Cyber deception is one of the most powerful and least understood defensive disciplines, most practitioners have read about honeypots, but few have ever deployed a breadcrumb, watched an attacker chase a fake credential, or felt the confusion deception causes from the attacker's side.
This session shares the fundamentals of deception by doing and experiencing: what deceptive artifacts exist (honey-credentials, deceptive configs, honey-services, synthetic activity), where they belong in a real environment, what telemetry they generate, and how they change an adversary's behavior. Everything is practiced in an open-source, Docker-based playground that recreates a realistic multi-tier company, with an attacker toolkit on one side and a defender SIEM on the other, so attendees can safely play both roles.
The 25-minute format is a guided demo; the 50-minute format is a hands-on lab.
Presented at La Villa Hacker — DEF CON 2026