# What is Active Defense?

> Active defense is an umbrella term for deliberate, adaptive actions that detect, disrupt, constrain, or learn from adversary activity rather than relying only on fixed barriers.

- Canonical URL: https://yellowcube.eu/glossary/active-defense/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Depending on the organization and framework, it may include threat hunting, deception, decoys, dynamic reconfiguration, automated blocking or isolation, adversary engagement, and coordinated disruption performed within explicit technical and legal authority.

Because the term has no single universal boundary, every active-defense plan should define what actions it includes, where they may occur, who authorizes them, and how safety, evidence, privacy, escalation, and unintended effects will be controlled.

### Key points

- **Defensive objective:** Specify whether the action should detect intrusion, deny access, slow movement, protect an asset, gather evidence, restore control, or impose a cost within the defended environment.
- **Execution constraints:** Define owned or authorized systems, permitted techniques, approvals, human oversight, stop conditions, evidence handling, communications, and coordination with providers or authorities.
- **Effect measurement:** Monitor adversary and system behavior, validate that the action achieved its objective, check for operational harm or evasion, and feed reliable observations into response and architecture decisions.
- **Important limitation:** Active defense is not blanket permission to “hack back.” Accessing, damaging, or disrupting systems outside established authority can harm victims or infrastructure, destroy evidence, escalate conflict, and violate law; qualified legal review is essential.

### Related terms

[Cyber defense](<https://yellowcube.eu/glossary/cyber-defense/>) · [Deception technology](<https://yellowcube.eu/glossary/deception-technology/>) · [Threat hunting](<https://yellowcube.eu/glossary/threat-hunting/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Security operations (SecOps)](<https://yellowcube.eu/glossary/security-operations/>)

### Sources

[NIST SP 800-160 Vol. 2 Rev. 1, Developing Cyber-Resilient Systems](https://csrc.nist.gov/pubs/sp/800/160/v2/r1/final) · [MITRE, Engage: A Framework and Community for Cyber Deception](https://www.mitre.org/news-insights/impact-story/mitre-engage-framework-and-community-cyber-deception) · [UK NCSC, Introduction to Active Cyber Defence](https://www.ncsc.gov.uk/section/active-cyber-defence/introduction) · [DHS and DOJ, CISA 2015 Non-Federal Entity Guidance](https://www.cisa.gov/sites/default/files/publications/Non-Federal%20Entity%20Sharing%20Guidance%20under%20the%20Cybersecurity%20Information%20Sharing%20Act%20of%202015_1.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

