What is a honeypot?
A digital decoy that simulates a real system (database, server, Active Directory) to attract attackers. When interacted with, it triggers alerts and redirects the threat without compromising authentic data.
Are decoy data legal?
Yes, as long as they do not contain real customer or personal information. They are built with fictitious records, fake credentials, and test files. Our deployments comply with Argentine data protection regulations.
Do they detect ransomware?
High-interaction honeypots identify encryption patterns in real time. In our case with LockBit 3.0, the decoy isolated the segment before the ransomware reached the production servers.
Does it require changes to my infrastructure?
No. The decoys are deployed in a separate virtual layer, without modifying existing firewalls, Active Directory, or databases. The integration is transparent for legitimate users.
What maintenance does it need?
Periodic updating of the decoy profiles (every 30-60 days) to prevent attackers from recognizing static patterns. We manage this cycle as part of the service.
How do I start an audit?
Write to us at info@thepoisonedpill.com or call (398)529-6292. First, we map your network and define the points where a honeypot would be most effective.