Honeytoken
Definition
A synthetic credential, document, or data record placed in a monitored location. Any attempt to use or access the honeytoken is an unambiguous signal of unauthorised activity, because legitimate users have no reason to touch it.
- Nature
- Synthetic credential, document, or data record
- Placement
- Monitored location within a system
- Signal value
- Any access indicates unauthorised activity
- Use phase
- Post-incident recovery and monitoring for recurrence
Common questions
Why is a honeytoken considered a high-confidence detection signal compared to other alerts?+
Because it has no legitimate business use, any interaction with it cannot be explained by normal user or process behaviour, which sharply reduces false positives compared to anomaly-based detection methods that flag unusual but sometimes innocent activity.
How does a honeytoken specifically help after a breach has already been contained?+
Placed among restored or monitored systems, it acts as a tripwire that reveals whether an attacker retained access or returned using leftover footholds, which is central to validating that a recovery was actually complete.
Related terms
- Baseline Comparison
- Comparison of a recovered system's current state, including running processes, network connections, scheduled tasks, and file hashes, against a known-good reference state...
- Extended Monitoring Window
- A defined period of heightened detection sensitivity following recovery, during which security operations maintain increased logging, alert thresholds, and analyst attention. Ends...
- Recovery Validation
- The verification process that confirms a restored system is clean, correctly configured, and free from residual attacker access. Distinct from eradication, which...
- Recurrence
- Re-establishment of attacker access or re-execution of the same attack vector after the prior incident has been eradicated. Recurrence triggers the incident...
- Tripwire
- A deliberately placed artefact or detection rule designed to fire only if an attacker returns or residual malware reactivates. Examples include canary...