What MITRE D3FEND D3-DF: Decoy File (Defensive Tactic - Deceive -> Decoy Object) requires
MITRE D3FEND D3-DF (Decoy File) is a defensive technique that places enticing fake files (canary tokens, decoy documents, fake credential stores, fake backup archives, fake source code) in locations where legitimate users would not access them, generating high-fidelity alerts on adversary interaction. Decoy files are a low-false-positive complement to behavioural detection. DF counters ATT&CK techniques T1005 (Data from Local System), T1083 (File and Directory Discovery), T1213 (Data from Information Repositories), T1530 (Data from Cloud Storage), T1486 (Data Encrypted for Impact). Required as deception layer under NIST SP 800-53 SC-26 (Decoys), SC-30 (Concealment and Misdirection), ISO 27001 A.5.7 (Threat intelligence) - deception complement, and CISA #StopRansomware Guide.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:DecoyFile/
SHA-256 integrity: 9bee22f4f43de7ca8ccc664f99d749c99f081fcf790f830bcd00dea05064d17e
Primary Citations — 8 traced to source
- MITRE D3FEND Defensive Technique D3-DF: Decoy File (https://d3fend.mitre.org/technique/d3f:DecoyFile/)
- NIST SP 800-53 Rev 5: SC-26 (Decoys), SC-30 (Concealment and Misdirection)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-d3fend-d3-df-decoy-file.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-d3fend-d3-df-decoy-file.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-d3fend-d3-df-decoy-file
- Back to registry: Browse all 10,085 compliance nodes