He walked away. Maya sat frozen for a moment, then laughed softly. She reopened the course homepage. A new module had unlocked: "Advanced Deception: Building Your Own Honeypots."
She copied it, wiped her logs using wevtutil (evading the host-based IDS), and closed all connections. Total time from first probe to exit: 22 minutes. No alerts. No honeypot interaction. The blue team’s dashboard remained green and peaceful.
She connected to a "Linux server" provided in the lab. It looked perfect—Ubuntu banner, bash prompt. She typed the test command. Then she tried to ls /tmp/ . No directory. Honeypot. She disconnected immediately.
The instructor opened a live trace file from a real engagement. "See here? The attacker found a honeypot but didn't realize the honeypot was feeding him fake credentials for a different network segment. He spent three days attacking a phantom Citrix server while his real target patched everything."