Topic map / Reference
Cyber deception topics
Explore the field through two questions: which technique is used and in what environment. Each topic connects definitions, sources, records and a practical guide.
00 / Foundations
Start with the vocabulary
MITRE Engage helps plan deception and engagement operations; D3FEND describes decoy objects and environments. The Atlas glossary explains the labels used here.
01 / Techniques
What the lure does
01 / HoneypotHoneypots and honeynetsSystems and services prepared to observe interactions that ordinary operations should not produce.↗02 / HoneytokenHoneytokens and decoy credentialsData, credentials or identifiers created to generate a signal when someone accesses or uses them.↗03 / DecoyDecoy assets and objectsSimulated assets that can steer reconnaissance or make a suspicious interaction visible.↗04 / Adversary engagementAdversary engagementPlanned operations to observe adversary decisions and learn from them while maintaining defensive control.↗05 / Moving target defenseMoving target defenseDeliberate environment changes that can hinder reconnaissance. Treated as a related area when no explicit deception is involved.↗
02 / Environments
Where it is placed
01 / NetworkNetworks and servicesLures for network services, protocols and assets, internal or exposed.↗02 / IdentityIdentity and credentialsDecoy accounts, credentials and tokens linked to access and lateral movement.↗03 / CloudCloud and hybrid environmentsDecoy objects, permissions and workloads distributed across cloud services and hybrid integrations.↗04 / ApplicationApplications and APIsDecoy web services, routes and data associated with applications and APIs.↗05 / OT/ICSOT, ICS and critical infrastructureLures for industrial networks where process safety and lab isolation are central conditions.↗
This taxonomy guides navigation. MITRE D3FEND and Engage provide reference terminology; Atlas labels are editorial choices and are not an official MITRE classification.