deception-engineering

Design and orchestrate deception assets to detect attackers across network zones.

Updated May 22, 2026
One-click install
npx skills add https://github.com/drupadsachania/aegis-skills --skill deception-engineering
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: deception-engineering
Source: https://github.com/drupadsachania/aegis-skills/tree/main/skills/deception-engineering
Command: npx skills add https://github.com/drupadsachania/aegis-skills --skill deception-engineering

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Deception-engineering provides a structured, phase-driven approach to embed monitored, fake assets inside critical zones of an organization, enabling deterministic detection and actionable intelligence when attackers interact with those assets.

Core Features & Use Cases

  • End-to-end deception workflow from threat modeling to documentation and runbooks.
  • Phase-driven guidance including attack-surface taxonomy, signal validity, deception placement, grid planning, and IR integration.
  • Multi-platform compatibility and MITRE mapping (mitre-engage, mitre-attack) with generated deception registry and runbooks.
  • Produce artifacts for IR, executive summaries, and runbooks to accelerate response.

Quick Start

Load Phase 1 to start mapping attack surfaces and validating signals.

Frequently Asked Questions about deception-engineering

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design and deploy honeypots across multiple network zones?

Honeypots and deception assets are deployed through a phase-driven workflow covering attack-surface taxonomy, signal validation, and grid planning across perimeter, internal, identity/AD, cloud, and OT boundary zones to ensure deterministic threat detection.

What is deception engineering and how does it map to MITRE ATT&CK?

Deception engineering embeds monitored fake assets inside a network to study attackers, mapping interactions to both MITRE ATT&CK and MITRE Engage frameworks to generate actionable intelligence and accelerate incident response.

How do I integrate deception assets with an existing incident response process?

Deception assets are integrated using generated IR integration notes, comprehensive runbooks, and detection rules per platform, ensuring formal documentation and rotation schedules align directly with existing incident response workflows.

Can I generate a deception registry and runbooks for cloud and OT environments?

Yes, deception engineering supports multi-platform compatibility across cloud and OT boundaries, generating a formal deception registry, executive summaries, and runbooks tailored for these specific environmental constraints.

What is the first step to start mapping attack surfaces for honeytoken placement?

The first step is loading Phase 1 to map attack surfaces and validate signals, establishing a structured taxonomy that guides subsequent honeytoken placement and deception grid planning across critical zones.

Does deception engineering work without external security automation dependencies?

Yes, deception engineering operates independently without external dependencies, providing a structured approach to security automation by generating its own detection rules, registries, and incident response artifacts.