Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

D3fend Deceive

  • 28 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Designs cyber deception with MITRE D3FEND: honeynets, decoy objects, decoy personas, and decoy credentials for honeypot and bait programs.

About

An agent skill for cyber deception operations using MITRE D3FEND, covering honeynets, decoy objects, decoy personas, and decoy credentials. A security engineer uses it when deploying honeypots, planting decoy data, baiting credentials, or designing deception programs.

  • Honeypot deployment and decoy file planting
  • Credential baiting and deception environment design

D3fend Deceive by the numbers

  • 28 all-time installs (skills.sh)
  • Ranked #1,512 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill d3fend-deceive

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs28
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Designs cyber deception with MITRE D3FEND: honeynets, decoy objects, decoy personas, and decoy credentials for honeypot and bait programs.

Files

SKILL.mdMarkdownGitHub ↗

D3FEND — Deceive

When to Use

  • Deploying honeynets (connected, integrated, standalone)
  • Planting decoy objects (files, network resources, personas)
  • Distributing decoy credentials and session tokens
  • Publishing decoy information (fake releases, personas)
  • Designing deception programs and adversary engagement
  • Monitoring deception environment for adversary interaction

When NOT to Use

  • Building detection rules or SIEM content → d3fend-detect
  • System hardening or secure config → d3fend-harden
  • Network segmentation → d3fend-isolate
  • Active defense / threat intel → cybersecurity
  • Adversarial testing (red team) → ai-redteam / offensive-security-analyst

Core Workflows

1. Decoy Environments (Honeynets)

TypeDeploymentUse Case
StandaloneIsolated network segmentResearch, early warning
IntegratedBlended with productionInsider threat, lateral movement
ConnectedLinked to real systemsAPT detection, TTP collection

See `references/honeynets.md`

2. Decoy Objects

  • Decoy files: Fake documents with tracking (canary tokens)
  • Decoy network resources: Fake shares, databases, services
  • Decoy personas: Fake user accounts with believable data
  • Decoy public releases: Fake credentials on dark web/pastebin
  • Decoy session tokens: Bait cookies/API keys with monitoring

See `references/decoy_objects.md`

3. Deception Program Design

1. Define objectives (detection, delay, intelligence) 2. Select deception layers (environment, object, persona) 3. Ensure believability and consistency 4. Monitor and collect adversary TTPs 5. Analyze and feed into threat intelligence

See `references/deception_program.md`

When to load references

  • Honeynetsreferences/honeynets.md
  • Decoy objectsreferences/decoy_objects.md
  • Deception programreferences/deception_program.md

Related skills

Securityappsecaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.