Ensure Honey Token threat detector begins in disabled state by default out-the-box

What is a one sentence summary of your feature request?

The honey token threat detector should ideally be disabled by default out-the-box since it requires extra configuration.

Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.

Due to the extra configuration requirements to utilize the Honey Token threat detector properly, it would make more sense to ensure it is not running by default (without extra configurations in place) to help with application performance (and because its not adding value without a honey token already being in place). In fact, it might be even better if we could force the logic to not let it be enabled unless a honey token is already configured.

How do you currently solve the challenges you have by not having this feature?

Manually disable the threat detector after install.

Hey Devon, this is a good idea and something we’ll change out of the box. Will share timelines when available.

1 Like