SKILL.md-

Deploy honeypots, honeytokens, and canaries to detect attacker activity.

Updated Apr 20, 2026
One-click install
npx skills add https://github.com/DCx7C5/ai-marketplace --skill skill-md
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: SKILL.md-
Source: https://github.com/DCx7C5/ai-marketplace/tree/main/skills/deception
Command: npx skills add https://github.com/DCx7C5/ai-marketplace --skill skill-md

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Deception-based defense provides early warning by deploying decoy assets (honeypots, honeytokens, and canaries) that lure and alert on attacker activity, enabling faster detection and containment.

Core Features & Use Cases

  • Deploys decoy assets across networks to observe attacker techniques and pivot points.
  • Generates high-fidelity alerts for lateral movement, credential abuse, and reconnaissance attempts.
  • Integrates with SOC workflows and SIEMs to automate containment and case creation.

Quick Start

Deploy deception assets across your network to begin monitoring for attacker activity.

Frequently Asked Questions about SKILL.md-

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I deploy honeypots and honeytokens to detect lateral movement?

Deploying honeypots and honeytokens across networks detects lateral movement by luring attackers into interacting with decoy assets, which generates immediate alerts for intrusion detection and breach containment.

How does deception technology detect credential abuse in a SOC environment?

Deception technology detects credential abuse by embedding honeytokens that trigger high-fidelity alerts when attackers attempt unauthorized access, enabling SOC teams to automate containment and incident response workflows.

Can I integrate canary alerts with SIEM workflows for incident response?

Canary alerts integrate with SIEM workflows to automate containment and case creation, streamlining incident response by feeding high-fidelity breach detection data directly into existing SOC operations.

What is the best way to set up enterprise deception environments for intrusion detection?

The best way to set up enterprise deception environments is orchestrating decoy assets across networks to satisfy realism requirements, catching reconnaissance attempts and credential abuse through high-fidelity alerting.

Does deception technology work for detecting network reconnaissance attempts?

Deception technology works for detecting network reconnaissance by deploying decoy assets that attackers probe during initial pivoting, generating alerts that reveal attacker techniques and lateral movement paths.

When should I not use honeypots for breach detection?

Honeypots for breach detection require careful orchestration to maintain realism; avoid deployment without proper alerting integration, as poorly configured decoys can generate noise and fail to integrate with SOC containment workflows.