T17:56:08","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8530"},"modified":"2026-06-18T17:56:08","modified_gmt":"2026-06-18T17:56:08","slug":"how-does-deception-based-threat-detection-work-in-cloud-and-hybrid-environments","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8530","title":{"rendered":"How does deception-based threat detection work in cloud and hybrid environments?"},"content":{"rendered":"<div class=\"elementor elementor-40117\">\n<div class=\"elementor-element elementor-element-58cf5e3c e-ecs-flex e-flex e-con-boxed wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-parent\">\n<div class=\"e-con-inner\">\n<div class=\"elementor-element elementor-element-4785a963 ha-has-bg-overlay elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Key Takeaways<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-51f09937 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Deception for cloud environments allows organizations to deploy realistic decoys, fake credentials and deceptive cloud assets on AWS, Azure, Kubernetes and hybrid setups to help improve early detection of attackers.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Modern Cloud deception platforms leverage environment discovery to identify high value assets and strategically deploy deceptive assets where attackers are expected to conduct reconnaissance or lateral movement activities.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Breadcrumbs, fake buckets, fake API keys, all of these are characteristics that allow us to generate high-confidence alerts with very low false positives since legitimate users do not typically interact with these assets.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Cloud deception enhances visibility throughout distributed environments and enables security teams to see in real time how attackers are behaving, how they are using credentials, how they are attempting to escalate privileges and how they are moving around.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Fidelis Deception\u00ae enhances hybrid cloud security by penetrating SIEM, XDR and incident response platforms, and adapting decoys to evolve in the cloud environment for quicker detection and response to threats.<\/span><\/p><\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-0b20bb2 e-ecs-flex e-flex e-con-boxed wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-parent\">\n<div class=\"e-con-inner\">\n<div class=\"elementor-element elementor-element-d15d937 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>The number of workloads being shifted to cloud and hybrid environments continues to grow as organizations increasingly adopt these environments, and the tactics of cybercriminals are evolving to take advantage of these distributed environments. These traditional security methods, like firewalls, anti-virus, and signature-based monitoring systems often fail to identify attackers operating from legitimate network accounts and disguise their activities with stealthy methods. This is where deception for cloud environments can be very useful. In hybrid environments, attackers often move between cloud workloads, on-premises systems, endpoints, and identity services. Deception technology helps organizations detect these movements across interconnected environments before attackers reach critical assets.<\/p>\n<p><a href=\"https:\/\/fidelissecurity.com\/threatgeek\/deception\/what-is-deception-in-cybersecurity\/\">Deception technology is about<\/a> placing realistic but fake digital assets into the cloud and hybrid environment to attract the attention of attackers, identify malicious activity, and alert them to potential compromise. Conventional defenses primarily aim to deter attackers from accessing an organization, while deception-based defenses look upstream to the attacker and try to detect them when they are sniffing around the corners, traveling laterally or gaining access to other accounts to elevate their privileges.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-49991f6 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Understanding Deception Technology in the Cloud<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-8cea1d7 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p><a href=\"https:\/\/fidelissecurity.com\/threatgeek\/cloud-security\/using-deception-technology-in-cloud-environments\/\">Cloud deception<\/a> works by deploying realistic but fake assets across cloud environments to detect malicious activity early. These deceptive assets can include virtual machines, storage buckets, APIs, credentials, containers, and user accounts that closely resemble legitimate resources. When attackers interact with them, security teams receive immediate alerts.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-95a11aa elementor-widget elementor-widget-image\">\n<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-026b061 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">How Deception-Based Threat Detection Works in the Cloud<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-5f1b8fd elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>To understand how deception-based threat detection works in the cloud, it is important to explore the different layers of a deception deployment. The modern <a href=\"https:\/\/fidelissecurity.com\/solutions\/deception\/\">deception platform<\/a> is constantly monitoring the cloud environment, discovering high value assets, and then intelligently seeding realistic deceptive environments where attackers are likely to look for their next target.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-6cf4f7d elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h4 class=\"elementor-heading-title elementor-size-default\">1. Automated Environment Discovery<\/h4>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-1d467ec elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>The first phase typically is automated environmental discovery. This deception platform sweeps workloads, cloud accounts, identities, endpoints, containers, storage systems, and network relationships to get a feel for the organization\u2019s infrastructure. This mapping process can be useful to pinpoint critical systems and common attacker ways.<\/p>\n<p>In hybrid infrastructures, this discovery process also maps connections between cloud resources and on-premises systems, helping security teams <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/deception\/deception-for-lateral-movement-detection\/\">identify potential lateral movement<\/a> paths across the environment.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-1020b19 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h4 class=\"elementor-heading-title elementor-size-default\">2. Deployment of Realistic Cloud Decoys<\/h4>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-41536a6 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>New deception platforms strategically deploy realistic decoys in cloud and hybrid environments to tempt the attacker in the stages of reconnaissance and lateral movement. These decoys can be fake AWS EC2 instances, bogus Azure storage repositories, fake Kubernetes pods, or simulated cloud administrator accounts that resemble real resources. Assessing these assets in areas where attackers are likely to look will establish detection points throughout the environment.<\/p>\n<p>The deception platform instantly generates alerts when attackers engage in these decoys, enabling security teams to <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/xdr-security\/deception-based-early-threat-detection-in-xdr\/\">detect malicious activity at an early stage<\/a>.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-195b3c0 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h3 class=\"elementor-heading-title elementor-size-default\">3. Breadcrumbs and Fake Credentials<\/h3>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-32398f3 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Breadcrumbs and planted credentials are another important point of cloud deception. Attackers commonly search for sensitive API keys, access tokens, SSH credentials, and cloud configuration files during reconnaissance and credential theft activities. Deception platforms are intentionally deployed with fake credentials where attackers are likely to find them. The attackers can use these credentials to access cloud resources, and the security team is immediately notified.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-ec31379 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h4 class=\"elementor-heading-title elementor-size-default\">4. Real-Time Threat Monitoring &amp; Visibility<\/h4>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-6ea67bf elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Deception technology\u2019s monitoring features are particularly potent because they provide real-time insight into attackers\u2019 behavior. Security analysts can watch to see how attackers are moving around, what resources they are attacking, the credentials they are attempting to use, or if they are attempting to move laterally or to escalate privileges.<\/p>\n<p>This visibility becomes especially important in hybrid environments where attackers may attempt to move between cloud workloads, user endpoints, identity systems, and on-premises infrastructure. This is because it offers valuable intelligence, which can help organizations react in advance of any actual systems to compromise.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-0fe7b8b elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h4 class=\"elementor-heading-title elementor-size-default\">5. Automated Incident Response Integration<\/h4>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-fd0f0ff elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Modern deceptions also can be integrated with <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/xdr-security\/xdr-vs-siem-vs-soar\/\">SIEM, XDR, and SOAR<\/a> platforms to automatically respond to deceptions. The platform can automatically isolate endpoints, block sessions, revoke credentials, or trigger incident response workflows in case of suspicious activity. This decreases the dwell time of an attacker and the potential damage that can be inflicted.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-4bab9fe1 e-con-full e-ecs-flex e-flex wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-child\">\n<div class=\"elementor-element elementor-element-75da1463 e-con-full e-ecs-flex e-flex wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-child\">\n<div class=\"elementor-element elementor-element-5cf64497 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-heading-title elementor-size-default\">On-Prem vs. Cloud Deception: Choosing the Right Architecture for Enterprise and Government Security<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-3ff9b57f elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Impact on visibility, control, and compliance<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Key challenges across enterprise and government environments<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">How to choose the right deployment strategy<\/span><\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-53e29e8c elementor-widget elementor-widget-button\">\n<div class=\"elementor-widget-container\">\n<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/fidelissecurity.com\/resource\/whitepaper\/cloud-on-prem-and-hybrid-deception-deployment\/\"><br \/>\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\"><br \/>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Read Now<\/span><br \/>\n\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-25777222 e-con-full elementor-hidden-tablet elementor-hidden-mobile e-ecs-flex e-flex wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-child\">\n<div class=\"elementor-element elementor-element-6ed482ad elementor-widget elementor-widget-image\">\n<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-60a4328 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Benefits of Deception for Cloud and Hybrid Security<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-aefa365 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\">\n<div class=\"elementor-widget-container\">\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Early Threat Detection <br \/> Early Threat Detection is one of the most significant benefits of the deception of technology. It is common for attackers to conduct a lengthy Recon \/ Cred discovery before carrying out destructive activities. These early stages are critical to identification of malicious activity by deception systems, which can allow defenders to act before attackers reach critical systems.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\"><a href=\"https:\/\/fidelissecurity.com\/threatgeek\/xdr-security\/reduce-false-positives-and-ensure-data-accuracy-with-xdr\/\">Reduced False Positives<\/a> <br \/> One of the other key advantages is the decrease in false positives.  Deception alerts are much more effective because legitimate users do not interact with deceptive assets.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Enhanced visibility of devices across hybrid environments. <br \/> Deception technology <a href=\"https:\/\/fidelissecurity.com\/resource\/datasheet\/hybrid-network-visibility-and-security\/\">improves visibility across hybrid infrastructures<\/a> by monitoring attacker activity across cloud workloads, endpoints, containers, identities, and on-premises systems. This helps security teams track attacker movement across interconnected environments more effectively.<\/span><\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\"><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Enhanced incident response and Zero Trust support <br \/> The intelligence collected via deception technology enhances the entire incident of action and security models by bringing active detection capabilities across the environment.<\/span><\/p><\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-14f7c0b elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Fidelis Deception for Cloud and Hybrid Environments<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-c9b0618 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p><a href=\"https:\/\/fidelissecurity.com\/\">Fidelis Security<\/a> provides advanced deception capabilities to inform organizations about the early stages of attack, in cloud and hybrid environments. <a href=\"https:\/\/fidelissecurity.com\/solutions\/deception\/\">Fidelis Deception<\/a>\u00ae features realistic decoys, credentials, breadcrumbs and cloud assets to replicate production workloads, storage, containers, endpoints, and identity services on AWS, Azure, Kubernetes, and on-premises infrastructure.<\/p>\n<p>These types of deceptive assets can be deployed throughout the environment to identify reconnaissance, credential theft, privilege escalation, and lateral movement prior to reaching critical systems. It also continuously identifies and tracks changes in infrastructure to ensure coverage adapts to dynamic cloud environments.<\/p>\n<p>High fidelity detection and wide ecosystem integration make Fidelis Deception\u00ae a valuable addition to hybrid security operations. The platform also creates fake API keys, access tokens, cloud credentials, and other misleading artifacts that result in alerts with very few false positive rates as legitimate users are less likely to interact with the platform.<\/p>\n<p>Security teams have real-time visibility into attacker actions, and integration with SIEM, XDR, SOAR, and incident response platforms allow for automated response actions like endpoint isolation, credential revocation and workflow orchestration. It brings a realistic deception, automation and hybrid coverage to increase threat visibility, rapid detection, and enhance cloud security operations.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-9360e34 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Conclusion<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-f619381 elementor-widget elementor-widget-text-editor\">\n<div class=\"elementor-widget-container\">\n<p>Deception-based threat detection is a proactive cybersecurity solution tailored to today\u2019s cloud and hybrid environment. Using realistic decoys, fake credentials, misleading workloads and clever breadcrumbs throughout distributed environments, organizations can identify attackers when they are trying to find their way into the environment and as they are moving laterally in the system before they cause any real harm.<\/p>\n<p>Cloud deception technologies will be increasingly important as the adoption of clouds grows, enabling organizations to gain better visibility, quicker detection, and longer time before attackers exploit them. Advanced deception platforms offer an extra layer of defense to organizations beyond what they can achieve with their baseline security tools to improve detection precision in complex hybrid environments.<\/p>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-59c68e37 content-align-cta-default elementor-widget elementor-widget-eael-cta-box\">\n<div class=\"elementor-widget-container\">\n<div class=\"eael-call-to-action cta-basic bg-img cta-preset-1\">\n<p class=\"title eael-cta-heading\"><span class=\"eael-cta-title-text elementor-repeater-item-4182408\">Our customers detect<\/span> <span class=\"eael-cta-title-text elementor-repeater-item-49f9954\">post-breach attacks over<\/span> <span class=\"eael-cta-title-text elementor-repeater-item-bb4e738\">9x Faster<\/span> <\/p>\n<p>Detect Advanced Threats Before Damage Escalates TrustedCybersecurity Leader for 20+ YearsSee why security teams choose us over other solutions<a href=\"https:\/\/fidelissecurity.com\/get-a-demo\/\" class=\"cta-button cta-preset-1  \">Request a Demo<\/a><a href=\"https:\/\/fidelissecurity.com\/resource\/datasheet\/deception\/\" class=\"cta-button cta-secondary-button \">Read Datasheet<\/a>\t<\/p><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-16252748 e-ecs-flex e-flex e-con-boxed wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-parent\">\n<div class=\"e-con-inner\">\n<div class=\"elementor-element elementor-element-a42e5b5 elementor-widget elementor-widget-heading\">\n<div class=\"elementor-widget-container\">\n<h2 class=\"elementor-heading-title elementor-size-default\">Frequently Asked Questions<\/h2>\n<\/div>\n<\/div>\n<div class=\"elementor-element elementor-element-6d8bff59 elementor-widget elementor-widget-eael-adv-accordion\">\n<div class=\"elementor-widget-container\">\n<div class=\"eael-adv-accordion\">\n<div class=\"eael-accordion-list\">\n<div class=\"elementor-tab-title eael-accordion-header active-default\">\n<h3 class=\"eael-accordion-tab-title\">How is Fidelis&#8217;s deception solution like cloud assets?<\/h3>\n<\/div>\n<div class=\"eael-accordion-content clearfix active-default\">\n<p>Fidelis Deception\u00ae simulates cloud assets and deploys very realistic decoys that simulate real cloud assets, user accounts, storage resources, credentials, containers, and services on cloud platforms. The decoys mimic the actions and characteristics of real assets and could be appealing targets for actors to engage in reconnaissance, credential theft, or lateral movement activities. The interactions result in high-confidence alerts, which assist security teams to identify threats early; since attackers have a hard time identifying decoys from assets, they are likely to detect them as well.<\/p>\n<\/div><\/div>\n<div class=\"eael-accordion-list\">\n<div class=\"elementor-tab-title eael-accordion-header active-default\">\n<h3 class=\"eael-accordion-tab-title\">What kind of deceptions do you see being applied to cloud or hybrid environments?<\/h3>\n<\/div>\n<div class=\"eael-accordion-content clearfix active-default\">\n<p>The deception in the cloud and hybrid world involves the strategic placement of fake assets, credentials, breadcrumbs and workloads throughout cloud services, cloud endpoints, identities, and on-premises infrastructure. Today, deception platforms will automatically determine the environment, the locations of high-value assets, and the areas where the attackers will look to deploy their deceptions. Through this, unauthorized or malicious activities like reconnaissance, misuse of credentials, privilege escalation, and lateral movement inside distributed environments are detected.<\/p>\n<\/div><\/div>\n<div class=\"eael-accordion-list\">\n<div class=\"elementor-tab-title eael-accordion-header active-default\">\n<h3 class=\"eael-accordion-tab-title\">Why is deception technology effective in hybrid cloud environments?<\/h3>\n<\/div>\n<div class=\"eael-accordion-content clearfix active-default\">\n<p>Cloud environments, on-premises systems, endpoints and identity platforms all exist together, resulting in more attack surface and visibility gaps. The gaps are bridged by deploying realistic decoys multiple times and places simultaneously, which is the essence of deception technology. Legitimate users are not likely to interact with deceptive assets, so high confidence alerts are provided to organizations, reducing the number of false positives, and providing better visibility of attacker activity across the entire infrastructure.<\/p>\n<\/div><\/div>\n<div class=\"eael-accordion-list\">\n<div class=\"elementor-tab-title eael-accordion-header active-default\">\n<h3 class=\"eael-accordion-tab-title\">A hybrid deception architecture is a combination of two or more deception architectures.<\/h3>\n<\/div>\n<div class=\"eael-accordion-content clearfix active-default\">\n<p>A Hybrid Deception Architecture is a security solution that involves the integration of deception technologies in both cloud and on-premises resources to provide a single view of threats. It usually consists of decoy workloads, misleading credentials, mock cloud resources, fragments, and centralized monitoring coupled with SIEM, XDR, and incident response tools. This architecture allows companies to identify attacks across a distributed infrastructure consistently, and to respond and investigate them quickly.<\/p>\n<\/div><\/div>\n<div class=\"eael-accordion-list\">\n<div class=\"elementor-tab-title eael-accordion-header active-default\">\n<h3 class=\"eael-accordion-tab-title\">Is it possible to use deception technology in AWS, Azure, and Kubernetes environments?<\/h3>\n<\/div>\n<div class=\"eael-accordion-content clearfix active-default\">\n<p>Yes. Modern deception platforms can deploy decoys in AWS, Azure, Kubernetes clusters, containers, virtual machines, or cloud storage services, all in multi-cloud and cloud-native environments. It enables organizations to track attacker activity across platforms and be visible in dynamic cloud environments.<\/p>\n<\/div><\/div>\n<div class=\"eael-accordion-list\">\n<div class=\"elementor-tab-title eael-accordion-header active-default\">\n<h3 class=\"eael-accordion-tab-title\">Are false positive results created because of cloud deception?<\/h3>\n<\/div>\n<div class=\"eael-accordion-content clearfix active-default\">\n<p>There are low false positives with cloud deception, because legitimate users don\u2019t engage in interaction with deceptive assets that often. Security teams are more likely to trust alerts because they are more likely to be genuine, as alerts are only generated when a user accesses fake credentials, fake workloads, fake storage buckets, etc.Typically, alerts are only sent when attackers interact with fake credentials, fake workloads, fake storage buckets, or other planted resources, and this increases the likelihood that the security team can trust them.<\/p>\n<\/div><\/div>\n<\/div><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>The post <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/deception\/deception-based-threat-detection-in-cloud-and-hybrid-environments\/\">How does deception-based threat detection work in cloud and hybrid environments?<\/a> appeared first on <a href=\"https:\/\/fidelissecurity.com\/\">Fidelis Security<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Key Takeaways Deception for cloud environments allows organizations to deploy realistic decoys, fake credentials and deceptive cloud assets on AWS, Azure, Kubernetes and hybrid setups to help improve early detection of attackers. Modern Cloud deception platforms leverage environment discovery to identify high value assets and strategically deploy deceptive assets where attackers are expected to conduct [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8531,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-8530","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8530"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8530"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8530\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8531"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8530"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8530"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8530"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}