Library / sourced records

Resource library

Search by kind, technique, environment or critical readings. Each record states its source and review depth.

132published resources

Results

10 found
Case study2026

Cargo Theft Actor in a Persistent Decoy

Review: Public pageCritical reading

Proofpoint observed post-compromise activity for over a month in a Deception.Pro decoy environment; adversary behavior research, not a commercial effectiveness trial.

EndpointNetworkDecoyAdversary engagement
Case study2026

Trapping a Mustang Panda

Review: Public pageCritical reading

IBM X-Force and Deception.Pro recorded two incidents in simulated organizations, observing reconnaissance, malware deployment and fake-document exfiltration.

EndpointOT/ICSDecoyAdversary engagement
Open software2025

BUDA

Review: RepositoryEditor contribution

Experimental framework generating fictitious user profiles and activity for decoy environments; the repository documents narratives, profiles and language-model integration.

EndpointNetworkDecoyAdversary engagement
Open software2015

ghost-usb-honeypot

Review: Repository

Repository about capture of USB-propagated malware; documentation and maintenance require further review.

EndpointHoneypot
Product

Deception.Pro

Review: Public pageCritical reading

Persistent instrumented environments for malware detonation and adversary observation, according to the platform description.

NetworkEndpointDecoyAdversary engagement
Case study

Energy Company / Proofpoint Shadow

Review: Public pageCritical reading

Energy company Shadow adoption story published by Proofpoint; investigation-time reduction is a customer statement reported by the vendor.

EndpointIdentityDecoy
Product

Proofpoint Shadow

Review: Public pageCritical reading

Commercial identity protection component deploying endpoint deceptions to alert on lateral movement, according to Proofpoint.

EndpointIdentityDecoyHoneytoken

Each record shows the source reviewed. Vendor claims and independent results are labeled separately.