Examples include decoy systems, services, credentials, records, files, or links that legitimate users and production processes should not need. Interaction can expose adversary behavior or defensive gaps.
A deception program starts with objectives and threat modeling, not a product category. Designers decide who may encounter it, what it should elicit, how it is contained, what evidence is collected, and how responders act.
Key points
DesignMake decoys plausible, distinguish them from production, restrict their privileges and data, and prevent them from becoming attack infrastructure.
OperationsMonitor interaction and health, protect management paths, document ownership, test response workflows, rotate artifacts, and retire stale deceptions safely.
GovernanceDefine authorization, collection purpose, retention and access rules, required notice, legal, privacy, and safety review, and escalation rules before deployment.
Important limitationA deception alert is not automatically proof of an external attacker, and silence does not prove absence of compromise. Misconfiguration, scanners, insiders, or legitimate automation may trigger decoys; sophisticated adversaries may recognize, avoid, or abuse them.