Andreas Wolter shares some thoughts:
CISA recently published guidance on using cyber decoys, tripwires, breadcrumbs, and honeytokens to detect attackers who are already operating inside an environment: Using Cyber Decoys to Strengthen Detection and Response
Looking at this through my SQL Server lens, I think it is worth considering how these concepts can be applied to database systems.
Before building any kind of database honeypot, you need to ask yourself:
Click through for that list of questions, as well as additional thoughts from Andreas.