Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

MITRE D3FEND™ Learning Center

D3-DPR — Decoy Public Release

Issuing publicly released media to deceive adversaries.

1Parent technique
1Source reference

Deceive · D3FEND ontology 1.6.0 · Active

Open official technique ↗
Official D3FEND definition

Definition

Issuing publicly released media to deceive adversaries.

Official D3FEND knowledge-base content

How it works

Publicly released media includes press release, videos, or other marketing collateral. The media may include URLs, points of contact, or other identifiers to entice interaction from adversaries.

Considerations

  • Information used in decoy public released media must contain enough realism to deceive and provide interaction from adversaries.
  • Continuous development, creation, and distribution of media and identifiers are needed to ensure adversary interaction continues over time.
  • Decoy public releases could be placed on platforms with different degrees of ownership, including entirely enterprise-owned infrastructure, IaaS, and SaaS (including social applications). Platforms that are not entirely enterprise-owned may be more likely to gather information
Bare Metal Cyber interpretation

Implementation perspective

Decoy Public Release should be treated as a technical defensive capability rather than a product checkbox. In practice, teams should define the protected scope, the conditions under which the technique acts, and the observable evidence that demonstrates the intended behavior. For this technique, likely engineering context includes the relevant system, activity, and evidence sources.

Use the technique to present controlled information, services, or artifacts that shape adversary behavior and create observable interaction.

Questions to ask

  • What behavior is the deceptive element intended to attract, delay, reveal, or redirect?
  • How is the deceptive element made plausible without creating unacceptable operational risk?
  • Which interactions are monitored, and who investigates them?
  • How is the deceptive environment isolated from production systems and sensitive data?

Evidence and validation

  • Design records describing the deception objective and placement
  • Isolation and containment test results
  • Monitoring and alert-routing configuration
  • Interaction records and documented investigative outcomes

Common failure patterns

  • The deceptive element is obvious, stale, or inconsistent with the surrounding environment.
  • Interactions are collected but not reviewed or connected to response processes.
  • The decoy introduces a new pathway to production data or systems.

This implementation perspective is original Bare Metal Cyber educational content. It does not replace the official D3FEND definition or establish that a specific product implements the technique.

Ontology hierarchy

Technique hierarchy

Top-level family

Parent techniques

Direct child techniques

None listed at this level.

Source record

Authoritative sources