Esc
Decoy Object
Definition
A Decoy Object is created and deployed for the purposes of deceiving attackers.
Synonyms: Lure.Technique Overview
Decoy objects are typically configured with detectable means of communication but do not have any legitimate business purpose. Any communication via or to these objects should be logged and analyzed to find potential indicators of compromise for a possible past or future attack against other systems.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Technique Subclasses
There are 7 techniques in this category, Decoy Object.
| Name | ID | Definition | Synonyms |
|---|---|---|---|
| Decoy Object | D3-DO | A Decoy Object is created and deployed for the purposes of deceiving attackers. | Lure |
| - Decoy Public Release | D3-DPR | Issuing publicly released media to deceive adversaries. | |
| - Decoy File | D3-DF | A file created for the purposes of deceiving an adversary. | |
| - Decoy Session Token | D3-DST | An authentication token created for the purposes of deceiving an adversary. | |
| - Decoy Persona | D3-DP | Establishing a fake online identity to misdirect, deceive, and or interact with adversaries. | |
| - Decoy User Credential | D3-DUC | A Credential created for the purpose of deceiving an adversary. | |
| - Decoy Network Resource | D3-DNR | Deploying a network resource for the purposes of deceiving an adversary. |
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , , and .
Command and Control
Application Layer Protocol
Encrypted Channel
Privilege Escalation
Boot or Logon Initialization Scripts
Boot or Logon Autostart Execution
Process Injection
Abuse Elevation Control Mechanism
Event Triggered Execution
Access Token Manipulation
Account Manipulation
Create or Modify System Process
Scheduled Task/Job
Stealth
Process Injection
Obfuscated Files or Information
Deobfuscate/Decode Files or Information
Hijack Execution Flow
Masquerading
Indicator Removal
Rootkit
Hide Artifacts
XSL Script Processing
Access Token Manipulation
System Binary Proxy Execution
Trusted Developer Utilities Proxy Execution
Impair Defenses
Credential Access
Unsecured Credentials
OS Credential Dumping
Modify Authentication Process
Brute Force
Steal or Forge Kerberos Tickets
Keychain
Steal Web Session Cookie
Forge Web Credentials
Steal Application Access Token
Credentials from Password Stores
Steal or Forge Authentication Certificates
Forced Authentication
Lateral Movement
Internal Spearphishing
Software Deployment Tools
Taint Shared Content
Use Alternate Authentication Material
Collection
Email Collection
Archive Collected Data
Automated Collection
Data Staged
Data from Local System
Data from Information Repositories
Data from Network Shared Drive
Persistence
Event Triggered Execution
Boot or Logon Autostart Execution
Modify Authentication Process
Boot or Logon Initialization Scripts
Account Manipulation
Server Software Component
Office Application Startup
Create or Modify System Process
Scheduled Task/Job
Execution
User Execution
Hijack Execution Flow
Software Deployment Tools
Command and Scripting Interpreter
Scheduled Task/Job
Trusted Developer Utilities Proxy Execution
Impact
Data Manipulation
Data Encrypted for Impact
Defacement
Defense Impairment
Modify Authentication Process
Discovery
File and Directory Discovery
System Network Configuration Discovery
System Owner/User Discovery
Remote System Discovery
Exfiltration
Exfiltration Over C2 Channel
Exfiltration Over Alternative Protocol