No techniques match this filter.
MAPPING THE DECEPTION SURFACE IN MITRE ATT&CK

Decoys cannot
go everywhere

32%
80 of 250 techniques
admit a decoy.
The other 170 admit none.

Cyber deception research commonly assumes a decoy can be placed wherever there is attacker behavior. We scored feasibility against ATT&CK v18.1, and we found the deception surface to be smaller than expected.

A decoy must sit on a sweep path or imitate a sought asset.
Outside both, it goes untouched, however convincing it is.
ATT&CK v18.1
HIGH FEASIBILITY MEDIUM NO DECOY POSSIBLE
TACTICS WITH MORE DECEPTION SURFACE
Discovery, execution, credential access, collection: phases where the attacker sweeps broadly or hunts a named asset, and touches something the defender can fabricate.
WHY 170 ADMIT NONE
The behavior runs on attacker-owned resources. Preparation, command channels and data-out routes never touch a defender asset. Or the attacker acts only on what they already hold: obfuscating code, editing timestamps, disabling tools on a host already compromised.
TAKEAWAY FOR DEFENDERS
Map first, deploy second. Focus on which attacker behaviors can yield more visibility and intelligence, and judge placements by interaction likelihood and malice fidelity before spending. Quality beats quantity.
COMPANION TO   Valeros, V., Catania, C., Lisý, V., Griffioen, H. (2026). “Decoys Cannot Go Everywhere: Mapping the Deception Surface in MITRE ATT&CK”. Data: CC BY 4.0 · Code: MIT
Research not affiliated or endorsed by MITRE. ATT&CK® is a registered trademark of The MITRE Corporation.