By Manny Fernandez

September 24, 2019

Interacting with a decoy in FortiDeceptor

Yesterday, I wrote a post showing how to deploy a Decoy and the Lures .  It did not show any of the discovery​ components of FortiDeceptor and the Incidents.

In my last post, I deployed a Linux decoy and created two lures for SSH and one lure for SAMBA.  Here I will simply use the credentials I had created (manny and qwerty).

Previous Decoy and Lures

2019-09-23_21-33-53

Above we can see a screenshot from the previous post.  We can see that we created a username manny and the password for  this ssh lure is qwerty

Connecting via SSH

2019-09-23_23-16-57.png

Above, you can see that I ssh'd to 10.1.108.200, the IP of the decoy.   I am not going to do anything crazy, just browse the environment.

2019-09-23_23-18-57.png

As I start to look at my newly found “booty” ( pirate version, not the modern version), I can see that there is a share directory/folder that looks promising.

2019-09-23_23-19-54.png

A simple ls shows fake files created under this folder.

What the FortiDeceptor is seeing

2019-09-23_23-21-47.png

On the dashboard, we can see that in the last 24 hours, we saw three incidents and forty events.

2019-09-23_23-22-20.png

Under the Incident section, choose Analysis.  Here you will see the three incidents.

2019-09-23_23-22-43.png

By choosing the small triangle on the side of the incident, it will expand that incident and reveal my (attacker in this case) activity including commands I typed.

2019-09-24_07-09-00.png

The second screen shot shows actual commands where the first one show the connectivity to the decoy itself.

2019-09-23_23-23-14 (1).gif

Under the Incident then Attack Map you have a cute graphic that shows the attacker icon, attacking the decoy icon.  (notice the gif, hard to see here).

2019-09-23_23-24-26.png

As in most of the Fortinet GUIs, there is a lot of shortcuts that make the interface very intuitive.  By clicking on the Decoy in the Attack Map section, you will be able to see these incidents and by clicking on them, it will take you to the Analysis screen I showed above.

Exporting

You can export this incident to a PDF (see below).

FortiDeceptor-Export

Conclusion

The key thing to remember about FortiDeceptor is that there are no False Positives.  Anyone interacting with this environment is in fact attacking it.  There is the ability of leaving breadcrumbs on legitimate devices in your environment that would lead an attacker to the FortiDeceptor environment.

 

Recent posts