Intent, Mechanism and Indicator
Trade space for information and time, and impose cost.
Role. The cheapest high-confidence detection available
Honeypots, decoy credentials and documents, honeytokens seeded through the data terrain.
The adversary interacts with a decoy, producing a detection with no false-positive budget.
Terrain It Consumes
Derived from where the form’s techniques are actually emplaced. The highlighted layer is the one the catalog names as its principal ground — the rest is terrain the form still has to touch, and that spread is how much of the estate employing it implicates.
- T1IdentityThe high ground2 techniques
- T2DevicesThe entry fords1 technique
- T3NetworksThe corridors1 technique
- T4Applications and WorkloadsThe urban terrain2 techniques
- T5DataThe objective3 techniques · principal ground
- T6Operational TechnologyGround you cannot maneuver freely on1 technique
- T7WorkforceTerrain that is also the force1 technique
- T8FacilitiesThe physical boundary1 technique
- TXCross-CuttingThe enablers of movement1 technique
Campaign Phasing
Dominance is taken from the campaign model; participation is derived from the techniques themselves. A form is usually present in more phases than it leads, and confusing the two is how a scheme ends up with no main effort.
| Phase | Role | Phase objective | Techniques employed |
|---|---|---|---|
| Phase 0 — ShapeSet conditions | Supporting | Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence. | 2 of 13 |
| Phase I — DeterRaise adversary cost | Dominant — main effort | Visible hardening, a deception grid, and a stated attribution posture. | 13 of 13 |
| Phase II — Seize InitiativeContest first contact | Supporting | Detect early, canalize movement, and buy decision time. | 9 of 13 |
| Phase III — DominateDefeat the attempt | Dominant — main effort | Hunt, contain, evict. | 1 of 13 |
Phase 0 — Shape
Set conditions
- Role
- Supporting
- Phase objective
- Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
- Techniques employed
- 2 of 13
Phase I — Deter
Raise adversary cost
- Role
- Dominant — main effort
- Phase objective
- Visible hardening, a deception grid, and a stated attribution posture.
- Techniques employed
- 13 of 13
Phase II — Seize Initiative
Contest first contact
- Role
- Supporting
- Phase objective
- Detect early, canalize movement, and buy decision time.
- Techniques employed
- 9 of 13
Phase III — Dominate
Defeat the attempt
- Role
- Dominant — main effort
- Phase objective
- Hunt, contain, evict.
- Techniques employed
- 1 of 13
Employment
When to Choose It
Choose ambush when alert fatigue, not sensor coverage, is the binding constraint — when the SOC sees plenty and believes little. Deception produces the one class of detection that needs no tuning: legitimate users have no reason to touch a decoy, so an interaction is contact by construction. It is also the form to choose when you need to buy information rather than deny access, because a decoy that holds an adversary’s attention is collection.
Precondition
An alert path that ends in a human within minutes. A decoy is a detection with no false-positive budget, and routing it into a queue that is triaged tomorrow throws that property away.
What It Costs
Low in money, high in discipline. Decoys must be maintained or they age into obviousness — stale timestamps, empty directories and implausible content are how an experienced adversary identifies the grid and routes around it. Decoy credentials that bind to real staff identities need legal and personnel review before emplacement, not after.
Rules of Engagement
Emplacing and maintaining the grid is standing SOC and terrain-owner work. Anything that engages the adversary beyond observation — feeding them fabricated content, or interacting deliberately — is an influence activity and needs explicit AO authorization and legal review.
How It Fails
Not whether it fails — how. Each of these is a state in which the form is still reported as implemented and has stopped producing the advantage it was chosen for.
- The grid is not maintained, so it reads as decoy to the adversary and as coverage to the defender.
- A decoy is reachable by a legitimate process — a backup agent, a discovery scanner, an inventory sweep — and the estate’s best detection becomes its noisiest.
- Deception is placed where an adversary who has already reached the objective would go, rather than along the path they must traverse. A decoy behind the crown jewels fires after the damage.
- Coverage is never measured, so the grid drifts into the layers that were easy to instrument and away from the ones the threat courses of action actually run through.
- Decoy hits are routed to the same queue as everything else, which discards the only property that made them worth emplacing.
Techniques (13)
Grouped by the terrain layer each is emplaced on. Techniques are the perishable layer of the framework — they churn, the form does not — so each is stated as what it does and the observable that shows it is working, never as a product.
T1 · Identity — 2 techniques
- M5.03
Decoy Credentials
Seed credential stores, memory and configuration with credentials that are valid-looking and monitored but powerless.
IndicatorCredential harvesting is detected on use of a planted credential.
Phases- I
- II
- M5.07
Identity-Plane Deception
Plant privileged-looking accounts and group memberships that no legitimate process ever touches.
IndicatorDirectory reconnaissance is detected at the enumeration stage.
Phases- I
- II
T2 · Devices — 1 technique
- M5.05
Canary Files on Endpoints
Distribute monitored files across the endpoint fleet to detect mass encryption and mass collection early.
IndicatorMass file operations are detected within the first affected hosts.
Phases- I
- II
T3 · Networks — 1 technique
- M5.04
Honeypot Services in Corridors
Place responsive services in the lateral corridors so that scanning and movement produce contact rather than silence.
IndicatorLateral reconnaissance produces an alert on first contact.
Phases- I
- II
T4 · Applications and Workloads — 2 techniques
- M5.06
Decoy Service Endpoints
Publish plausible but unused API and administrative endpoints that only enumeration would find.
IndicatorEnumeration of the application surface produces contact.
Phases- I
- II
- M5.08
Decoy Cloud Resources
Stand up monitored buckets, roles and secrets that legitimate workloads never call.
IndicatorCloud credential abuse is detected on first exploratory call.
Phases- I
- II
T5 · Data — 3 techniques
- M5.01
Decoy Records in the Data Layer
Seed the record stores with realistic decoy records whose only purpose is to be accessed by someone who should not.
IndicatorAccess to a decoy produces a high-confidence detection with no false-positive tail.
Phases- I
- II
- M5.02
Honeytokens in Document Stores
Place tokenized documents in collaboration and file estate where staged collection would find them.
IndicatorStaging for exfiltration is detected during collection, not after.
Phases- I
- II
- M5.10
Deception Coverage Measurement
Measure what share of the data layer is actually seeded, and treat the unseeded remainder as a gap.
IndicatorDeception coverage is a reported number, not an impression.
Phases- 0
- I
T6 · Operational Technology — 1 technique
- M5.11
Control Network Deception
Place decoy controllers and engineering workstations on the control network, where legitimate traffic is narrow and predictable.
IndicatorAny interaction with a decoy controller is unambiguous.
Phases- I
- II
T7 · Workforce — 1 technique
- M5.12
Phishing Deception and Reporting
Exercise the workforce against realistic lures and treat the reporting rate, not the click rate, as the measure that matters.
IndicatorReporting rate exceeds click rate and the first report arrives within minutes.
Phases- 0
- I
T8 · Facilities — 1 technique
- M5.13
Physical Deception
Seed facilities with tokens whose only plausible use is by someone who should not have them — dropped media, decoy badges, decoy racks.
IndicatorPhysical decoy interaction produces findings with no false-positive tail.
Phases- I
Controls That Assess It
Derived from the controls the form’s own techniques name, so the assessment surface cannot disagree with the catalog. A control reached by many techniques is load-bearing for this form; one reached by a single technique is not, and an assessor sampling it will learn very little.
By Family
- CECycle Execution and Assurance3 controls · reaches 13 of 13 techniques
- SMScheme of Maneuver2 controls · reaches 13 of 13 techniques
- KTKey Terrain and Decisive Points4 controls · reaches 6 of 13 techniques
- TATempo and Temporal Advantage2 controls · reaches 3 of 13 techniques
- FOFederal Obligations2 controls · reaches 2 of 13 techniques
- ENEngagement and Pursuit1 control · reaches 1 of 13 techniques
- FCFacilities Terrain1 control · reaches 1 of 13 techniques
- IDIdentity Terrain1 control · reaches 1 of 13 techniques
- WFWorkforce Terrain1 control · reaches 1 of 13 techniques
By Control
- SM-7 Deception Emplacement13 techniques — To obtain detection with no false-positive budget, and to ensure that signal is acted on rather than queued.
- CE-2 Priority Intelligence Requirements10 techniques — To direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.
- KT-4 Adversary Reachability Assessment3 techniques — To produce a computed, repeatable answer to the question a control catalog cannot ask — can they get there from here — and to record the answer as a trend rather than a one-time finding.
- CE-3 Fusion and Confidence2 techniques — To distinguish assessment from assertion, so that decisions taken on analytic conclusions carry the uncertainty of those conclusions with them.
- TA-1 Decision Loop Measurement2 techniques — To make the defender's tempo a measured quantity rather than an impression, so that the numerator of temporal advantage exists at all.
- CE-4 Coverage and Residual Risk Computation1 technique — To produce a posture figure that can be reproduced and challenged rather than asserted, so that the number carries authority beyond the tool that generated it.
- EN-1 Event Declaration and Triage1 technique — To convert raw events into a decided position quickly, since this is the segment of the decision loop that most often binds.
- FC-1 Facility Terrain Identification1 technique — To resolve the estate to physical locations, so that defense, recovery and continuity can be reasoned about in the place things actually are.
- FO-1 Privacy Terrain Identification1 technique — To make privacy exposure positional, so that the elements holding personal information can be defended, minimized and accounted for as terrain.
- FO-4 Operational Technology Terrain1 technique — To stop operational technology being scored as though it were a server estate, and to make the connections between the two declarable.
- ID-2 Credential Strength and Binding1 technique — To ensure the credential is as strong as the access behind it, so that proofing and authentication assurance are matched rather than assumed.
- KT-2 Decisive Point Protection Floor1 technique — To ensure designation produces protection, so that identifying a decisive point is an act with consequences rather than an annotation.
- KT-3 Avenue of Approach Analysis1 technique — To convert the estate's connectivity into a set of named approach routes, so that defense can be emplaced on the routes that exist rather than distributed evenly across ground.
- KT-5 Barrier Sufficiency1 technique — To make the barriers on which negative reachability results depend into named, owned, monitored controls, so that the assurance KT-4 provides cannot be silently withdrawn.
- SM-6 Maneuver Effectiveness Validation1 technique — To replace assumed effectiveness with demonstrated effectiveness, so the coverage figure reflects what controls do rather than what was assumed of them.
- TA-4 Pre-authorized Response1 technique — To remove authority latency from the decision loop, so that the segment most programs cannot shorten with tooling is shortened by governance.
- WF-3 Role-Based Readiness1 technique — To prepare people for the attacks their role attracts, and to know whether the preparation worked.
The cycle-execution controls test that deception telemetry is collected and routed; the coverage controls test whether the grid maps to the threat courses of action rather than to convenience; the tempo controls test the time from decoy interaction to human decision. Ask when each decoy was last refreshed — the freshness distribution is the honest measure of a deception program.
Sequencing
A scheme names a sequence, not a set. These are the ordinary neighbors of this form — not a mandatory order, but the order in which each one’s preconditions are usually met.
Typically Preceded By
- M4 Obstacle / CanalizationSite decoys on the corridors canalization already forces movement through.
- M1 Screen / GuardThreat courses of action from the screen say which decoys are worth holding.
Typically Followed By
- M7 CounterattackA decoy interaction is the highest-quality hunt trigger the estate produces.
- M6 DelayTime bought at the decoy is only useful if something slows the adversary down.
Named as a successor by M4 Obstacle / Canalization. Derived from those forms’ own declarations, so the two directions of the sequence cannot disagree.
Named as a predecessor by M6 Delay, M7 Counterattack. Derived the same way, from the other direction.