# What is Deception Technology?

> Deception technology is an industry umbrella term for controlled decoys, fabricated artifacts, misleading responses, and monitoring designed to attract, divert, delay, or reveal unauthorized activity.

- Canonical URL: https://yellowcube.eu/glossary/deception-technology/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Examples include decoy systems, services, credentials, records, files, or links that legitimate users and production processes should not need. Interaction can expose adversary behavior or defensive gaps.

A deception program starts with objectives and threat modeling, not a product category. Designers decide who may encounter it, what it should elicit, how it is contained, what evidence is collected, and how responders act.

### Key points

- **Design:** Make decoys plausible, distinguish them from production, restrict their privileges and data, and prevent them from becoming attack infrastructure.
- **Operations:** Monitor interaction and health, protect management paths, document ownership, test response workflows, rotate artifacts, and retire stale deceptions safely.
- **Governance:** Define authorization, collection purpose, retention and access rules, required notice, legal, privacy, and safety review, and escalation rules before deployment.
- **Important limitation:** A deception alert is not automatically proof of an external attacker, and silence does not prove absence of compromise. Misconfiguration, scanners, insiders, or legitimate automation may trigger decoys; sophisticated adversaries may recognize, avoid, or abuse them.

### Related terms

[Honeypot](<https://yellowcube.eu/glossary/honeypot/>) · [Honeytoken](<https://yellowcube.eu/glossary/honeytoken/>) · [Canary token](<https://yellowcube.eu/glossary/canary-token/>) · [Active defense](<https://yellowcube.eu/glossary/active-defense/>) · [Threat hunting](<https://yellowcube.eu/glossary/threat-hunting/>)

### Sources

[MITRE Engage: A Practical Guide to Adversary Engagement](https://engage.mitre.org/wp-content/uploads/2022/04/EngageHandbook-v1.0.pdf) · [NIST SP 800-160 Vol. 2 Rev. 1: Developing Cyber-Resilient Systems](https://csrc.nist.gov/pubs/sp/800/160/v2/r1/final) · [NIST SP 800-53 Rev. 5: Control SC-26, Decoys](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

