What It Does
Plant privileged-looking accounts and group memberships that no legitimate process ever touches.
Observable indicator. Directory reconnaissance is detected at the enumeration stage.
Where It Sits
A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.
- Form of maneuverM5 AmbushTrade space for information and time, and impose cost.
- Terrain layerT1 IdentityThe high ground. Key terrain: The ICAM policy decision point, privileged accounts, external-user and mission-staff identities.
- Position in the form7 of 13M5 carries 13 cataloged techniques; this is the 7th in catalog order.
Phases It Is Employed In
Employed in 2 of the campaign’s six phases. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.
- Phase IDeterVisible hardening, a deception grid, and a stated attribution posture.
- Phase IISeize InitiativeDetect early, canalize movement, and buy decision time.
Controls That Assess It
The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.
- CE-2 Priority Intelligence RequirementsCycle Execution and Assurance — To direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.
- KT-4 Adversary Reachability AssessmentKey Terrain and Decisive Points — To produce a computed, repeatable answer to the question a control catalog cannot ask — can they get there from here — and to record the answer as a trend rather than a one-time finding.
- SM-7 Deception EmplacementScheme of Maneuver — To obtain detection with no false-positive budget, and to ensure that signal is acted on rather than queued.
In MITRE D3FEND
What this technique is called in MITRE’s countermeasure ontology. The join runs technique-to-technique: D3FEND catalogs countermeasures, and the thing with a countermeasure’s shape here is the technique, not the control.
- D3-DP Decoy PersonaDeceive tactic
- D3-DST Decoy Session TokenDeceive tactic
- D3-DUC Decoy User CredentialDeceive tactic
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
Related Techniques
The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.
Assessed Alongside
Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 32 that share at least one control.
- 3 shared controlsM5.08 Decoy Cloud ResourcesM5 Ambush · T4 Applications and Workloads
- CE-2
- KT-4
- SM-7
- 3 shared controlsM5.03 Decoy CredentialsM5 Ambush · T1 Identity
- CE-2
- KT-4
- SM-7
- 2 shared controlsM5.01 Decoy Records in the Data LayerM5 Ambush · T5 Data
- CE-2
- SM-7
- 2 shared controlsM5.02 Honeytokens in Document StoresM5 Ambush · T5 Data
- CE-2
- SM-7
- 2 shared controlsM5.04 Honeypot Services in CorridorsM5 Ambush · T3 Networks
- CE-2
- SM-7
- 2 shared controlsM5.05 Canary Files on EndpointsM5 Ambush · T2 Devices
- CE-2
- SM-7