Attack redirection is the practice of diverting suspicious traffic or attacker interaction away from production systems and toward controlled decoys. This allows defenders to observe behavior, collect forensic detail, and reduce risk to real assets while still learning how the intrusion is progressing.
What Attack Redirection Does
Attack redirection is a defensive deception technique: instead of letting suspicious traffic, probing, or interactive attacker activity reach production assets, defenders steer it into controlled decoys, isolated proxies, or observation points. The goal is to preserve safety while still learning how the intrusion behaves.
Because the redirected path is intentionally non-production, the method sits between detection and containment. It can buy time, reduce exposure, and create a safer environment for observation, but it only works when the diversion is believable enough to keep the attacker engaged.
How Attack Redirection Is Used
Redirection can be applied at different layers. Network controls may shunt traffic to a sinkhole or honeypot, application controls may place a controlled façade in front of a sensitive service, and identity- or session-adjacent controls may steer suspicious interaction into a monitored path that reveals intent without exposing real data.
The practical value is not simply blocking, but preserving visibility. A well-designed redirection path can show payloads, timing, tool use, follow-on requests, and operator behavior, which helps defenders understand whether the activity is casual scanning, credential abuse, or a more deliberate intrusion attempt. For a broader view of how adversary activity is tracked across the attack chain, see MITRE ATT&CK Enterprise Matrix.
Controls, Decoys, and Trust Boundaries
Attack redirection depends on tight control of the decoy environment. The redirected system must be isolated from real assets, instrumented for logging, and constrained so that an attacker cannot pivot from the trap into production. If the decoy is poorly segmented, the technique can become a new foothold rather than a safe observation point.
In practice, the redirection layer often sits alongside other controls that enforce least privilege, segmentation, and monitored access paths. That makes it useful both for incident response and for active defense experiments, where defenders want a realistic place to observe malicious behavior without exposing core systems. The same security discipline also appears in NIST Cybersecurity Framework 2.0 and NIST SP 800-207 Zero Trust Architecture, both of which reinforce controlled trust boundaries and verified access paths.
Where Attack Redirection Adds the Most Value
Redirection is especially useful when defenders need to observe an intrusion in progress, preserve evidence, or slow an adversary without tipping them off immediately. It can expose tactics such as reconnaissance, lateral movement attempts, credential probing, or automated exploitation, provided the decoy is convincing enough to keep the activity flowing.
Its value declines when the environment is too easy to distinguish from production, when alerts are not integrated with forensic capture, or when the redirection path creates operational noise without actionable detail. In well-run programs, the technique complements detection and response rather than replacing them. Related operational guidance on threat visibility and control layering appears in CISA cyber threat advisories, which help defenders contextualize observed attacker behavior.
Risk and Threat Considerations
Attack redirection reduces exposure only if the decoy is truly isolated and the diversion logic is trustworthy. The main risk is that an attacker recognizes the trap, ignores it, or uses the decoy as a way to learn defensive coverage, while a weaker but more dangerous risk is that the controlled environment accidentally provides a path back into production.
Failure mechanism: Poor isolation, weak segmentation, or incomplete instrumentation allows redirected traffic to escape the decoy boundary, or gives defenders a false sense of safety while the real attack continues elsewhere.
Impact: The organisation can lose visibility, waste response effort, expose sensitive telemetry, or create a secondary compromise path that turns a monitoring control into an attack surface.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1595 — Active Scanning | Attack redirection is often used to observe scanning and probing behavior. |
| T1021 — Remote Services | Redirected sessions often involve interactive access over remote services. | |
| Recommendation — Map redirected probing to active scanning and watch for enumeration patterns in decoy telemetry. Instrument redirected remote-service sessions to capture authentication and lateral-movement attempts. | ||
| NIST CSF 2.0 | DE.CM-01 — Networks and systems are monitored to detect potential cybersecurity events | Attack redirection exists to observe suspicious traffic and generate detection telemetry. |
| PR.AA-05 — Identity and access privileges are managed, incorporating the principles of least privilege and separation of duties | Safe redirection depends on restricting what the decoy can reach and do. | |
| Recommendation — Monitor redirected traffic as a detection source and feed resulting telemetry into event triage. Apply least-privilege access boundaries so decoys cannot reach production assets. | ||
| NIST SP 800-53 Rev 5 | SC-7 — Boundary Protection | Redirection relies on separating hostile traffic from production through controlled boundaries. |
| Recommendation — Enforce boundary protection around redirection points and decoy environments. | ||
Practitioner Guidance
What to watch for: Treat attack redirection as a control that must be designed, tested, and monitored, not just deployed. The most useful implementations are the ones that clearly define what will be redirected, what must never be reachable from the decoy, and what evidence should be captured when the path is exercised.
Practitioner takeaway: Redirection is strongest when it is paired with containment and observation, because the point is to learn from hostile interaction without granting real access.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org