Monitoring honeypot (honeytoken) identities
Monitor honeypot identities with Vectra Threat Intel to detect activity over RDP, SMB, RPC, NTLM, and Kerberos.
Steps to Enable
1. Create STIX 1.2 File
2. Enable Monitoring in the Vectra UI


3. Examine Threat Intelligence Alerts

4. Update the Threat Feed with new STIX 1.2 files as the desired indicators change


Attachments
Last updated
Was this helpful?