Learn Cyber Deception!

Learn Cyber Deception!

Source: YouTube · John Hammond · published Dec 20, 2025 · 1:12:48

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This video features Adrien Sanabria discussing the philosophy and practical application of cyber deception as a high-fidelity early detection mechanism, emphasizing that defenders can flip the script on attackers who must be right every time once inside a network 19:0021:17.

Key Takeaways:
• Cyber deception should be viewed as an early detection mechanism similar to a burglar alarm, allowing defenders to catch intruders with simple traps rather than complex, resource-intensive environments 19:0025:03.
• The narrative that "attackers only need to be right once" flips once an attacker is inside a network; the attacker must then avoid traps every single time, while the defender only needs to catch them once 21:1730:32.
• Attackers operate in a "fog of war," forcing them to scan for specific enticing targets like passwords.xlsx, which defenders can exploit using fake credentials and documents 22:0022:44.
• Tools like Canarytokens.org offer free, accessible ways to create web bug or DNS tokens that alert defenders when accessed, potentially slowing down attackers even if the trap is identified 31:3633:34.

Sanabria demonstrates creating a web bug token to show how easily defenders can monitor for unauthorized access to sensitive-looking files 35:33.

Sources:

  • 19:00 Deception as an early detection mechanism
  • 21:17 Flipping the "attacker needs to be right once" narrative
  • 22:44 Exploiting attacker "fog of war"
  • 31:36 Intro to Canarytokens and web bugs
  • 35:33 Demo of triggering a token

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Learn cyber security and focus technical training with just hacking.com, where all-star instructors and industry experts provide hands-on, affordable, and practical learning across courses, free upskill challenges, hackalong training videos, and capture the flag competitions. There's always something to hack with new content twice a month all throughout the year. plus bimonthly live streams. You can sharpen your skills in our ondemand and interactive lab environments. Advance your career and level up regardless of your experience or budget. Forget all the noise and get to just hacking. Sign up now at just hacking.com. Hello everybody. Welcome, welcome back. Welcome to another just hacking training live stream. Hey, super sweet to be hanging out with you all. Happy Friday, happy weekend com…