mislead

Deploy honeypots and decoy assets to detect unauthorized probing.

105|13|Updated Mar 9, 2026
One-click install
npx skills add https://github.com/Hmbown/Wizards-of-the-Ghosts --skill mislead
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: mislead
Source: https://github.com/Hmbown/Wizards-of-the-Ghosts/tree/main/generated/hermes/monitoring-and-protection/mislead
Command: npx skills add https://github.com/Hmbown/Wizards-of-the-Ghosts --skill mislead

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Mislead provides defensive deception techniques (honeypots, canary tokens, decoy endpoints, and fake datasets) to reveal who is probing or snooping. The approach helps detect unauthorized access while minimizing risk to real assets by isolating decoys. It requires explicit boundaries, isolation, and a clear monitoring objective before deployment.

Core Features & Use Cases

  • Honeypots, canary tokens, decoy endpoints, and fake datasets to attract and detect probing activities.
  • Isolated surfaces provide visibility into attacker tactics without impacting production.
  • Defines monitoring, response playbooks, and evidence collection to inform security processes.

Quick Start

Deploy a defensive decoy surface in a controlled environment and configure basic monitoring to alert on decoy interactions.

Frequently Asked Questions about mislead

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I deploy a honeypot to detect unauthorized probing in my environment?

Deploy a honeypot by introducing decoy assets and fake datasets in a controlled environment, then configure monitoring to alert on any interactions. This reveals probing activity without risking production data by isolating the decoys.

What are defensive deception techniques and when do I need them?

Defensive deception uses honeypots, canary tokens, and decoy endpoints to detect unauthorized snooping. You need these techniques when you want visibility into adversary reconnaissance across isolated environments without impacting real assets.

Can I use canary tokens and decoy endpoints alongside production data safely?

Yes, canary tokens and decoy endpoints are isolated from production data to minimize risk. This approach requires explicit isolation boundaries and clear monitoring objectives before deployment to ensure real assets remain unaffected.

What is the best way to monitor adversary reconnaissance without risking production systems?

The best way to monitor reconnaissance safely is deploying isolated decoy surfaces with fake datasets. This provides visibility into attacker tactics while maintaining strict isolation boundaries and defined response plans before deployment.

Do I need a defined response plan before setting up decoy assets?

Yes, you must establish defined response plans, monitoring objectives, and isolation boundaries before deploying decoy assets. These prerequisites ensure evidence collection informs security processes without exposing production data to risk.

Why does deploying fake datasets require explicit isolation boundaries?

Deploying fake datasets requires explicit isolation boundaries to prevent unauthorized probing from impacting production systems. Isolation ensures decoys attract and detect probing activities while maintaining clear separation from real assets.