Skip to content

Honeytoken

Definition

A synthetic credential, document, or data record placed in a monitored location. Any attempt to use or access the honeytoken is an unambiguous signal of unauthorised activity, because legitimate users have no reason to touch it.

Nature
Synthetic credential, document, or data record
Placement
Monitored location within a system
Signal value
Any access indicates unauthorised activity
Use phase
Post-incident recovery and monitoring for recurrence

Common questions

Why is a honeytoken considered a high-confidence detection signal compared to other alerts?+

Because it has no legitimate business use, any interaction with it cannot be explained by normal user or process behaviour, which sharply reduces false positives compared to anomaly-based detection methods that flag unusual but sometimes innocent activity.

How does a honeytoken specifically help after a breach has already been contained?+

Placed among restored or monitored systems, it acts as a tripwire that reveals whether an attacker retained access or returned using leftover footholds, which is central to validating that a recovery was actually complete.

Related terms

Baseline Comparison
Comparison of a recovered system's current state, including running processes, network connections, scheduled tasks, and file hashes, against a known-good reference state...
Extended Monitoring Window
A defined period of heightened detection sensitivity following recovery, during which security operations maintain increased logging, alert thresholds, and analyst attention. Ends...
Recovery Validation
The verification process that confirms a restored system is clean, correctly configured, and free from residual attacker access. Distinct from eradication, which...
Recurrence
Re-establishment of attacker access or re-execution of the same attack vector after the prior incident has been eradicated. Recurrence triggers the incident...
Tripwire
A deliberately placed artefact or detection rule designed to fire only if an attacker returns or residual malware reactivates. Examples include canary...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.