About

I'm Aadam Dirie, a Cyber Deception Engineer at the world's largest retailer. My work sits between detection engineering, "reverse" red teaming and threat intelligence: building environments where an attacker's first confident move is also their loudest one.

What I work on

  • Deception engineering — decoy hosts, services, and lures designed to be believable to an intruder and invisible to everyone else.
  • Honeytokens — credentials, keys, and documents that produce high-confidence alerts with almost no false positives.
  • Adversary engagement — turning intrusion attempts into intelligence about tooling, tradecraft, and intent.
  • Detection quality — making sure the signal a decoy produces reaches a responder with enough context to act.

Why this blog

Deception is under-documented compared to the rest of security engineering. Most of what exists is either vendor material or academic. I write the middle layer: build logs, failure modes, and patterns that survive contact with a real environment.

Elsewhere

The fastest way to reach me is LinkedIn. Everything published here is my own view, not my employer's.

Get new field notes

Occasional posts on deception engineering, honeytokens, and adversary behaviour. No noise, unsubscribe any time.

Prefer RSS? Grab the feed.