Defensive technique

Adversary engagement

Planned operations to observe adversary decisions and learn from them while maintaining defensive control.

Research question

What is the hypothesis, who controls the operation and how are results interpreted?

Context and method

Definitions and technical considerations should be checked against the primary source. Atlas records are a selection tagged with this topic; a matching tag does not demonstrate operational outcomes.

Cross-reference

This topic across source types

These counts describe tagged Atlas records, not the worldwide number of studies or offerings.

Linked library

Associated records

16 tagged records
Case study2026

Cargo Theft Actor in a Persistent Decoy

Review: Public pageCritical reading

Proofpoint observed post-compromise activity for over a month in a Deception.Pro decoy environment; adversary behavior research, not a commercial effectiveness trial.

EndpointNetworkDecoyAdversary engagement
Case study2026

Trapping a Mustang Panda

Review: Public pageCritical reading

IBM X-Force and Deception.Pro recorded two incidents in simulated organizations, observing reconnaissance, malware deployment and fake-document exfiltration.

EndpointOT/ICSDecoyAdversary engagement
Open software2025

BUDA

Review: RepositoryEditor contribution

Experimental framework generating fictitious user profiles and activity for decoy environments; the repository documents narratives, profiles and language-model integration.

EndpointNetworkDecoyAdversary engagement
Open software2024

DOLOS-T

Review: RepositoryEditor contribution

Open framework for planning deception operations and deploying decoys and services with Python and Docker, according to its repository and documentation.

NetworkApplicationDecoyHoneypot