Share via

Deception Capability in Defender

Alyse Hart 90 Reputation points
2025-03-04T21:26:46.4633333+00:00

I'm looking at testing out the Deception Capability in Defender XDR, but had a question in regard to the alerting and response in the event a lure or decoy is accessed on a device. If an alert is generated as a result of a Deception Rule match, are there any automated AIR response investigations or actions taken on those devices? or is this just more of a canary/honey token type of alert?

Community Center | Not monitored
0 comments No comments

1 answer

Sort by: Most helpful
  1. Alyse Hart 90 Reputation points
    2025-03-10T20:47:26.4+00:00

    Validated and tested that these alerts do not trigger and AIR response investigation.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.