Deception Defense
Deception technology that turns an attacker's move into an alarm
The fastest way to know an attacker is inside is to leave something they can't resist touching — and to make sure no one else ever would. Immune plants decoy files and traps across your environment so the moment ransomware reaches for them, you have near-certain proof of an attack, often before a single real file is harmed.
Immune's deception engine detects ransomware in about two seconds with almost no false positives: any interaction with a decoy is a near-certain attack signal, because legitimate users never touch it.
Why deception is one of the most reliable signals in security
Most detection faces an inherent difficulty: it has to separate a tiny amount of malicious activity from an enormous amount of legitimate activity, and every judgment call risks either missing an attack or crying wolf. Deception sidesteps that problem entirely. A decoy file — a canary — is placed where an attacker will find it but where no legitimate workflow ever goes. It looks like a valuable target: a patient archive, a credentials file, a backup index. But it is bait. Because no real user or application has any reason to open it, the act of touching it is itself the alarm. There is nothing to analyze and almost nothing to get wrong.
This gives deception two qualities that are rare together: it is extraordinarily fast and extraordinarily precise. When ransomware sweeps through a directory encrypting everything, it hits the canary almost immediately, and Immune has a high-confidence signal within roughly two seconds — frequently before the bulk of real files are affected. And because the signal is so unambiguous, it carries almost no false positives, sparing security teams the alert fatigue that plagues noisier methods. Independent security research consistently finds deception among the earliest and most reliable ways to detect an attack in progress.
See it in action
The deception console shows every canary deployed, its zone, trip status, and the confidence signal it raised — all in real time.

Features
What the deception engine provides
Realistic canary files
Decoys crafted to look exactly like the real clinical and business documents attackers seek.
Strategic placement
Traps positioned along the paths attackers actually take — shares, high-value directories, staging points.
Instant high-confidence signal
Any interaction triggers an immediate alert treated as a near-certain attack.
Decoy services & credentials
Beyond files, deception extends to lure services and credentials that expose reconnaissance.
Invisible to real users
Legitimate workflows never touch the decoys, so clinical operations are unaffected.
Continuously rotated
Names, locations, and signatures shift so attackers can't learn and avoid the traps.
How it works
How canary defense works
Plant the decoys
Immune places realistic canary files and lures across shares, high-value directories, and likely attacker paths.
Blend in perfectly
Decoys are indistinguishable from real assets to an attacker, while remaining invisible to legitimate workflows.
Wait for the touch
The traps sit quietly. Because no real user has any reason to open them, they generate no noise.
Fire on interaction
The instant ransomware reads, modifies, or encrypts a decoy, Immune raises a high-confidence signal — in about two seconds.
Ignite the response
The signal elevates detection confidence and can immediately trigger containment before encryption spreads.
Advantages
The advantages of deception-first detection
Speed where it counts
Catches encryption in its first seconds, buying time to contain without disruption.
Near-zero false positives
The signal is unambiguous, so it never buries teams in noise or interrupts care.
Catches novel attacks
Deception doesn't rely on recognizing known malware — it catches whatever touches the trap.
Ignites the whole loop
A hit raises detection confidence and can trigger immediate containment.
A layer most tools omit
Deception is the fourth detection category many platforms skip — Immune makes it first-class.
Unpredictable to attackers
Continuous rotation means recon can't map and avoid the decoys.
Use cases
Where deception proves its value
File-share ransomware
Canaries in shared directories catch mass-encryption in its first moments.
Backup protection
Decoys around backup stores expose attackers hunting for recovery points to destroy.
Lateral-movement detection
Lure services reveal attackers probing the network for their next hop.
Credential-theft traps
Decoy credentials expose reconnaissance and privilege-escalation attempts.
Why it matters in healthcare
The detection layer that buys you time
In a hospital, every minute of a spreading attack carries a real clinical and financial cost. Deception delivers something the other detection methods cannot: a signal so clean and so fast that it can trigger containment almost the instant an attacker begins to act. It is the perfect ignition for the rest of Immune's loop — a canary hit does not just raise an alert; it elevates confidence, tightens the boundary, and starts containment before encryption spreads beyond the first directory. It is the tripwire that sets the whole immune response in motion.
Common questions
Deception technology and canary defense, answered
+How do canary files detect ransomware?
Canary files are decoys that look like real documents but are never used by legitimate workflows. Because no genuine user or process should ever touch them, any attempt to read, modify, or encrypt one is an almost certain sign of an attacker — giving a high-confidence alert within about two seconds, often before real files are affected.
+What is deception technology?
Deception technology plants traps — decoy files, services, and credentials — throughout an environment to lure and expose attackers. Because interacting with a decoy has no legitimate purpose, deception produces extremely reliable, low-false-positive signals that an intrusion is underway.
+Why is deception faster than other detection methods?
Most detection has to distinguish malicious activity from a huge volume of legitimate activity, which takes analysis and risks false positives. A canary hit needs no such analysis — the interaction itself is the signal — so deception is among the fastest, highest-confidence ways to detect an attack.
+Can attackers avoid the traps?
Immune makes decoys indistinguishable from real assets and continuously rotates their names, locations, and characteristics through its moving-target defense, so an attacker cannot reliably learn which files are traps and avoid them.
+Does deception interfere with clinical workflows?
No. Decoys are placed where attackers go but where legitimate users never do, so day-to-day clinical work is completely unaffected and no false alarms interrupt care.
+What happens the moment a canary is triggered?
A canary interaction is treated as a high-confidence attack signal. It raises the detection engine's confidence, can immediately tighten the boundary around the affected area, and can trigger containment before encryption spreads beyond the first directory.
Explore the platform
Related capabilities
Catch ransomware in its first two seconds
Book a demo and watch a canary trap expose a simulated attack instantly — and trigger containment before real files are touched.
