deception-engineering

Design and orchestrate deception assets to detect attackers across network zones.

Updated May 22, 2026
One-click install
npx skills add https://github.com/drupadsachania/aegis-skills --skill deception-engineering
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: deception-engineering
Source: https://github.com/drupadsachania/aegis-skills/tree/main/skills/deception-engineering
Command: npx skills add https://github.com/drupadsachania/aegis-skills --skill deception-engineering

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Deception-engineering provides a structured, phase-driven approach to embed monitored, fake assets inside critical zones of an organization, enabling deterministic detection and actionable intelligence when attackers interact with those assets.

Core Features & Use Cases

  • End-to-end deception workflow from threat modeling to documentation and runbooks.
  • Phase-driven guidance including attack-surface taxonomy, signal validity, deception placement, grid planning, and IR integration.
  • Multi-platform compatibility and MITRE mapping (mitre-engage, mitre-attack) with generated deception registry and runbooks.
  • Produce artifacts for IR, executive summaries, and runbooks to accelerate response.

Quick Start

Load Phase 1 to start mapping attack surfaces and validating signals.

Frequently Asked Questions about deception-engineering

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design and deploy honeypots across multiple network zones?▼

Honeypots and deception assets are deployed through a phase-driven workflow covering attack-surface taxonomy, signal validation, and grid planning across perimeter, internal, identity/AD, cloud, and OT boundary zones to ensure deterministic threat detection.

What is deception engineering and how does it map to MITRE ATT&CK?▼

Deception engineering embeds monitored fake assets inside a network to study attackers, mapping interactions to both MITRE ATT&CK and MITRE Engage frameworks to generate actionable intelligence and accelerate incident response.

How do I integrate deception assets with an existing incident response process?▼

Deception assets are integrated using generated IR integration notes, comprehensive runbooks, and detection rules per platform, ensuring formal documentation and rotation schedules align directly with existing incident response workflows.

Can I generate a deception registry and runbooks for cloud and OT environments?▼

Yes, deception engineering supports multi-platform compatibility across cloud and OT boundaries, generating a formal deception registry, executive summaries, and runbooks tailored for these specific environmental constraints.

What is the first step to start mapping attack surfaces for honeytoken placement?▼

The first step is loading Phase 1 to map attack surfaces and validate signals, establishing a structured taxonomy that guides subsequent honeytoken placement and deception grid planning across critical zones.

Does deception engineering work without external security automation dependencies?▼

Yes, deception engineering operates independently without external dependencies, providing a structured approach to security automation by generating its own detection rules, registries, and incident response artifacts.