Deception & Operations Planning Frameworks

Russell Handorf

ShmooCon XX (Final) · Day 2 · Bring It On

Overview

In an era where ransomware attacks are rampant and data breaches are a common headline, traditional security measures often fall short. Russell Handorf's ShmooCon talk, "Deception & Operations Planning Frameworks," challenges the prevailing "checkbox security" mindset, advocating for a sophisticated, strategic approach to defense: deception operations. Handorf argues that while foundational security is indispensable, advanced adversaries necessitate a proactive and intelligent strategy to misdirect, delay, and gather intelligence on threats. This talk moves beyond the simplistic concept of a Honeypot, positioning deception as a comprehensive, well-planned military-style operation designed to protect critical assets and identify malicious actors.

Watch on YouTube

Visual summary for Deception & Operations Planning Frameworks by Russell Handorf
Visual summary for Deception & Operations Planning Frameworks by Russell Handorf

Key moments

  1. 0:00 Introduction and current industry challenges
  2. 2:10 Reintroducing the 'little pink book' for deception
  3. 4:00 The benefits and pitfalls of deception operations
  4. 5:30 Deception operations are more than just honeypots
  5. 6:00 Essential questions for planning deception operations

Deception & Operations Planning Frameworks

Speakers: Russell Handorf, Security Professional

Conference: ShmooCon

YouTube: https://www.youtube.com/watch?v=yIutY_2FcU

Overview

In an era where ransomware attacks are rampant and data breaches are a common headline, traditional security measures often fall short. Russell Handorf's ShmooCon talk, "Deception & Operations Planning Frameworks," challenges the prevailing "checkbox security" mindset, advocating for a sophisticated, strategic approach to defense: deception operations. Handorf argues that while foundational security is indispensable, advanced adversaries necessitate a proactive and intelligent strategy to misdirect, delay, and gather intelligence on threats. This talk moves beyond the simplistic concept of a Honeypot, positioning deception as a comprehensive, well-planned military-style operation designed to protect critical assets and identify malicious actors.

Handorf's presentation is particularly insightful because it grounds theoretical concepts in a highly relatable and entertaining real-world scenario: managing trespassers on his 140-acre property. This unique analogy allows him to illustrate complex cyber security principles, such as infrastructure knowledge, adversary profiling, and operational planning, through the lens of physical security challenges. By detailing his journey from basic land management to deploying sophisticated technical and social engineering deception tactics, Handorf provides a practical framework for developing and implementing effective deception strategies in any domain, emphasizing commitment, meticulous planning, and a deep understanding of the adversary.

The core message is a call to action for defenders to evolve their thinking. Instead of merely reacting to threats or implementing solutions without understanding, organizations must embrace deception as a force multiplier. This involves not just deploying tools, but crafting a deliberate strategy that integrates technical measures with psychological manipulation, ultimately creating an environment where adversaries are forced to reveal themselves and expend resources, giving defenders the critical advantage needed to protect their "crown jewels."

Background

▶ Watch: Introduction and current industry challenges (0:00)

The roots of modern information security, as Handorf points out, can be traced back to foundational documents like the Rainbow Books, a series of computer security standards developed by the U.S. National Computer Security Center (NCSC) in the 1980s. These seminal works laid the groundwork for many day-to-day controls now taken for granted, including log analysis, access controls, and role-based access control. Crucially, Handorf highlights a lesser-known volume, the "little pink book," officially titled NCSG 030: A Guide to Understanding Covert Channels Analysis of Trusted Systems. Published over 21 years ago, this guide delved into deception operations from a technical perspective, examining how CPU and memory architectures could be manipulated to deceive adversaries and detect anomalous activity. It introduced concepts that, while foundational, have largely been overlooked or poorly implemented in the mainstream.

Despite these early insights, the contemporary cybersecurity landscape is fraught with challenges. Handorf laments the persistence of ransomware attacks, the commonplace nature of breach notification settlements, and a prevalent "cargo cult mentality" where organizations purchase and implement security solutions merely to check a box, without truly understanding their purpose or efficacy. He also notes the unreliability and inconsistency of external security assistance, leading to a cycle of repeating the same mistakes. The fundamental issue, Handorf asserts, is that many organizations still fail to get the basics right—a robust infrastructure, comprehensive inventory management, reliable log analysis, and a clear understanding of their network's normal operational cadence. Without these fundamentals, any advanced security measure, including deception, is destined to fail, becoming little more than an "another IDS that's just spamming them with noise."

Handorf underscores that a deception operation is not merely a Honeypot. While a Honeypot is a single system or network segment designed to attract and trap attackers, a deception operation is a holistic, strategic endeavor. It requires deliberate intent, a clear definition of objectives, an understanding of the adversary, and a robust plan for deployment, management, and eventual dismantling. The problem, as Handorf sees it, is that many commercial deception tooling vendors focus on selling a product rather than enabling a comprehensive strategy, leading to frustration and disengagement among security engineers who are left to manage yet another source of alerts without adequate strategic context.

To illustrate these principles and develop a practical framework, Handorf draws upon his personal experience as a first-time landowner. After purchasing 140 acres of land that had been abandoned for decades, he faced widespread trespassing—from innocent hikers to hunters, shooters, and even a squatter. The local community perceived the land as an extension of their own, necessitating Handorf to establish new boundaries and rules. This real-world scenario provides a tangible analogy for an organization's digital assets, where unauthorized access and malicious intent often stem from a lack of clear boundaries and perceived vulnerability. Handorf's journey to secure his land, moving from basic physical security to sophisticated deception, serves as the practical backdrop for his proposed operations planning framework.

Key Findings

▶ Watch: Reintroducing the 'little pink book' for deception (2:10)

Handorf's talk distills several critical findings regarding the effective implementation of deception operations, both in the physical world and the digital realm. The overarching discovery is that deception is a comprehensive strategy, not a standalone tool or product. It transcends the simple Honeypot concept by requiring a deep, intentional commitment and integration into an organization's broader security posture.

Firstly, a robust foundational infrastructure is paramount. Just as Handorf had to understand every inch of his 140 acres, deploy basic physical security (locks, cameras, patrolling), and establish a cadence of monitoring, organizations must have an intimate knowledge of their digital environment. This includes accurate asset inventories, comprehensive log analysis, and a clear understanding of normal network behavior. Without these fundamentals, deception efforts will be ineffective, generating noise rather than actionable intelligence, and potentially even exposing real assets. Handorf's "cybersecurity 101 playbook" for his land—installing gates, locks, and surveillance cameras—demonstrates this prerequisite.

Secondly, clear objectives and adversary profiling are essential for successful deception. Handorf emphasizes the need to define precisely what problem the deception aims to solve, who is being deceived (e.g., nation-state actors versus insider threats), why, for how long, and how complex the operation needs to be. This rigorous pre-planning ensures that resources are allocated effectively and that the deception is tailored to the specific threat. In his land analogy, Handorf identified various types of trespassers, from casual hikers to dangerous shooters and poachers, each requiring a different level of response and deception complexity.

Thirdly, deception acts as a powerful force multiplier for threat intelligence. When properly implemented, a deception operation provides strong signals of anomalous activity. Handorf likens this to a "duress switch" or "panic alarm"—if a deception asset is triggered, it's a clear indicator that something malicious is occurring. This direct, high-fidelity signal significantly enhances a threat intelligence team's ability to identify, track, and analyze adversary tactics, techniques, and procedures (TTPs), providing invaluable insights that passive monitoring often misses.

Finally, Handorf's personal project, the "Rattlesnake Sanctuary," serves as a practical framework for applying these principles. This multi-layered deception operation demonstrated that combining physical deterrents with digital lures and social engineering can effectively alter adversary behavior. The "Rattlesnake Sanctuary" proved that a well-conceived deception, even a seemingly outlandish one, can instill a "healthy fear," slow down adversaries, and collect critical intelligence, ultimately achieving defensive goals by playing on the adversary's emotional state and curiosity. This real-world success validates the strategic approach to deception that Handorf advocates.

Technical Deep Dive

▶ Watch: The benefits and pitfalls of deception operations (4:00)

Handorf's talk meticulously outlines the technical and strategic components necessary for effective deception operations, moving from foundational security to advanced, multi-layered lures. He begins by stressing the "punch list" of questions that must be answered before embarking on any deception:

  1. Infrastructure Knowledge: A complete understanding of inventory, log analysis, and network cadence. This is the bedrock; without it, deception is futile.
  2. Problem Definition: Clearly articulating the specific security challenge the deception aims to address.
  3. Adversary Identification: Precisely defining the target of deception—is it a sophisticated nation-state actor, an opportunistic cybercriminal, or an insider threat? This dictates the complexity and resources required.
  4. Duration and Commitment: Determining the operational lifespan (hours, days, weeks, years) and the level of investment (e.g., forming an LLC for authenticity, creating extensive backstories).
  5. Complexity and Goals: Deciding if the goal is merely to slow down the adversary for observation or to completely thwart their access to "crown jewels."
  6. Dismantling Strategy: Planning how to gracefully terminate the deception operation without tipping off the adversary to its true nature.

Handorf illustrates these concepts through his personal "land management" scenario. Initially, he implemented a "cybersecurity 101 playbook" for his property: installing locks on gates, deploying surveillance cameras, and conducting regular patrols. While effective for most basic issues, this wasn't sufficient for persistent or dangerous trespassers. He then escalated to more technical and psychological solutions:

  • Enhanced Surveillance: Deploying additional surveillance cameras and Hack Five Pineapples (wireless network auditing tools) to collect Wi-Fi probe requests and other signals intelligence (SIGINT) from trespassers' mobile devices. This allowed him to identify device SSIDs, map them to physical locations using WiGLE, and correlate this data with ingress/egress timings.
  • Psychological Deterrents: Erecting "spooky solution" signs warning of an "active firing range" and coordinating with law enforcement friends to occasionally generate noise on the property. His personal practice of turkey hunting in "ninja mode" and startling trespassers with a sudden "hello" also served as a low-tech social engineering tactic.

The culmination of his deception strategy was the creation of the Rattlesnake Sanctuary. This highly authentic, multi-faceted operation involved:

  • Authenticity Backstop: Establishing a legitimate LLC (Rattlesnake Sanctuary) and a corresponding website. This provided a credible cover story that would withstand casual scrutiny.
  • Physical Lures: Designing and placing professional-looking signs with the "Rattlesnake Sanctuary" branding, featuring QR codes at the bottom. These signs were strategically mounted 75 to 100 feet inside the property lines, ensuring that anyone scanning them was already trespassing.
  • Social Engineering: Exploiting the trespassers' inherent anxiety and curiosity. Handorf noted that people trespassing are already on edge, and the sight of an official-looking sign with a QR code, combined with the fear of snakes (specifically the protected Timber Rattler in Pennsylvania), was designed to trigger an emotional response and compel them to interact.
  • Digital Cattle Shoot: Upon scanning the QR code, users were directed to a "cattle shoot" comprising two websites (one on IPv4 and one on IPv6). These sites were designed to run Java-based scripts to collect specific information from the visitor's device.
  • Data Collection for Law Enforcement: The primary purpose of the digital interaction was to gather actionable intelligence. This included collecting the visitor's TCP Source Port information, which Handorf explicitly states is crucial for law enforcement to obtain data from internet service providers via a 273D or administrative subpoena, especially when dealing with carrier-grade NAT.
  • Real-time Alerts: Handorf configured the system to send him a real-time text message notification whenever a QR code was scanned, providing him with immediate time and date information of the trespasser's presence.
  • Covert Disclosure: To address legal requirements (specifically after consulting with an attorney about data collection), the website included a subtle "Pi symbol" in the lower right-hand corner. Clicking this symbol revealed the true intent of the site: "Yep, while we do like rattlesnakes, the purpose of the site is to find, track, and identify trespassers." This allowed Handorf to collect data while maintaining plausible deniability regarding explicit consent, given the context of trespassing.

This intricate blend of physical, digital, and psychological tactics demonstrates the depth of planning and technical execution required for a successful deception operation, far exceeding the capabilities of a simple Honeypot.

Demo / Proof of Concept

▶ Watch: Deception operations are more than just honeypots (5:30)

The entirety of Handorf's talk, particularly the detailed account of his "Rattlesnake Sanctuary" project, serves as a compelling proof of concept for his deception operations planning framework. While there wasn't a live, interactive demo in the traditional sense, Handorf presented a thorough walkthrough of the physical and digital components of his system and showcased its real-world outcomes.

The core of the demonstration revolved around the Rattlesnake Sanctuary LLC and its associated signage. Handorf displayed images of the professional-looking signs, prominently featuring the "Rattlesnake Sanctuary" name and logo, along with a QR code at the bottom. He explained their strategic placement 75 to 100 feet inside his property lines, ensuring any interaction confirmed a trespass. The signs themselves, coupled with the local knowledge of the Timber Rattler being a protected species in Pennsylvania, were designed to create an emotional and psychological deterrent.

The digital aspect of the proof of concept was the "cattle shoot" website. Handorf showed screenshots of the website, which presented itself as a collective of landowners dedicated to protecting rattlesnakes. He explained how this website, accessible via both IPv4 and IPv6, employed Java-based scripts to collect specific visitor information. Crucially, he highlighted the collection of TCP Source Port information, which is vital for law enforcement to trace back to an ISP and identify individuals through a 273D or admin subpoena, especially in environments using carrier-grade NAT. This demonstrated the practical utility of the collected data for real-world interdiction.

A key element of the proof of concept was the covert disclosure mechanism. Handorf pointed out the subtle "Pi symbol" in the lower right-hand corner of the website. He articulated that clicking this symbol would reveal the site's true purpose: "Yep, while we do like rattlesnakes, the purpose of the site is to find, track, and identify trespassers." This detail underscored the legal considerations and careful planning involved in such an operation, ensuring that data collection, while deceptive, had a legally defensible disclosure.

The success of the "Rattlesnake Sanctuary" was evidenced by tangible results:

  • Direct Interdiction: Handorf reported that two individuals who scanned the QR code were subsequently identified. The collected information was passed to the police, who performed a "knock and talk," resulting in the trespassers conceding and agreeing to stay off the property.
  • Behavioral Change: He also shared observations and video evidence of other individuals approaching the signs, seeing them, and immediately turning around and leaving the property without engaging further. This demonstrated the deterrent effect of the deception, even without direct digital interaction.
  • Reduced Trespassing: Most impressively, Handorf stated that it had been approximately 155 days since the last trespasser on his property, indicating a significant reduction in unauthorized access.

The "Rattlesnake Sanctuary" effectively served as a large-scale, real-world proof of concept for Handorf's deception planning framework, showcasing how a carefully designed, multi-layered deception operation can achieve its objectives of intelligence gathering, deterrence, and behavioral modification.

Defensive Implications

▶ Watch: Essential questions for planning deception operations (6:00)

Handorf's talk offers profound implications for cybersecurity defenders, urging a shift from reactive, product-centric security to a proactive, strategic, and intelligence-driven approach. The defensive implications can be distilled into several key areas:

  1. Prioritize Foundational Security First: Before considering any advanced deception strategy, organizations must master the basics. This means having an accurate and up-to-date asset inventory, robust and centralized log analysis, and a clear understanding of their network's normal cadence. Handorf explicitly states that without these "cybersecurity 101" elements, deception will only exacerbate problems by creating more noise and frustration, rather than providing actionable intelligence. Defenders should invest in making their core infrastructure "as healthy as it can be."
  1. Embrace Deception as a Strategic Force Multiplier, Not a Product: Defenders must understand that deception is a sophisticated operational strategy, not merely a commercial tool to be purchased and deployed. It requires meticulous planning, clear objectives, and significant commitment. When integrated correctly, deception can be a massive force multiplier for threat intelligence teams, providing high-fidelity signals of compromise. If a deception asset is triggered, it's akin to a "duress switch" or "panic alarm," indicating a high-confidence malicious event that warrants immediate attention and deeper investigation.
  1. Develop a Comprehensive Deception Operations Planning Framework: Organizations should adopt Handorf's "punch list" of questions as a framework for planning any deception operation:
  • Define the Problem: Clearly articulate the specific threat or behavior you aim to address.
  • Profile the Adversary: Understand who you are trying to deceive (e.g., opportunistic attackers vs. advanced persistent threats) to tailor the complexity and resources.
  • Determine Scope and Duration: Plan how long the deception will run and how deeply it needs to be integrated (e.g., creating fake personas, building detailed backstories).
  • Establish an Exit Strategy: Crucially, plan how to dismantle the deception gracefully without revealing its true nature to potential adversaries.
  • Legal Consultation: As demonstrated by the "Pi symbol" disclosure, organizations must consult with legal counsel to ensure compliance with data collection laws, especially when gathering information from potentially unauthorized users.
  1. Leverage Psychological and Social Engineering Tactics: Deception isn't purely technical; it involves manipulating adversary psychology. Defenders should consider how to create an environment that plays on an attacker's curiosity, fear, or perceived opportunity. This could involve crafting believable fake documents, user accounts, network segments, or even entire "companies" that appear legitimate but are designed to lure and trap. The "Rattlesnake Sanctuary" highlights how fear and curiosity can be potent tools in behavioral modification.
  1. Focus on Intelligence Gathering and Adversary TTPs: The primary goal of deception is to gather intelligence on adversary behavior. When an attacker interacts with a deception asset, defenders gain invaluable insights into their tactics, techniques, and procedures (TTPs), tools, and objectives. This information can then be used to strengthen real defenses, improve threat hunting, and develop more effective incident response plans. Specific data points like TCP Source Port information can be critical for law enforcement follow-up.
  1. Deception Requires Significant Investment and Commitment: Handorf is clear that deception is not a cheap or easy solution. It demands considerable time, resources, and expertise. It's a continuous process of monitoring, analysis, and adaptation. Organizations must be willing to commit to this investment, viewing it as a long-term strategic advantage rather than a quick fix. Handorf's personal commitment to his land's security, stating he "wish I didn't have to do this but at the end I was committed because I'm crazy," underscores the dedication required.

By adopting these defensive implications, organizations can move beyond basic perimeter defense and develop sophisticated, proactive security postures that not only protect their assets but also actively engage and outmaneuver their adversaries.

Key Takeaways

  • Deception is a Strategic Framework, Not Just a Product: Effective deception extends far beyond deploying a simple Honeypot; it's a comprehensive, deliberate operational strategy requiring meticulous planning, clear objectives, and deep integration into an organization's security posture.
  • Foundational Security is Non-Negotiable: A robust understanding of your infrastructure, including accurate inventory, comprehensive log analysis, and network cadence, is absolutely essential. Without these basics, any advanced deception effort will likely fail or generate unmanageable noise.
  • Adversary Profiling and Clear Objectives are Crucial: Define precisely who you are trying to deceive, what problem you are solving, why, and for how long. This dictates the complexity, resources, and ultimate success of the operation.
  • Deception is a Force Multiplier for Threat Intelligence: When executed correctly, deception operations provide high-fidelity signals of malicious activity, acting like a "duress switch" that significantly enhances a threat intelligence team's ability to identify and analyze adversary TTPs.
  • Embrace Both Technical and Psychological Tactics: Successful deception combines technical lures (e.g., fake network segments, data collection points) with social engineering and psychological manipulation to exploit an adversary's curiosity, fear, or perceived opportunity, influencing their behavior.
  • Commitment, Planning, and Legal Consultation are Essential: Deception operations demand significant time, resources, and the foresight to plan for both deployment and graceful dismantling. Always consult with legal counsel regarding data collection practices to ensure compliance and mitigate risks.

About the Speaker(s)

Russell Handorf is a seasoned security professional with extensive experience in deception operations and planning. Throughout his career, he has been involved in developing and responding to various deception strategies, though he explicitly stated during his talk that he is "not representing anyone who I used to work for or currently work for, it's just me." Handorf holds a PhD, which he humorously attributes more to stubbornness than intelligence, highlighting his tenacious and committed approach to problem-solving. His unique blend of high-level strategic thinking, practical field experience, and a willingness to apply cybersecurity principles to unconventional scenarios (like securing his own land) makes him a compelling voice in the security community. He is passionate about moving beyond traditional security paradigms to embrace more proactive and intelligent defensive measures.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This talk is a masterclass in applying sophisticated deception operations planning, typically reserved for nation-state cyber operations, to a real-world, deeply personal problem: protecting private land. Handorf's

Heather Calloway (CISO) — STRONG ACCEPT

Russell Handorf's talk on deception operations is a welcome challenge to the pervasive "checkbox security" mindset. He effectively articulates deception not as a mere technical tool, but as a strategic planning framework crucial for intelligence gathering and adversary manipulation. While the analogy of securing private land may seem unconventional for a corporate CISO, the core principles of meticulous planning, clear objective setting, adversary profiling, and foundational infrastructure are directly applicable to building resilient, accountable security programs. This presentation offers valuable insights for leaders seeking to move beyond reactive defenses toward a more proactive…

→ Top-rated talks at ShmooCon XX (Final)

All talks from ShmooCon XX (Final)