Deployment environment

Endpoints and workstations

Defensive lures and artifacts placed on endpoints to expose reconnaissance or misuse.

Research question

What endpoint interaction triggers the signal and how is it distinguished from legitimate activity?

Context and method

Definitions and technical considerations should be checked against the primary source. Atlas records are a selection tagged with this topic; a matching tag does not demonstrate operational outcomes.

Cross-reference

This topic across source types

These counts describe tagged Atlas records, not the worldwide number of studies or offerings.

Linked library

Associated records

11 tagged records
Case study2026

Cargo Theft Actor in a Persistent Decoy

Review: Public pageCritical reading

Proofpoint observed post-compromise activity for over a month in a Deception.Pro decoy environment; adversary behavior research, not a commercial effectiveness trial.

EndpointNetworkDecoyAdversary engagement
Case study2026

Trapping a Mustang Panda

Review: Public pageCritical reading

IBM X-Force and Deception.Pro recorded two incidents in simulated organizations, observing reconnaissance, malware deployment and fake-document exfiltration.

EndpointOT/ICSDecoyAdversary engagement
Open software2025

BUDA

Review: RepositoryEditor contribution

Experimental framework generating fictitious user profiles and activity for decoy environments; the repository documents narratives, profiles and language-model integration.

EndpointNetworkDecoyAdversary engagement