MITRE D3FEND
Deceive Tactic - MITRE D3FEND

MITRE D3FEND MITRE-D3FEND-Deceive-Tactic-Decoy-Environment-Decoy-Object-Honeypots-Honey-Tokens-Decoy-Network: MITRE D3FEND Deceive Tactic + Decoy Environment + Decoy Object + Honeypots + Honey Tokens + Decoy Network

Apply D3FEND DECEIVE tactic to present false data and impressions to adversaries to misdirect their efforts. D3-DE Decoy Environment (D3-DST Decoy Session Token + D3-DPB Decoy Public Release + D3-CDE Connected Honeynet + D3-DUC Decoy User Credential + D3-IDA Integrated Honeynet + D3-SHN Standalone Honeynet). D3-DO Decoy Object (D3-DF Decoy File + D3-DPR Decoy Persona + D3-DR Decoy Resource Development + D3-DK Decoy Knowledge + D3-DTAA Decoy User Account + D3-DT Decoy Token). Deception activities include honeypot deployment (Cowrie + Dionaea + Honeyd + T-Pot + Modern Honey Network) + honeytoken services (Canary Tokens + Thinkst Canary + Tracebit) + deception platforms (Acalvio + Attivo Networks + Illusive Networks + CounterCraft + TrapX) + decoy file generation + fake identity provisioning + deceptive credentials (LDAP traps + AD honeypot accounts) + breadcrumbs + tripwires + early warning systems. Deception complements traditional defense by providing high-fidelity alerts when adversaries interact with decoys + intelligence gathering on tactics + time-cost imposition. NSA Active Cyber Defense doctrine + ENISA active defense guidance.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.