Ask an organization what its most sensitive asset is, and they will likely say a server that aligns to the CIA triad (Confidentiality, Integrity, and Availability). Ask a pentester the same question and they will say it is domain administrator. Why is that? Malicious actors don’t know how an organization fully operates. We need to turn our SOC’s biggest weakness into its biggest strength: blindspots. Attackers don’t know what will happen when they run a command for the first time in an environment. This presentation will explore creating checkpoints at key environment operations for attackers, weaponizing the ambiguity of how environments operate. Turning their actions against them, instead into high fidelity canary token detections facilitating automatic response.