The #1 Greatest Security Risk: Attackers Breaching Data Through Active Directory
Multiple security applications exist to reduce hacking, and some address it with a computer honeypot. Most try to prevent access to the brain and heart of the network: Active Directory (AD) and Active Directory Certificate Services (ADCS).
Active Directory is the #1 target for attackers trying to take over a network. Once they control it, they can change permissions, expand access, and capture the flag — game over.
Yet few security applications address this weakness directly, even though it is exactly what sophisticated attackers look for.
Security Problems
ADCS abuse goes unseen
ADCS gives attackers a fast path to privilege escalation. Most tools still do not catch certificate abuse through deception or in general, or by using a computer honeypot.
Security teams are left trying to separate legitimate certificate activity from malicious abuse. The volume of alerts (good or bad) creates noise & leaves a dangerous gap around certificate services attack paths.
Active Directory attacks do not stop at one path
Once attackers get access to Active Directory, they can move across multiple attack paths to steal credentials, escalate privileges, and expand control.
Many products catch part of that movement, but not enough to stop the internal pivot before it becomes a domain-wide compromise.
Noise Slows Response
Traditional tools flood teams with alerts that still need investigation before anyone knows what is real. That slows response, buries real attacks in noise, and gives attackers more time to move deeper into the environment.
Deployment is too heavy
Focused identity deception is too often buried inside larger platforms, heavier rollouts, or added infrastructure. Teams need a faster, lighter way to deploy protection inside Active Directory without buying more platform baggage.
Prideful Pricing – WAY too expensive
Many vendors are proud of their products… look at their pricing! But they are unaffordable to the masses, and still bypass the single attack area that hackers love to exploit.
The Big Question
How do you bring the certainty of a computer honeypot into Active Directory — with focused identity deception, deep attack coverage, fast deterministic alerts, and simple deployment — without buying a bloated platform or settling for partial protection?
Introducing…
Credibility
Top Penetration Testers
Built by one of nation’s top professional penetration testers that has consistently hacked Fortune 500 companies. Have hacked over 90% of so-called “secure” systems. Concentrates on the single “Game Over” systems that others miss.
Leadership
Leadership experience includes Senior Vice President at Motorola and Vice President at GE Security. The team has worked with Microsoft, IBM, Apple, Sony, Adobe, Intel, HP, 3M, Citrix, VMware, Fort Knox, and the Louvre across hundreds of engagements, from small organizations to the Fortune 500. Certifications include OSCP, CRTO, CASP+, and ARTE.
Concentrates on Active Directory
#1 target for attackers trying to hijack a network.
Best Solution
Five main reasons to consider Claymore Labs Directory Decoy
- The ONLY Purpose-built Identity Deception for ADCS Honeypots
- Deeper Active Directory Attack Coverage
- Sub-2-Second Detection & Near-Zero False Positives
- Simple, FAST, Lightweight Deployment
- Price Performance Leader
1. ONLY Purpose-Built Identity Deception for ADCS Honeypots
No commercial product—and only one early-stage open-source tool covering ESC1 alone—offers deceptive certificate templates, leveraging a computer honeypot as a detection mechanism.
Claymore Labs Directory Decoy is the first and only product to successfully deploy ADCS honeypot templates covering ESC1 (SAN abuse), ESC3 (Enrollment Agent abuse), and ESC6 (EDITF flag abuse). Unlike a traditional computer honeypot, Directory Decoy places deception directly inside the directory and certificate-service attack paths sophisticated attackers love to exploit.
ADCS ESC1 Honeypot
Catch attackers probing ESC1, the most common ADCS escalation path, before certificate abuse turns into dangerous privileged access
ADCS ESC3 Honeypot
Expose enrollment agent abuse through deceptive templates built to catch a specialized privilege-escalation path.
ADCS ESC6 Honeypot
Trap attackers exploiting CA-level misconfigurations through deceptive templates tied to EDITF_ATTRIBUTESUBJECTALTNAME2 abuse.
More Computer Honeypot Certificate Templates
Also supports ESC2, ESC4, ESC9, ESC13 and more.
Safe-by-Design Architecture
Delivers realistic-looking certificate templates that cannot issue real certificates. Zero risk of the computer honeypot itself becoming an attack vector–keeping the deception effective without introducing new risk.
2. Deeper Active Directory Coverage
Claymore Labs Directory Decoy provides broader and deeper AD attack coverage. Help security teams catch the dangerous techniques that turns a routine breach into a domain-wide control… a “game over” event.
Directory Decoy uses computer honeypot objects that have no legitimate business use, so any interaction is a trigger – confirmed hostile.
DCSync Detection
Tripwire objects that alert on unauthorized directory replication requests. Helps expose attempts to pull password hashes from the domain controller.
Kerberoast Detection
Decoy SPN service accounts that catch attackers requesting Kerberos tickets for offline cracking, exposing credential theft early.
AS-REP Detection
Decoy accounts with Kerberos pre-authentication disabled. Helps catch attackers harvesting AS-REP hashes for offline cracking.
Pre-Windows 2000 (Pre2k) Detection
Legacy-style decoys that catch abuse of older Active Directory weakness. Helps surface an attack path that is often overlooked.
Resource-Based Constrained Delegation
Decoy computer honeypot objects catch attackers trying to impersonate privileged users through delegation abuse. Detects a dangerous lateral-movement path before attackers can move deeper into the network.
3. Sub-2-Second Detection & Near-Zero False Positives
Security teams are tired of noisy alerts and slow investigations. Claymore Labs Directory Decoy honeypots generate deterministic, high-confidence detection.
When an attacker touches a fake certificate template or another deception object with no legitimate use, the interaction provides an immediate indicator of compromise. That means faster response with less guesswork.
Deterministic Detection
Detection fires when an attacker interacts with a deception object that has no legitimate use. Once honeypotted, the attacker has revealed real behavior instead of merely triggering another uncertain anomaly.
Near-zero False Positives
Uses deception artifacts with no legitimate business use, so accidental alerts are rare by design. Helps analysts trust the signal and respond faster.
Near Real-Time Computer Honeypot Alerting
Delivers sub-2-second alert speed after a tripwire is touched. Helps teams respond while the attacker is still moving, not after the damage spreads.
Actor Attribution
Every alert shows the exact account, timestamp, and source context, giving analysts an immediate place to start without extra correlation.
Optional Automated Containment
Alert-only or auto-disable response modes, with temporary or manual re-enable options. Helps stop attacker movement fast with guardrails, audit logs, and break-glass control.
Webhook-First Integration
Send events to any SIEM, ticketing, paging, or email/SMS system. Your SOC stays in your tools. Claymore Labs Directory Decoy focuses on the signal; you choose the workflow.
PSA Integrations
Sends Directory Decoy alerts directly into PSA tools like ConnectWise. Keeps detections inside the MSP’s normal ticketing workflow so teams can respond faster without checking another console.
4. Simple, FAST Lightweight Deployment
Claymore Labs Directory Decoy delivers focused identity protection without the drag of added hardware, long rollouts, or broader platform complexity
Lightweight deployment on servers rather than on every workstation. Keeps setup fast and operational overhead low.
Standalone Product
Works on its own, so value does not depend on buying into a larger platform. This simplifies evaluation and adoption.
SaaS Deployment
Delivered as a cloud-based service, so there is no heavy infrastructure to stand up or maintain.
Blistering Fast Setup Time
The first honeypot deployment typically takes under 15 minutes, with lightweight agents installed on domain controllers and certificate authorities. Protection goes live quickly instead of dragging into a long implementation.
Lightweight Footprint
Uses lightweight agents, requires no additional hardware, and keeps CPU overhead at 0.01% or less, minimizing operational friction
5. Price Performance Leader
Enterprise deception products range from $10,000 per year for stand-alone, to $50,000 – $200,000 annually when you are locked into platform bundles requiring the entire stack. Without strong Active Directory deception!
Claymore Labs Directory Decoy delivers deeper Active Directory deception than any of these products–at a fraction of the cost.
Near-Zero Operational Overhead
Set it and forget it deployment with minimal ongoing tuning. Unlike SIEM rules that require continuous refinement, honeypots don’t need updating because they don’t rely on behavioral baselines.
Minimal Infrastructure Cost
Lightweight SaaS delivery with low operating overhead. Helps keep costs down as usage grows.
6. Built for IT and MSP/MSSP
Multi-Tenant Operations from day one. Claymore Labs Directory Decoy wasn’t retrofitted for multi-tenant delivery. The architecture was designed for IT, but also from the ground up for MSPs and MSSPs managing hundreds of client environments.
Unlike Thinkst Canary (separate consoles per client), Acalvio (partial multi-tenancy), or platform-locked solutions (SentinelOne, Zscaler), Directory Decoy provides a true MSP operational experience.
Multi-Tenant Console
Single dashboard to manage all client environments. Full visibility across every client—no console-hopping, no API aggregation workarounds.
Lightweight DC-Only Agent
Deploy on domain controllers and certificate servers—not every endpoint. Radically faster time-to-deploy vs full endpoint agent rollouts. Minutes per client, not days.
Vendor-Agnostic Architecture
Works regardless of EDR/XDR stack. Your clients’ choice of CrowdStrike, SentinelOne, Microsoft, or other EDR doesn’t matter. Claymore runs independently.
Standardized Deployment Patterns
Repeatable honeypot configurations create consistent deployment plays across client environments — the same quality every time, for every client.
How Does It Compare?
- The ONLY Purpose-built Identity Deception for ADCS Honeypots
- Deeper Active Directory Attack Coverage
- Sub-2-Second Detection- Kills False Positives
- Simple, FAST, Lightweight Deployment
- Price Performance Leader
Click HERE or image to enlarge..
What’s Holding You Back?
Now that you can see the advantages of Claymore Labs Directory Decoy, what’s holding you back? Following are common questions…
"We already have Microsoft Defender for Identity with our E5 license."
Great—MDI is a solid baseline. But MDI’s honeytokens are rudimentary: you manually tag existing accounts, and that’s it. There’s no automated honeypot creation, no ADCS deception, and no multi-tenant MSP console.
MDI’s Kerberoasting detection relies on network traffic analysis, which has documented bypasses (Synacktiv demonstrated that separating the LDAP query from the SPN request with a time delay evades detection).MDI users also report tuning challenges with false positives from AD Connect and MSOL accounts. Claymore doesn’t replace MDI—it fills the gaps MDI can’t reach. They’re complementary.
"We already use Canary or another deception tool."
Thinkst Canary is excellent at what it does: network-level deception with fake file shares, routers, and SSH services. But it has no Kerberoasting, no AS-REP roasting, no DCSync, no ADCS, and no Pre2k honeypots. Canary catches lateral movement at the network layer.
Claymore fills in the massive gaps others miss, such as identity-layer attacks that lead to domain compromise. You’d use both—Canary for network deception, Claymore for identity deception. Different attack surfaces, complementary coverage.
"What if we already have EDR, SIEM, or XDR tools?"
That is fine. Claymore still fits because it supports SIEM/SOAR export, API integrations, and EDR/XDR integration. It can strengthen the stack you already have instead of replacing everything as it runs independently.
"Can attackers avoid honeypots?"
CrowdStrike has publicly stated that ‘attackers have been bypassing honeypots for over 25 years.’ That’s true, for obvious network honeypots.
Claymore’s identity-layer honeypot lures are designed to blend into AD with realistic metadata, backdated timestamps, and believable group memberships and more.They are architected to be indistinguishable from real AD objects, so they are near impossible to filter out during attacker reconnaissance. And once triggered, the attacker is instantly caught.
"Claymore is new, how do we know it works?"
The concepts behind it are not new. Kerberoasting honeypots, DCSync detection through deception, and honeytoken-style traps are already well-establish. What is new is packaging them into a focused platform with stronger ADCS deception and simpler deployment as a multi-tenant managed service with ADCS coverage nobody else has built.
"We’re worried about agents on domain controllers."
That is a fair concern. Its agent is designed to be lightweight, with low CPU overhead, no hardware requirement, and a smaller footprint than broader tools that depend on heavier endpoint deployment. Claymore’s DC-only deployment is actually the lightest touch in the category. The goal is to add focused detection on the systems that matter most without creating unnecessary operational drag.
Your Old Life
An attacker starts poking around your identity environment. Your existing tools send a wave of alerts, but nothing feels certain. Your team spends time sorting noise from signal, trying to figure out whether this is a false alarm, a misconfiguration, or a real attacker.
Meanwhile, techniques like DCSync, Kerberoast, or certificate abuse keep moving in the background. The attacker penetrates your Active Directory, assigns himself admin rights–GAME over.
Your New Life?
Now imagine the same environment with Claymore Labs Directory Decoy in place. The attacker touches a lure they should never see–they tripwire is triggered! No false positives, no delays–you KNOW you’ve been violated.
Within 2 seconds, your team is alerted, the offending account is disabled and the nasty intruder is FLUSHED.
They cringe. You smile. Life is good!
Now that you can see the advantages of Directory Decoy, what’s holding you back? Following are common questions…
Contact Me Please
Please complete the information below and we will contact you soon to answer any questions, give a demo, or a quote. Thank you!

























