Z.353 honeytoken telemetry routing + investigation steps.
A honeytoken (AWS canary key, fake admin credential, decoy URL, etc.) was accessed.
Honeytokens are pure-deception assets - any access is high-fidelity evidence of compromise
or insider snooping.
honeytoken_triggered4. Z.353 dispatches alert via Z.400 fanout to operator + SOC L2 queue
honeytoken_id fieldblock-ioc from Mini App4. Open IR case - severity High by default (Critical if Tier-0 asset adjacency)
5. Preserve evidence - Vault ciso/data/forensics/
| Token | Likely meaning |
|---|---|
| Fake AWS key from S3 bucket | Bucket reconnaissance |
| Vault decoy secret | Privileged credential dump |
| Decoy URL in source code | Code repo compromise |
| Canary Word doc | Phishing victim opened |