<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DeceptIQ Blog</title>
    <link>https://deceptiq.com/blog</link>
    <description>Insights on deception technology, threat detection, and cybersecurity strategy from the DeceptIQ team.</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 27 Apr 2026 11:41:44 GMT</lastBuildDate>
    <atom:link href="https://deceptiq.com/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>What&apos;s in a Good Honeytoken</title>
      <link>https://deceptiq.com/blog/whats-in-a-good-honeytoken</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/whats-in-a-good-honeytoken</guid>
      <pubDate>Tue, 06 Jan 2026 00:00:00 GMT</pubDate>
      <description>A good honeytoken gets used. Learn the principles that make adversaries validate credentials rather than skip past them.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>strategy</category>
    </item>
    <item>
      <title>Pre-emptive Detection Without Prediction</title>
      <link>https://deceptiq.com/blog/pre-emptive-detection-without-prediction</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/pre-emptive-detection-without-prediction</guid>
      <pubDate>Tue, 30 Dec 2025 00:00:00 GMT</pubDate>
      <description>Via negativa detection defines what should never happen rather than predicting attacks. When it fires, you&apos;ve caught an attack you didn&apos;t predict.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>strategy</category>
    </item>
    <item>
      <title>Getting Started with Early Warning Honey Tokens</title>
      <link>https://deceptiq.com/blog/getting-started-early-warning-honey-tokens</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/getting-started-early-warning-honey-tokens</guid>
      <pubDate>Sun, 28 Dec 2025 00:00:00 GMT</pubDate>
      <description>A practical guide to deploying early warning honey tokens effectively. Learn the lifecycle, placement strategy, and best practices that make deception work.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>best-practices</category>
    </item>
    <item>
      <title>Registry Writes Without Registry Callbacks</title>
      <link>https://deceptiq.com/blog/ntuser-man-registry-persistence</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/ntuser-man-registry-persistence</guid>
      <pubDate>Sat, 27 Dec 2025 00:00:00 GMT</pubDate>
      <description>Explore NTUSER.MAN, an overlooked Windows profile mechanism that allows registry persistence without triggering CmRegisterCallback EDR monitoring.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>The Reflexive Game: Why Deception Operates on Minds, Not Systems</title>
      <link>https://deceptiq.com/blog/the-reflexive-game-deception</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/the-reflexive-game-deception</guid>
      <pubDate>Wed, 24 Dec 2025 00:00:00 GMT</pubDate>
      <description>Deception operates on thinking adversaries who adapt to your moves. Understanding this reflexive dynamic between defender and attacker changes everything.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>strategy</category>
    </item>
    <item>
      <title>The Post-Compromise Gap: Why Mature Adversaries Keep Winning</title>
      <link>https://deceptiq.com/blog/post-compromise-gap</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/post-compromise-gap</guid>
      <pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate>
      <description>An insider&apos;s perspective on why current security products fail to stop modern red teams and sophisticated attackers, and what security teams need to know.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>Deception Taxonomy: A Common Language</title>
      <link>https://deceptiq.com/blog/deception-taxonomy</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/deception-taxonomy</guid>
      <pubDate>Tue, 16 Dec 2025 00:00:00 GMT</pubDate>
      <description>A common language for deception operations. The vocabulary needed to discuss honey tokens, tripwires, and alert lifecycles with precision.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>Detecting Unauthenticated AWS OSINT: Catching Adversaries Before They&apos;re Inside</title>
      <link>https://deceptiq.com/blog/detecting-unauth-aws-osint</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/detecting-unauth-aws-osint</guid>
      <pubDate>Sun, 14 Dec 2025 00:00:00 GMT</pubDate>
      <description>Detect unauthenticated S3 bucket enumeration before attackers get inside. Tools like cloud_enum run freely without alerts - until now.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>product-insights</category>
    </item>
    <item>
      <title>macOS Stealers: How Modern Infostealers Harvest Credentials</title>
      <link>https://deceptiq.com/blog/macos-stealers-technical-analysis</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/macos-stealers-technical-analysis</guid>
      <pubDate>Tue, 02 Dec 2025 00:00:00 GMT</pubDate>
      <description>Technical analysis of macOS information stealers using Banshee as a case study. How they phish passwords, decrypt Keychains, and exfiltrate browser data.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>Windows Stealers: How Modern Infostealers Harvest Credentials</title>
      <link>https://deceptiq.com/blog/windows-stealers-technical-analysis</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/windows-stealers-technical-analysis</guid>
      <pubDate>Tue, 02 Dec 2025 00:00:00 GMT</pubDate>
      <description>Technical analysis of Windows infostealers using Sryxen as a case study. How they decrypt browser data via DPAPI and exfiltrate credentials.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>Field Notes on Malware: The Evolution of C2 Evasion and What It Means for Detection</title>
      <link>https://deceptiq.com/blog/field-notes-on-malware</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/field-notes-on-malware</guid>
      <pubDate>Wed, 26 Nov 2025 00:00:00 GMT</pubDate>
      <description>Modern C2 evasion techniques from BOFs to RISC-V emulation. Why malware developers haven&apos;t adopted certain capabilities and what defenders need to know.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>Processing CloudTrail Logs from S3: Discovery and Resumption Patterns</title>
      <link>https://deceptiq.com/blog/processing-cloudtrail-logs-s3</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/processing-cloudtrail-logs-s3</guid>
      <pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate>
      <description>Process CloudTrail logs efficiently using S3&apos;s hierarchical structure. Learn discovery patterns and resumption strategies for organization trails.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>engineering</category>
    </item>
    <item>
      <title>The Psychology Behind Effective Honey Tokens</title>
      <link>https://deceptiq.com/blog/psychology-effective-honey-tokens</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/psychology-effective-honey-tokens</guid>
      <pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate>
      <description>Attackers validate credentials when type and context match their targeting. Understanding cognitive shortcuts determines honey token detection success.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>Early Warning Detection for Credential Theft: Why Behavioral Analysis Fails</title>
      <link>https://deceptiq.com/blog/early-warning-detection-credential-theft</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/early-warning-detection-credential-theft</guid>
      <pubDate>Tue, 18 Nov 2025 00:00:00 GMT</pubDate>
      <description>57% of breaches discovered externally. Infostealer credentials evade EDR for years. Early warning honey tokens detect validation before lateral movement.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>EventBridge Pattern Matching: A Field Guide</title>
      <link>https://deceptiq.com/blog/eventbridge-pattern-matching-guide</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/eventbridge-pattern-matching-guide</guid>
      <pubDate>Mon, 17 Nov 2025 00:00:00 GMT</pubDate>
      <description>Master AWS EventBridge pattern construction for security detection. Learn pattern expansion, nested logic, and common pitfalls with practical examples.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>engineering</category>
    </item>
    <item>
      <title>AI-Orchestrated Attacks: Why Detection Speed Matters More Than Ever</title>
      <link>https://deceptiq.com/blog/ai-orchestrated-attacks-honey-tokens</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/ai-orchestrated-attacks-honey-tokens</guid>
      <pubDate>Sun, 16 Nov 2025 00:00:00 GMT</pubDate>
      <description>AI-orchestrated attacks automate 80-90% of tactical operations at machine speed. Early warning detection becomes critical when attacks move in milliseconds.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>Early Warning Honey Tokens: Give Adversaries Options</title>
      <link>https://deceptiq.com/blog/early-warning-honey-tokens</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/early-warning-honey-tokens</guid>
      <pubDate>Tue, 11 Nov 2025 00:00:00 GMT</pubDate>
      <description>Early warning honey tokens break the attacker&apos;s risk calculus. Learn how planting monitored credentials creates detection opportunities at validation time.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>product-insights</category>
    </item>
    <item>
      <title>DeceptIQ: High-Fidelity Detection at Cloud Scale</title>
      <link>https://deceptiq.com/blog/launch</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/launch</guid>
      <pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate>
      <description>Built by red teamers to catch adversaries. The deception technology platform we wish every organization we compromised had in place.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>product-insights</category>
    </item>
    <item>
      <title>From Phish to Package: NPM Supply Chain Attacks</title>
      <link>https://deceptiq.com/blog/from-phish-to-package-npm-supply-chain-attacks</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/from-phish-to-package-npm-supply-chain-attacks</guid>
      <pubDate>Sun, 20 Jul 2025 00:00:00 GMT</pubDate>
      <description>Analysis of a recent NPM supply chain attack that deployed Scavenger malware through compromised packages, including a new overlooked phishing technique.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>Understanding Your Adversary: The Human Side of Threat Intelligence</title>
      <link>https://deceptiq.com/blog/understanding-your-adversary-cyber-deception</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/understanding-your-adversary-cyber-deception</guid>
      <pubDate>Sat, 05 Jul 2025 00:00:00 GMT</pubDate>
      <description>Recognize attackers as goal-driven individuals to transform your defensive strategy. Simple, psychologically-grounded deceptions outperform complexity.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>Threat Intelligence in Cyber Deception: A Planning Guide</title>
      <link>https://deceptiq.com/blog/threat-intelligence-cyber-deception-guide</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/threat-intelligence-cyber-deception-guide</guid>
      <pubDate>Fri, 04 Jul 2025 00:00:00 GMT</pubDate>
      <description>How threat intelligence transforms cyber deception from guesswork into strategic planning - understanding what attackers actually do and why it matters.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>The Cyber Deception Maturity Model: Where Does Your Organization Stand?</title>
      <link>https://deceptiq.com/blog/cyber-deception-maturity-model</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/cyber-deception-maturity-model</guid>
      <pubDate>Mon, 23 Jun 2025 00:00:00 GMT</pubDate>
      <description>Assess your deception maturity with this framework. Includes KPIs, metrics, implementation guidance, and a self-assessment quiz for your organization.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>industry-analysis</category>
    </item>
    <item>
      <title>Deception Fundamentals: The Missing Piece in Your Security Strategy</title>
      <link>https://deceptiq.com/blog/deception-fundamentals</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/deception-fundamentals</guid>
      <pubDate>Sun, 15 Jun 2025 00:00:00 GMT</pubDate>
      <description>A deep dive into deception fundamentals, from military doctrine to cybersecurity. Learn why attackers avoid most honey tokens and how to build effective ones.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>industry-analysis</category>
    </item>
    <item>
      <title>Modern Adversary TTPs: The Rise of &apos;Read Teaming&apos;</title>
      <link>https://deceptiq.com/blog/rise-of-read-teaming</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/rise-of-read-teaming</guid>
      <pubDate>Sat, 07 Jun 2025 00:00:00 GMT</pubDate>
      <description>An insider&apos;s perspective on why current security products fail to stop modern red teams and sophisticated attackers, and what security teams need to know.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>threat-research</category>
    </item>
    <item>
      <title>AWS Honey Tokens: The Good, the Bad, and the Ugly</title>
      <link>https://deceptiq.com/blog/aws-honey-tokens-good-bad-ugly</link>
      <guid isPermaLink="true">https://deceptiq.com/blog/aws-honey-tokens-good-bad-ugly</guid>
      <pubDate>Mon, 28 Apr 2025 00:00:00 GMT</pubDate>
      <description>AWS honey tokens are powerful detection tools with hidden risks. Learn their benefits, technical flaws, fingerprinting vulnerabilities, and real-world implications.</description>
      <author>rad@deceptiq.com (Rad Kawar)</author>
      <category>industry-analysis</category>
    </item>
  </channel>
</rss>