Start here

A safe first configuration.

  1. Install Free first. It contains detection, audit, hardening, scanner, MFA, SSO, firewall, file-integrity and evidence-export features.
  2. Activate Pro alongside Free. Do not delete Free. Pro adds licensed workflows and infrastructure integrations.
  3. Enter the licence key. Open DecoyNest → PRO License, then activate and verify.
  4. Run local checks before integrations. Review hardening, create a file baseline, enable MFA and confirm the audit log is recording events.

Your first healthy-state checklist

  • The audit log receives a fresh login event.
  • File Integrity shows a completed baseline, not a scan still in progress.
  • MFA recovery codes are stored outside WordPress and a second administrator can still sign in.
  • A manual encrypted backup completes and its archive exists at the selected destination.
Privacy baseline

Threat-intelligence sharing is optional and off by default. Cloud backups go to an account you connect. Sentinel events go directly from your WordPress site to Azure.

Directory

What every module does.

Honeypot sensors

Plausible decoy routes record hostile reconnaissance without exposing a real login or vulnerable component.

Attack chains

Correlates related events into sessions and multi-step behaviour, with MITRE ATT&CK context.

Vulnerability scanner

Matches WordPress core, plugin and theme versions against known vulnerabilities.

File integrity

Builds a local baseline and reports added, modified or removed files while suppressing expected update noise.

Audit log

Records authentication, user, plugin, theme, settings and MFA changes with actor, address and time.

MFA and SSO

Adds TOTP two-factor and optional Google, Microsoft or GitHub sign-in. Test SSO before enforcing it.

Firewall and headers

Applies focused IP/country controls and browser security headers. Review compatibility before enabling strict policies.

Hardening

Checks common WordPress exposure and configuration weaknesses and explains each recommended change.

Forensic export

Free evidence package containing timeline, integrity status, findings, inventory and environment data.

Forensic Workspace (Pro)

Interactive local timeline, severity charts, filters and actor/target pivots over the same evidence.

Encrypted backup (Pro)

Manual or scheduled database and wp-content archives, encrypted before optional cloud upload.

SIEM integrations

Business and Agency plans add Microsoft Sentinel streaming plus CEF and Syslog audit export.

Pro guide

Backups and encryption.

Open DecoyNest → Backup (Pro), accept the data-processing notice, then configure the schedule, archive contents, encryption and destination.

01 / BUILDCreate the archive

The database and selected wp-content files are collected on your WordPress server.

02 / PROTECTEncrypt locally

Encryption happens before an archive is eligible for cloud transfer.

03 / RETAINStore and rotate

The encrypted file is retained locally and, if connected, copied to your cloud account.

ScheduleManual, daily, weekly, or every 30 days. WordPress Cron must be able to run.
IncludeDatabase and/or wp-content. A complete recovery normally needs both.
Keep lastLocal retention from 1 to 30 archives.
Storage directoryUse an absolute writable path above public_html. Public web-root storage should be the last resort.

Which encryption profile?

  • AES-256-GCM — the conservative choice for compliance-oriented environments and policies that explicitly require AES.
  • XChaCha20-Poly1305 — a modern software-oriented authenticated-encryption profile; availability depends on the server Sodium extension.
Keep the passphrase outside WordPress.

It must be at least 16 characters. Changing it only affects new archives, so retain every old passphrase needed for historical backups. Cloud upload is refused when archive encryption is not configured.

Operational recommendation: Run one restore exercise before relying on automation. A successful upload proves transport, not recoverability. Record the archive date, passphrase reference and restore result in your recovery procedure.

OAuth setup

Google Drive, OneDrive and Dropbox.

Each site owner creates an OAuth application in the chosen provider. DecoyNest displays the exact callback URL beside every provider: copy that value exactly, including HTTPS and the full admin-post.php query.

Common sequence

Create provider app → register DecoyNest callback URL → copy Client ID and Client Secret → save Backup settings → click Connect → approve access → create a manual test backup.

Google Drive
  1. In Google Cloud Console, create or select a project and enable Google Drive API.
  2. Open Google Auth Platform → Clients and create an OAuth client of type Web application.
  3. Add the exact DecoyNest OAuth redirect URI under Authorized redirect URIs.
  4. Copy the Client ID and Client Secret into the Google Drive row, save, then Connect.

Requested scope: drive.file — access to files created or opened by this app, not the whole Drive.

Google OAuth web-server documentation ↗
Microsoft OneDrive
  1. In Microsoft Entra admin center, open App registrations → New registration.
  2. Under Authentication, add a Web redirect URI using the exact callback displayed by DecoyNest.
  3. Under Certificates & secrets, create a client secret and copy its Value immediately.
  4. Copy Application (client) ID and the secret Value into DecoyNest, save, then Connect.

Requested delegated scopes: Files.ReadWrite offline_access.

Microsoft app-registration documentation ↗
Dropbox
  1. Create an app in Dropbox App Console using the Dropbox API.
  2. Choose the narrowest storage access suitable for your backup policy, then enable files.content.write.
  3. Add the exact DecoyNest callback under OAuth 2 Redirect URIs.
  4. Copy App key as Client ID and App secret as Client Secret, save, then Connect.
Dropbox OAuth guide ↗
Business / Agency

Microsoft Sentinel setup.

DecoyNest uses the Azure Monitor Logs Ingestion API. You need a Log Analytics workspace, custom table, Data Collection Rule (DCR), an application identity, and permission for that identity to publish through the DCR.

  1. Create a custom Log Analytics table ending in _CL and a direct-ingestion DCR whose input schema matches DecoyNest events.
  2. Create a Microsoft Entra app registration and client secret.
  3. On the DCR, open Access Control (IAM) and assign Monitoring Metrics Publisher to the app service principal.
  4. Copy the five values below into DecoyNest → Sentinel (Pro), save, enable, then Send Test Event.
Tenant IDEntra ID → App registrations → your app → Overview → Directory (tenant) ID.
Client IDThe same Overview page → Application (client) ID.
Client SecretCertificates & secrets → Client secrets → Value. Do not use Secret ID.
DCE EndpointDCR Overview/JSON → Logs ingestion endpoint, or the Logs Ingestion URI from a linked Data Collection Endpoint. Paste only the base HTTPS endpoint.
DCR Rule IDData Collection Rule → Overview → Immutable ID. It begins with dcr-. Do not paste the Azure Resource ID.
Stream NameThe input stream name in the DCR streamDeclarations/dataFlows. It is case-sensitive and normally begins Custom-. Default: Custom-DecoyNestEvents_CL.
Most common Azure mistake

The app was created but never assigned Monitoring Metrics Publisher on the DCR. Authentication can succeed while ingestion is still denied.

Microsoft Logs Ingestion API documentation ↗
Pro operations

Licensing and private updates.

  • A licence is bound to the site URL and a random installation identifier; deactivating releases its slot.
  • Validation is normally cached for 24 hours, with a 72-hour grace period after the last successful check, never beyond actual expiry.
  • Pro updates use WordPress’s normal update screen but are downloaded from the authenticated DecoyNest update channel.
  • Free detection continues when a licence expires; paid integrations stop without deleting local evidence or existing archives.
Incident response

Evidence and Forensic Workspace.

Use the Pro workspace for rapid filtering and pivots. Use the Free forensic package when you need a portable case archive or third-party analysis. “No indicators found” means no matching evidence exists in the available record; it is not proof that no compromise occurred.

  • Check the evidence-chain integrity strip before drawing conclusions.
  • Pivot by actor and target, then narrow by source, severity and time window.
  • Export before remediation if evidence preservation matters.
Transparency

Where your data goes.

Most DecoyNest security evidence remains in your WordPress database. Network transmission only occurs when you activate a feature that needs an external service.

License APIReceives the licence key, normalized site URL and installation identifier for activation, entitlement and expiry checks.
Threat intelligenceOnly starts after explicit opt-in. Sensor events are sent through the issued installation token for central analysis.
Cloud backupSends encrypted archives directly to the provider account that you connect via OAuth.
Microsoft SentinelSends selected security events directly to the Azure ingestion endpoint configured by your administrator.
Before production use

Review retention, access control and data-processing requirements with the site owner. Do not put credentials, secrets or personal data into support tickets or screenshots.

Troubleshooting

Fast checks before opening a ticket.

A cloud provider says redirect_uri_mismatch

Copy the callback shown in Backup settings again. Scheme, hostname, path, query string and trailing slash must match the provider registration exactly.

Scheduled backups do not run

Confirm Backup shows a next scheduled time, WordPress Cron is not disabled, the destination is writable, a passphrase is stored, and the selected cipher is available on the server.

Sentinel authentication or ingestion fails

Verify the secret Value rather than its ID, check secret expiry, confirm the endpoint is the logs-ingestion base URI, use the DCR Immutable ID, match stream name case, and verify Monitoring Metrics Publisher assignment.

A paid page still says a valid licence is required

Open PRO License and confirm status, plan, expiry and entitlement list. Activate and verify again if the plan was changed recently, then reload the paid page.

Reference library

Official further reading.

Provider interfaces change over time. These primary sources explain the concepts and contain the latest portal-specific steps.