L24
Honeypots and internal/external threats
Cram this first — memory hook
Honeypot = bait with an alarm; internal does not mean innocent or malicious by default.
Exam trap
Tactics, Techniques and Procedures appears on the same slides, but is excluded from the default learning/testing path because your scope explicitly excludes it.
The slide facts
Honeypots and honeynets are deception technologies. Threats may originate outside or inside an organization; internal threats include careless users and infected devices, not only deliberate insiders.
If you have time — extra
A honeypot is a decoy intended to attract suspicious interaction and provide detection or investigation evidence. A honeynet is a network of decoys. Think of an instrumented empty office: nobody should need its fake payroll folder, so attempts to use it deserve attention. A decoy must be contained and monitored; it does not replace securing real systems. An internal threat may be an employee who makes a damaging mistake, a malicious insider or a compromised internal device. An external attacker may obtain valid credentials and then appear to operate through trusted access. Location, identity and intent are separate questions. Behavioral information highlights unusual activity; reputation information points to already known suspicious destinations or artifacts. Neither offers perfect certainty.
Walkthrough
Identify the asset and suspicious behavior, establish whether the access was expected, correlate observations, contain confirmed misuse, and investigate without treating every unusual action as automatically malicious.