Spot defensive deception during an authorized engagement before you trigger it — canarytokens (HTTP/DNS/AWS-key/document/Slack/kubeconfig), Active Directory honey accounts and Kerberoast bait, decoy files, and honeypots — using provenance discipline and telltale patterns so a planted tripwire does not burn the operation. Use before acting on found credentials, roasting an SPN, or opening a too-convenient file. Unattributable access is a trap until proven otherwise; if you cannot say where it came from, do not use it.