Depending on the organization and framework, it may include threat hunting, deception, decoys, dynamic reconfiguration, automated blocking or isolation, adversary engagement, and coordinated disruption performed within explicit technical and legal authority.
Because the term has no single universal boundary, every active-defense plan should define what actions it includes, where they may occur, who authorizes them, and how safety, evidence, privacy, escalation, and unintended effects will be controlled.
Key points
Defensive objectiveSpecify whether the action should detect intrusion, deny access, slow movement, protect an asset, gather evidence, restore control, or impose a cost within the defended environment.
Execution constraintsDefine owned or authorized systems, permitted techniques, approvals, human oversight, stop conditions, evidence handling, communications, and coordination with providers or authorities.
Effect measurementMonitor adversary and system behavior, validate that the action achieved its objective, check for operational harm or evasion, and feed reliable observations into response and architecture decisions.
Important limitationActive defense is not blanket permission to “hack back.” Accessing, damaging, or disrupting systems outside established authority can harm victims or infrastructure, destroy evidence, escalate conflict, and violate law; qualified legal review is essential.