Skip to content

Tripwire

Definition

A deliberately placed artefact or detection rule designed to fire only if an attacker returns or residual malware reactivates. Examples include canary files, honeytoken credentials, and SIEM rules scoped to previously compromised accounts.

Purpose
Detect reactivation or return of an attacker, not the initial intrusion
Examples
Canary files, honeytoken credentials, scoped SIEM rules
Scope
Bound to previously compromised accounts or assets
Deployment stage
Post-remediation monitoring, not initial detection

Common questions

Why place a tripwire instead of just watching normal logs?+

Normal logging is broad and noisy. A tripwire is deliberately narrow, tied to an account, file, or credential the attacker already touched, so any alert on it carries a much higher probability of being real rather than background noise.

When should a tripwire be deployed during an investigation?+

After containment and remediation, once the environment is believed clean. It answers the question of whether eradication actually worked, so it belongs in the monitoring phase rather than the initial response.

Related terms

Baseline Comparison
Comparison of a recovered system's current state, including running processes, network connections, scheduled tasks, and file hashes, against a known-good reference state...
Extended Monitoring Window
A defined period of heightened detection sensitivity following recovery, during which security operations maintain increased logging, alert thresholds, and analyst attention. Ends...
Honeytoken
A synthetic credential, document, or data record placed in a monitored location. Any attempt to use or access the honeytoken is an...
Recovery Validation
The verification process that confirms a restored system is clean, correctly configured, and free from residual attacker access. Distinct from eradication, which...
Recurrence
Re-establishment of attacker access or re-execution of the same attack vector after the prior incident has been eradicated. Recurrence triggers the incident...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.