The short answer
| Term | What it is | A trigger usually means | MITRE D3FEND |
|---|---|---|---|
| Decoy | Any object or environment created to deceive an adversary | Someone interacted with something that has no legitimate use | Decoy Object and Decoy Environment |
| Honeypot | A decoy system or service an adversary can connect to | Someone probed, connected to, or used a system that has no legitimate users | Decoy Environment (D3-DE) |
| Honeynet | A network of honeypots | As above, across several decoy systems | Integrated, Connected, and Standalone Honeynet |
| Honeytoken | A decoy piece of data, such as a credential, record, file, or link | Someone found it and used or opened it | Decoy Object (D3-DO) and its sub-techniques |
| Canary token | A honeytoken that alerts by itself through a callback | The token was opened, resolved, or used | Decoy Object, usually Decoy File or Decoy User Credential |
| Lure | Another word for a decoy object | Depends on the object | Listed by D3FEND as a synonym of Decoy Object |
The rest of this guide explains each term and how to choose between them.
Why the terms get mixed up
“Honeypot” is the most familiar term, so it is often used for any kind of deception. Product names add to the confusion. Thinkst, for example, offers a commercial product called Thinkst Canary and a free service called Canarytokens, so “canary” has become shorthand for a whole category.1
Standards have moved towards “decoy”. NIST SP 800-53 Revision 4 named control SC-26 “Honeypots”. Revision 5 renamed it “Decoys”: components designed to be the target of malicious attacks so those attacks can be detected, deflected, and analysed, with honeypots, honeynets, and deception nets given as examples.2
MITRE D3FEND’s Deceive tactic is built around two techniques, Decoy Environment and Decoy Object. It lists “Honeypot” as a synonym of Decoy Environment and “Lure” as a synonym of Decoy Object.345
What is a decoy?
A decoy is anything created and placed to deceive an adversary, so that interacting with it reveals their activity. D3FEND splits decoys into two groups:
- Decoy Environment (D3-DE): hosts and networks built to deceive an adversary. This is where honeypots and honeynets sit.4
- Decoy Object (D3-DO): individual objects created and deployed to deceive, such as credentials, files, tokens, personas, and network resources.5
The property that makes every decoy useful is the same: it has no legitimate business purpose. A failed sign-in to a real account might be a typo. An attempt to use a credential that exists only as a decoy has very few innocent explanations, so the signal is unusually specific.
D3FEND divides Decoy Object into six sub-techniques:3
| D3FEND technique | ID | What it covers |
|---|---|---|
| Decoy User Credential | D3-DUC | Usernames, passwords, keys, and other credentials created to deceive an adversary |
| Decoy Session Token | D3-DST | Authentication tokens created to deceive an adversary |
| Decoy File | D3-DF | Documents and other files created to deceive an adversary |
| Decoy Persona | D3-DP | Online identities created to mislead, deceive, or interact with adversaries |
| Decoy Network Resource | D3-DNR | Network resources, such as services and endpoints, deployed to deceive an adversary |
| Decoy Public Release | D3-DPR | Publicly released media issued to deceive adversaries |
What is a honeypot?
A honeypot is a decoy system or service that an adversary can connect to and interact with. The definition NIST publishes from CNSSI 4009 describes a system or system resource designed to attract potential adversaries “like honey is attractive to bears”.6 The Australian Cyber Security Centre describes a honeypot as a computer system designed to attract malicious actors so defenders can develop better defensive measures and responses.7
ENISA adds the defining property: a honeypot’s only job is to be probed, attacked, or accessed without authorisation, so anyone using it is suspicious by definition.8
Low-interaction and high-interaction honeypots
ENISA classifies honeypots by how much they let an adversary do:8
- Low-interaction honeypots emulate services or applications. They are cheaper and safer to run, but emulation is easier to tell apart from a real system.
- High-interaction honeypots run real operating systems and services. They capture richer behaviour, but they give an adversary a real system to use, so they need strong isolation and close monitoring.
ENISA also separates server-side honeypots, which wait for incoming connections, from client-side honeypots, which actively connect to services to find malicious servers or content.8
Honeynets
A honeynet is a network of honeypots. D3FEND describes three arrangements:4
- Integrated Honeynet (D3-IHN): decoys placed inside a production environment.
- Connected Honeynet (D3-CHN): a decoy environment connected to the enterprise network that simulates some functionality without exposing production systems.
- Standalone Honeynet (D3-SHN): a decoy environment with no connection to production systems.
The Honeynet Project, a non-profit security research organisation founded in 1999, publishes open research and open-source tools in this area.9
Where honeypots fit today
Honeypot security depends heavily on placement:
- Internet-facing honeypots see a constant stream of automated scanning. That is valuable for research and threat intelligence, but it rarely gives early warning of an attack aimed at your organisation.
- Internal honeypots sit inside the network where nothing legitimate should connect to them. A connection is a strong sign of internal reconnaissance or lateral movement, which MITRE ATT&CK tracks as techniques such as Remote System Discovery (T1018) and Network Service Discovery (T1046).1011
An enterprise honeypot also needs an owner, a maintenance plan, and a response workflow. A honeypot that nobody monitors is a liability, not a sensor.
What is a honeytoken?
A honeytoken is a decoy piece of data rather than a decoy system. In a 2003 article, Lance Spitzner described honeytokens as records or files with no legitimate use, so that any access to them signals misuse. His example was a decoy patient record in a hospital database that no legitimate user should ever open.12
Common honeytokens include:
- decoy credentials, API keys, and connection strings;
- decoy database records and customer entries;
- decoy documents and spreadsheets;
- decoy email addresses;
- decoy session tokens and cookies.
The key difference from a honeypot is location. A honeytoken lives inside real systems, documents, repositories, and workflows, where an adversary is already looking. It detects discovery and use, so it can catch activity that never touches a separate decoy system, such as an adversary testing a stolen credential or an insider browsing records they have no reason to see.
In MITRE ATT&CK terms, honeytokens commonly sit in the path of techniques such as Unsecured Credentials (T1552), Valid Accounts (T1078), File and Directory Discovery (T1083), and Data from Information Repositories (T1213).13141516
A honeytoken only works if its use is observable. Decide in advance what counts as use, where that use will be recorded or reported, and who receives the alert.
What is a canary token?
A canary token is a honeytoken designed to raise an alert by itself. The name comes from the canary in a coal mine: an early warning that something is wrong. Most canary tokens work through a callback. When the token is opened, resolved, or used, it triggers a web request, DNS lookup, or other event that sends an alert.
Common forms include:
- a document that calls home when it is opened;
- a URL or QR code that alerts when it is visited;
- a DNS name that alerts when it is resolved;
- a cloud access key that alerts when someone uses it;
- a configuration file, such as a VPN profile, that alerts when it is used.
Thinkst’s free Canarytokens service is the best-known example. Thinkst describes Canarytokens as digital tripwires that notify you when they are touched, and offers token types including Google Docs and Sheets, QR codes, WireGuard VPN configurations, AWS API keys, AWS S3 buckets, and Office 365 mail bugs.171 Written as one word, “Canarytokens” refers to Thinkst’s service; “canary token” is the general term.
Canary tokens are quick to deploy and easy to understand. Their limits come from the callback: if the callback cannot happen, there is no alert, and automated tools such as link scanners and document previewers can trigger one without a person being involved. Test each token where it will actually live.
Where lures fit
D3FEND lists “lure” as a synonym of Decoy Object.5 In practice, people use “lure” for a decoy placed to attract interest: a believable credential in a runbook, a sensitive-looking file, or a route that appears to lead somewhere valuable. Treat it as another word for a decoy object rather than a separate category.
Cyber deception vs honeypots
Cyber deception, sometimes called deception technology, is the broader practice. It covers choosing an objective, placing decoys of every kind along likely adversary paths, monitoring interaction, and routing the result into investigation and response. A honeypot is one technique within that practice.
The choice of decoy should follow the adversary’s path. If that path runs through stolen credentials, cloud access, or sensitive data rather than network scanning, a standalone honeypot may never see it. A decoy credential in a repository or a decoy file next to real data sits directly on that path. A practical approach is to combine lightweight decoy objects close to real assets with a small number of carefully placed decoy systems.
The UK National Cyber Security Centre’s 2025 cyber deception trials found that deception can work but is not plug-and-play, and that its effectiveness depends on having the right data, context, and strategy.18 That applies to every term in this guide.
How the terms map to MITRE D3FEND
| Common term | D3FEND technique | ID |
|---|---|---|
| Honeypot, decoy system | Decoy Environment | D3-DE |
| Honeypot inside production | Integrated Honeynet | D3-IHN |
| Honeynet connected to the enterprise network | Connected Honeynet | D3-CHN |
| Isolated honeynet | Standalone Honeynet | D3-SHN |
| Decoy, lure, or honeytoken in general | Decoy Object | D3-DO |
| Honey credential, decoy credential, canary access key | Decoy User Credential | D3-DUC |
| Decoy session or authentication token | Decoy Session Token | D3-DST |
| Canary document, honeyfile, decoy file | Decoy File | D3-DF |
| Decoy persona or identity | Decoy Persona | D3-DP |
| Decoy service, endpoint, or storage location | Decoy Network Resource | D3-DNR |
| Deliberately published decoy information | Decoy Public Release | D3-DPR |
Which one should you use?
Start with the behaviour you want to detect, then choose the decoy that sits on that path.
| If you want to detect | Start with | Why |
|---|---|---|
| Stolen or leaked credentials being tested | Decoy credentials (honeytokens) | They sit where credentials leak and alert when used |
| Someone opening sensitive documents or records | Decoy files or records with built-in alerting | They detect access directly, including by insiders |
| Internal reconnaissance and lateral movement | Decoy services or internal honeypots | Nothing legitimate should connect to them |
| Misuse of cloud access | Decoy cloud credentials and resources | They sit on cloud discovery and data-access paths |
| Opportunistic internet scanning | Internet-facing honeypots | Useful for research and threat intelligence |
| Suspicious AI-agent activity | Decoy credentials, documents, APIs, or MCP surfaces | They reveal actions outside an agent’s approved task |
Whatever you choose, keep the first deployment narrow, make sure an alert has somewhere to go, and test it before relying on it. The cyber deception readiness checklist covers how to choose and prepare a first use case.
For worked examples, see identity-led deception for cloud credential compromise, FIRCY for AWS environments, and detecting rogue AI agents with cyber deception.
Common mistakes
- Calling everything a honeypot. It blurs requirements and procurement. Say what the decoy is and what behaviour it should reveal.
- Placing a honeypot far from real adversary paths. An isolated system on the internet mostly sees automated scanning.
- Deploying tokens with nowhere to send the alert. A decoy without an owner and a response workflow is just a fake object.
- Using real data or real credentials as decoys. A decoy should create evidence, not access.
- Forgetting normal automation. Scanners, backup tools, indexers, and link previewers can all touch decoys. Understand them before setting severity.
- Never testing. Trigger every decoy in an authorised test and confirm the alert reaches the right person with enough context to act.
How FIRCY uses these terms
FIRCY uses decoy as the umbrella term, consistent with MITRE D3FEND and NIST SP 800-53 Revision 5. FIRCY still uses honeypot, honeytoken, and canary token where they describe a specific type, because they are how many teams search for and talk about deception.
FIRCY Sense uses cyber deception for active defence. Decoy credentials, documents, services, and other signals are placed where adversaries are likely to look, and each interaction becomes early-warning evidence that teams can route into existing SIEM, SOAR, ticketing, and response workflows.
To see how this fits a wider defensive strategy, read What is active defence in cyber security?.
Related FIRCY resources
- What is active defence in cyber security?
- Cyber deception readiness checklist
- Identity-led deception for cloud credential compromise
- Detecting rogue AI agents with cyber deception
- FIRCY for AWS environments
- FIRCY Sense platform
Ready to put a decoy on a real adversary path? Apply for a FIRCY Sense trial and bring one behaviour you want to detect.
Sources and further reading
-
Thinkst, “Canarytokens documentation”, https://docs.canarytokens.org/guide/ ↩︎ ↩︎
-
NIST, “Security and Privacy Controls for Information Systems and Organizations”, SP 800-53 Revision 5, control SC-26 Decoys, https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf. The Revision 4 name, SC-26 Honeypots, is shown at CSF Tools, https://csf.tools/reference/nist-sp-800-53/r5/sc/sc-26/ ↩︎
-
MITRE D3FEND, “Deceive”, https://d3fend.mitre.org/tactic/d3f:Deceive/ ↩︎ ↩︎
-
MITRE D3FEND, “Decoy Environment”, https://d3fend.mitre.org/technique/d3f:DecoyEnvironment/ ↩︎ ↩︎ ↩︎
-
MITRE D3FEND, “Decoy Object”, https://d3fend.mitre.org/technique/d3f:DecoyObject/ ↩︎ ↩︎ ↩︎
-
NIST Computer Security Resource Center, Glossary, “honeypot” (from CNSSI 4009-2022), https://csrc.nist.gov/glossary/term/honeypot ↩︎
-
Australian Cyber Security Centre, Glossary, “honeypot”, https://www.cyber.gov.au/learn-basics/view-resources/glossary/h ↩︎
-
ENISA, “Proactive detection of security incidents II: Honeypots”, November 2012, https://www.enisa.europa.eu/publications/proactive-detection-of-security-incidents-II-honeypots ↩︎ ↩︎ ↩︎
-
The Honeynet Project, “About”, https://www.honeynet.org/about/ ↩︎
-
MITRE ATT&CK, “Remote System Discovery”, https://attack.mitre.org/techniques/T1018/ ↩︎
-
MITRE ATT&CK, “Network Service Discovery”, https://attack.mitre.org/techniques/T1046/ ↩︎
-
Lance Spitzner, “Honeytokens: The Other Honeypot”, SecurityFocus, July 2003, summarised at https://it.slashdot.org/story/03/07/17/2049234/honeytokens-the-other-honeypot ↩︎
-
MITRE ATT&CK, “Unsecured Credentials”, https://attack.mitre.org/techniques/T1552/ ↩︎
-
MITRE ATT&CK, “Valid Accounts”, https://attack.mitre.org/techniques/T1078/ ↩︎
-
MITRE ATT&CK, “File and Directory Discovery”, https://attack.mitre.org/techniques/T1083/ ↩︎
-
MITRE ATT&CK, “Data from Information Repositories”, https://attack.mitre.org/techniques/T1213/ ↩︎
-
Thinkst Canary, “Canarytoken Overview and Use Cases”, https://help.canary.tools/hc/en-gb/articles/10905485310109-Canarytoken-Overview-and-Use-Cases ↩︎
-
UK National Cyber Security Centre, “Cyber deception trials: what we’ve learned so far”, 11 December 2025, https://www.ncsc.gov.uk/blog-post/cyber-deception-trials-what-weve-learned-so-far ↩︎