Step 2 of 8 — Set Posture
Step 2 of 8

Set your deception posture

Choose how aggressively HoneyNet populates your environment with deceptive assets. You can change this at any time.

🟢 Conservative
Minimal footprint. High-signal lures only — fake admin accounts and one honeypot credential per major service. Ideal for regulated environments.
4 fake identities 6 false credentials 2 fake S3 buckets 3 decoy routes
🟡 Balanced Recommended
Full-spectrum coverage. Fake identities across Entra ID, honeypot mailboxes in M365, ghost secrets in Secrets Manager, and internal decoy routes. Catches 95% of post-breach movement.
12 fake identities 18 false credentials 8 fake S3 buckets 11 decoy routes
🔴 Aggressive
Maximum saturation. Fake assets seeded at every likely pivot point. Significantly raises attacker cognitive load — any lateral movement touches a lure within minutes.
28 fake identities 41 false credentials 19 fake S3 buckets 24 decoy routes

Deployment scope — Balanced posture

TargetAsset typeCountRotation
Entra IDFake service accounts814 days
M365 mailboxesHoneypot inboxes47 days
AWS S3Ghost buckets w/ fake keys821 days
Internal DNSDecoy hostnames630 days
Secrets ManagerFalse API keys510 days