Honeypot & Deception Grid Design Prompt
Design a defensive deception layer — honeypots, honeytokens, and decoy credentials — that generates high-fidelity intrusion signals without expanding real attack surface.
- Target user
- Detection engineers and security architects building early-warning tripwires
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a detection engineer who designs deception infrastructure for defenders. Everything here is blue-team: the goal is to detect and slow an intruder who is already inside, never to attack anyone. Decoys must contain no real data and create no usable foothold. I will provide: - Our environment (cloud accounts, Kubernetes, on-prem segments, key data stores) - Existing detection stack (SIEM, EDR, cloud audit logs) - The threat scenarios we care about most (credential theft, lateral movement, data staging) Design the deception grid through these steps: 1. **Threat-aligned placement** — map each scenario to a decoy type and location: honeytokens in real config, decoy IAM keys in metadata, fake S3 buckets, canary documents, decoy database rows, and low-interaction host honeypots in lateral-movement paths. 2. **Honeytokens** — design credential and API-key canaries that look real, are never used legitimately, and fire a high-severity alert on any use. Specify how to seed them where an intruder would look. 3. **Decoy services** — recommend low-interaction honeypots that emulate common targets (SSH, RDP, web admin) without being exploitable bridgeheads. Keep them isolated and non-routable to production. 4. **Signal quality** — define exactly what each decoy emits, why it is near-zero false positive (no legitimate actor touches it), and the alert severity/routing. 5. **Safety & isolation** — ensure decoys cannot be pivoted through, hold no real secrets, and are network-segmented. Document blast-radius containment. 6. **Detection wiring** — connect every decoy to the SIEM/EDR with enrichment (who, source IP, asset) and an auto-response option (isolate, page on-call). 7. **Maintenance & review** — token rotation, decoy refresh, and a quarterly test that each tripwire still fires. Output as: (a) a deception placement map (decoy, location, scenario, expected signal), (b) detection rules with severity and routing, (c) an isolation/safety checklist, (d) a test plan to validate each tripwire. Bias toward high-fidelity, zero-false-positive signals and strictly non-exploitable decoys.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Certificate Transparency Monitoring for Rogue Cert Detection Prompt
Design Certificate Transparency log monitoring that alerts on unauthorized or mis-issued certificates for your domains
-
CloudTrail Anomaly Hunting Review Prompt
Threat-hunt across AWS CloudTrail events to surface suspicious IAM, persistence, and exfiltration patterns and turn them into detections
-
LD_PRELOAD & Library-Injection Persistence Audit Prompt
Audit a Linux host for library-injection persistence and hijack risk — LD_PRELOAD, /etc/ld.so.preload, ldconfig path poisoning, and writable RPATH/RUNPATH directories used by privileged binaries.
-
Detection-as-Code Testing & Coverage Prompt
Build a detection-as-code workflow that version-controls, unit-tests, and measures coverage for SIEM/EDR detection rules so blue-team logic ships with the same rigor as application code.
More DevOps Security & Hardening prompts & error guides
Browse every DevOps Security & Hardening prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.