Decoys vs Honeypots vs Honeytokens vs Canary Tokens

Decoys, honeypots, honeytokens, and canary tokens are often used as if they mean the same thing. They overlap, but they are not interchangeable, and the differences matter when you are deciding what to deploy, what telemetry you need, and what a triggered alert actually tells you.

Decoy is the umbrella term. A honeypot is a decoy system or network. Honeytokens and canary tokens are decoy objects, such as credentials, files, records, and links, that reveal when someone finds and uses them.

This guide explains each term, maps them to MITRE D3FEND’s deception techniques, and gives a practical way to choose between them.

Quick answer: A decoy is any object or environment created to deceive an adversary and reveal their activity. A honeypot is a decoy system or service that an adversary can connect to and interact with. A honeytoken is a decoy piece of data, such as a credential, database record, or document, that has no legitimate use, so any use of it is suspicious. A canary token is a honeytoken designed to raise an alert by itself, usually through a callback such as a web request, DNS lookup, or API call. MITRE D3FEND groups honeypots and honeynets under Decoy Environment, and honeytokens and canary tokens under Decoy Object.

The short answer

Term What it is A trigger usually means MITRE D3FEND
Decoy Any object or environment created to deceive an adversary Someone interacted with something that has no legitimate use Decoy Object and Decoy Environment
Honeypot A decoy system or service an adversary can connect to Someone probed, connected to, or used a system that has no legitimate users Decoy Environment (D3-DE)
Honeynet A network of honeypots As above, across several decoy systems Integrated, Connected, and Standalone Honeynet
Honeytoken A decoy piece of data, such as a credential, record, file, or link Someone found it and used or opened it Decoy Object (D3-DO) and its sub-techniques
Canary token A honeytoken that alerts by itself through a callback The token was opened, resolved, or used Decoy Object, usually Decoy File or Decoy User Credential
Lure Another word for a decoy object Depends on the object Listed by D3FEND as a synonym of Decoy Object

The rest of this guide explains each term and how to choose between them.

Why the terms get mixed up

“Honeypot” is the most familiar term, so it is often used for any kind of deception. Product names add to the confusion. Thinkst, for example, offers a commercial product called Thinkst Canary and a free service called Canarytokens, so “canary” has become shorthand for a whole category.1

Standards have moved towards “decoy”. NIST SP 800-53 Revision 4 named control SC-26 “Honeypots”. Revision 5 renamed it “Decoys”: components designed to be the target of malicious attacks so those attacks can be detected, deflected, and analysed, with honeypots, honeynets, and deception nets given as examples.2

MITRE D3FEND’s Deceive tactic is built around two techniques, Decoy Environment and Decoy Object. It lists “Honeypot” as a synonym of Decoy Environment and “Lure” as a synonym of Decoy Object.345

What is a decoy?

A decoy is anything created and placed to deceive an adversary, so that interacting with it reveals their activity. D3FEND splits decoys into two groups:

  • Decoy Environment (D3-DE): hosts and networks built to deceive an adversary. This is where honeypots and honeynets sit.4
  • Decoy Object (D3-DO): individual objects created and deployed to deceive, such as credentials, files, tokens, personas, and network resources.5

The property that makes every decoy useful is the same: it has no legitimate business purpose. A failed sign-in to a real account might be a typo. An attempt to use a credential that exists only as a decoy has very few innocent explanations, so the signal is unusually specific.

D3FEND divides Decoy Object into six sub-techniques:3

D3FEND technique ID What it covers
Decoy User Credential D3-DUC Usernames, passwords, keys, and other credentials created to deceive an adversary
Decoy Session Token D3-DST Authentication tokens created to deceive an adversary
Decoy File D3-DF Documents and other files created to deceive an adversary
Decoy Persona D3-DP Online identities created to mislead, deceive, or interact with adversaries
Decoy Network Resource D3-DNR Network resources, such as services and endpoints, deployed to deceive an adversary
Decoy Public Release D3-DPR Publicly released media issued to deceive adversaries

What is a honeypot?

A honeypot is a decoy system or service that an adversary can connect to and interact with. The definition NIST publishes from CNSSI 4009 describes a system or system resource designed to attract potential adversaries “like honey is attractive to bears”.6 The Australian Cyber Security Centre describes a honeypot as a computer system designed to attract malicious actors so defenders can develop better defensive measures and responses.7

ENISA adds the defining property: a honeypot’s only job is to be probed, attacked, or accessed without authorisation, so anyone using it is suspicious by definition.8

Low-interaction and high-interaction honeypots

ENISA classifies honeypots by how much they let an adversary do:8

  • Low-interaction honeypots emulate services or applications. They are cheaper and safer to run, but emulation is easier to tell apart from a real system.
  • High-interaction honeypots run real operating systems and services. They capture richer behaviour, but they give an adversary a real system to use, so they need strong isolation and close monitoring.

ENISA also separates server-side honeypots, which wait for incoming connections, from client-side honeypots, which actively connect to services to find malicious servers or content.8

Honeynets

A honeynet is a network of honeypots. D3FEND describes three arrangements:4

  • Integrated Honeynet (D3-IHN): decoys placed inside a production environment.
  • Connected Honeynet (D3-CHN): a decoy environment connected to the enterprise network that simulates some functionality without exposing production systems.
  • Standalone Honeynet (D3-SHN): a decoy environment with no connection to production systems.

The Honeynet Project, a non-profit security research organisation founded in 1999, publishes open research and open-source tools in this area.9

Where honeypots fit today

Honeypot security depends heavily on placement:

  • Internet-facing honeypots see a constant stream of automated scanning. That is valuable for research and threat intelligence, but it rarely gives early warning of an attack aimed at your organisation.
  • Internal honeypots sit inside the network where nothing legitimate should connect to them. A connection is a strong sign of internal reconnaissance or lateral movement, which MITRE ATT&CK tracks as techniques such as Remote System Discovery (T1018) and Network Service Discovery (T1046).1011

An enterprise honeypot also needs an owner, a maintenance plan, and a response workflow. A honeypot that nobody monitors is a liability, not a sensor.

What is a honeytoken?

A honeytoken is a decoy piece of data rather than a decoy system. In a 2003 article, Lance Spitzner described honeytokens as records or files with no legitimate use, so that any access to them signals misuse. His example was a decoy patient record in a hospital database that no legitimate user should ever open.12

Common honeytokens include:

  • decoy credentials, API keys, and connection strings;
  • decoy database records and customer entries;
  • decoy documents and spreadsheets;
  • decoy email addresses;
  • decoy session tokens and cookies.

The key difference from a honeypot is location. A honeytoken lives inside real systems, documents, repositories, and workflows, where an adversary is already looking. It detects discovery and use, so it can catch activity that never touches a separate decoy system, such as an adversary testing a stolen credential or an insider browsing records they have no reason to see.

In MITRE ATT&CK terms, honeytokens commonly sit in the path of techniques such as Unsecured Credentials (T1552), Valid Accounts (T1078), File and Directory Discovery (T1083), and Data from Information Repositories (T1213).13141516

A honeytoken only works if its use is observable. Decide in advance what counts as use, where that use will be recorded or reported, and who receives the alert.

What is a canary token?

A canary token is a honeytoken designed to raise an alert by itself. The name comes from the canary in a coal mine: an early warning that something is wrong. Most canary tokens work through a callback. When the token is opened, resolved, or used, it triggers a web request, DNS lookup, or other event that sends an alert.

Common forms include:

  • a document that calls home when it is opened;
  • a URL or QR code that alerts when it is visited;
  • a DNS name that alerts when it is resolved;
  • a cloud access key that alerts when someone uses it;
  • a configuration file, such as a VPN profile, that alerts when it is used.

Thinkst’s free Canarytokens service is the best-known example. Thinkst describes Canarytokens as digital tripwires that notify you when they are touched, and offers token types including Google Docs and Sheets, QR codes, WireGuard VPN configurations, AWS API keys, AWS S3 buckets, and Office 365 mail bugs.171 Written as one word, “Canarytokens” refers to Thinkst’s service; “canary token” is the general term.

Canary tokens are quick to deploy and easy to understand. Their limits come from the callback: if the callback cannot happen, there is no alert, and automated tools such as link scanners and document previewers can trigger one without a person being involved. Test each token where it will actually live.

Where lures fit

D3FEND lists “lure” as a synonym of Decoy Object.5 In practice, people use “lure” for a decoy placed to attract interest: a believable credential in a runbook, a sensitive-looking file, or a route that appears to lead somewhere valuable. Treat it as another word for a decoy object rather than a separate category.

Cyber deception vs honeypots

Cyber deception, sometimes called deception technology, is the broader practice. It covers choosing an objective, placing decoys of every kind along likely adversary paths, monitoring interaction, and routing the result into investigation and response. A honeypot is one technique within that practice.

The choice of decoy should follow the adversary’s path. If that path runs through stolen credentials, cloud access, or sensitive data rather than network scanning, a standalone honeypot may never see it. A decoy credential in a repository or a decoy file next to real data sits directly on that path. A practical approach is to combine lightweight decoy objects close to real assets with a small number of carefully placed decoy systems.

The UK National Cyber Security Centre’s 2025 cyber deception trials found that deception can work but is not plug-and-play, and that its effectiveness depends on having the right data, context, and strategy.18 That applies to every term in this guide.

How the terms map to MITRE D3FEND

Common term D3FEND technique ID
Honeypot, decoy system Decoy Environment D3-DE
Honeypot inside production Integrated Honeynet D3-IHN
Honeynet connected to the enterprise network Connected Honeynet D3-CHN
Isolated honeynet Standalone Honeynet D3-SHN
Decoy, lure, or honeytoken in general Decoy Object D3-DO
Honey credential, decoy credential, canary access key Decoy User Credential D3-DUC
Decoy session or authentication token Decoy Session Token D3-DST
Canary document, honeyfile, decoy file Decoy File D3-DF
Decoy persona or identity Decoy Persona D3-DP
Decoy service, endpoint, or storage location Decoy Network Resource D3-DNR
Deliberately published decoy information Decoy Public Release D3-DPR

Which one should you use?

Start with the behaviour you want to detect, then choose the decoy that sits on that path.

If you want to detect Start with Why
Stolen or leaked credentials being tested Decoy credentials (honeytokens) They sit where credentials leak and alert when used
Someone opening sensitive documents or records Decoy files or records with built-in alerting They detect access directly, including by insiders
Internal reconnaissance and lateral movement Decoy services or internal honeypots Nothing legitimate should connect to them
Misuse of cloud access Decoy cloud credentials and resources They sit on cloud discovery and data-access paths
Opportunistic internet scanning Internet-facing honeypots Useful for research and threat intelligence
Suspicious AI-agent activity Decoy credentials, documents, APIs, or MCP surfaces They reveal actions outside an agent’s approved task

Whatever you choose, keep the first deployment narrow, make sure an alert has somewhere to go, and test it before relying on it. The cyber deception readiness checklist covers how to choose and prepare a first use case.

For worked examples, see identity-led deception for cloud credential compromise, FIRCY for AWS environments, and detecting rogue AI agents with cyber deception.

Common mistakes

  • Calling everything a honeypot. It blurs requirements and procurement. Say what the decoy is and what behaviour it should reveal.
  • Placing a honeypot far from real adversary paths. An isolated system on the internet mostly sees automated scanning.
  • Deploying tokens with nowhere to send the alert. A decoy without an owner and a response workflow is just a fake object.
  • Using real data or real credentials as decoys. A decoy should create evidence, not access.
  • Forgetting normal automation. Scanners, backup tools, indexers, and link previewers can all touch decoys. Understand them before setting severity.
  • Never testing. Trigger every decoy in an authorised test and confirm the alert reaches the right person with enough context to act.

How FIRCY uses these terms

FIRCY uses decoy as the umbrella term, consistent with MITRE D3FEND and NIST SP 800-53 Revision 5. FIRCY still uses honeypot, honeytoken, and canary token where they describe a specific type, because they are how many teams search for and talk about deception.

FIRCY Sense uses cyber deception for active defence. Decoy credentials, documents, services, and other signals are placed where adversaries are likely to look, and each interaction becomes early-warning evidence that teams can route into existing SIEM, SOAR, ticketing, and response workflows.

To see how this fits a wider defensive strategy, read What is active defence in cyber security?.

Ready to put a decoy on a real adversary path? Apply for a FIRCY Sense trial and bring one behaviour you want to detect.

Sources and further reading


  1. Thinkst, “Canarytokens documentation”, https://docs.canarytokens.org/guide/ ↩︎ ↩︎

  2. NIST, “Security and Privacy Controls for Information Systems and Organizations”, SP 800-53 Revision 5, control SC-26 Decoys, https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf. The Revision 4 name, SC-26 Honeypots, is shown at CSF Tools, https://csf.tools/reference/nist-sp-800-53/r5/sc/sc-26/ ↩︎

  3. MITRE D3FEND, “Deceive”, https://d3fend.mitre.org/tactic/d3f:Deceive/ ↩︎ ↩︎

  4. MITRE D3FEND, “Decoy Environment”, https://d3fend.mitre.org/technique/d3f:DecoyEnvironment/ ↩︎ ↩︎ ↩︎

  5. MITRE D3FEND, “Decoy Object”, https://d3fend.mitre.org/technique/d3f:DecoyObject/ ↩︎ ↩︎ ↩︎

  6. NIST Computer Security Resource Center, Glossary, “honeypot” (from CNSSI 4009-2022), https://csrc.nist.gov/glossary/term/honeypot ↩︎

  7. Australian Cyber Security Centre, Glossary, “honeypot”, https://www.cyber.gov.au/learn-basics/view-resources/glossary/h ↩︎

  8. ENISA, “Proactive detection of security incidents II: Honeypots”, November 2012, https://www.enisa.europa.eu/publications/proactive-detection-of-security-incidents-II-honeypots ↩︎ ↩︎ ↩︎

  9. The Honeynet Project, “About”, https://www.honeynet.org/about/ ↩︎

  10. MITRE ATT&CK, “Remote System Discovery”, https://attack.mitre.org/techniques/T1018/ ↩︎

  11. MITRE ATT&CK, “Network Service Discovery”, https://attack.mitre.org/techniques/T1046/ ↩︎

  12. Lance Spitzner, “Honeytokens: The Other Honeypot”, SecurityFocus, July 2003, summarised at https://it.slashdot.org/story/03/07/17/2049234/honeytokens-the-other-honeypot ↩︎

  13. MITRE ATT&CK, “Unsecured Credentials”, https://attack.mitre.org/techniques/T1552/ ↩︎

  14. MITRE ATT&CK, “Valid Accounts”, https://attack.mitre.org/techniques/T1078/ ↩︎

  15. MITRE ATT&CK, “File and Directory Discovery”, https://attack.mitre.org/techniques/T1083/ ↩︎

  16. MITRE ATT&CK, “Data from Information Repositories”, https://attack.mitre.org/techniques/T1213/ ↩︎

  17. Thinkst Canary, “Canarytoken Overview and Use Cases”, https://help.canary.tools/hc/en-gb/articles/10905485310109-Canarytoken-Overview-and-Use-Cases ↩︎

  18. UK National Cyber Security Centre, “Cyber deception trials: what we’ve learned so far”, 11 December 2025, https://www.ncsc.gov.uk/blog-post/cyber-deception-trials-what-weve-learned-so-far ↩︎


Frequently asked questions

What is the difference between a honeypot and a honeytoken?

A honeypot is a decoy system or service that an adversary can probe or interact with. A honeytoken is a decoy piece of data, such as a credential, database record, document, or link, placed inside real systems and workflows. A honeypot shows what an adversary does when they reach a decoy system. A honeytoken shows that someone found and used something they should never have touched.

Is a canary token the same as a honeytoken?

A canary token is a type of honeytoken built to raise an alert by itself, usually through a callback such as a web request, DNS lookup, or API call. Canarytokens, written as one word, is also the name of a free service from Thinkst.

Is cyber deception the same as a honeypot?

No. A honeypot is one deception technique. Cyber deception is the broader practice of planning, placing, monitoring, and responding to decoys of every kind, including honeypots, decoy credentials, decoy files, decoy personas, and decoy network resources.

Why use the term decoy instead of honeypot?

Decoy covers every type of deception object and environment without implying a particular product or design. MITRE D3FEND uses Decoy Object and Decoy Environment, and NIST renamed its honeypot control, SC-26, to Decoys in SP 800-53 Revision 5.

Are honeypots still useful?

Yes, for the right job. Internal honeypots are useful for detecting reconnaissance and lateral movement, because nothing legitimate should connect to them. Internet-facing honeypots are better suited to research and threat intelligence than to early warning of a targeted attack. Every honeypot needs isolation, maintenance, and an owner.

Which should we deploy first?

Start with the behaviour you want to detect, not the technology. Decoy credentials suit stolen or leaked credentials. Decoy files and records with built-in alerting suit sensitive document access. Decoy services and internal honeypots suit internal discovery and lateral movement.

Can honeytokens and canary tokens detect insiders?

They can, because they detect access and use rather than malware. Insider-focused decoys need legal, privacy, HR, and security review before deployment, and a clear defensive purpose.