Deception techniques and decoy objects, often called honey items, can be useful in intrusion detection,and attack analysis. Attacks by Advanced Persistent Threats (APTs) have been shown to be difficult to detect due tothe stealthy and sophisticated nature of the attack techniques. Structured attacks carried out over a period of timeare difficult for traditional defences to detect. Using deception techniques and honey items may be a way ofhighlighting these APT actor type interactions as they progress through a structured attack. This work explores theuse of honey items to classify intrusion interactions, differentiating automated attacks from those which need somehuman reasoning and interaction towards APT detection. Multiple decoy items are deployed on honeypots in a virtualhoney network, some as breadcrumbs to detect indications of a structured manual attack. Monitoring functionalitywas created around Elastic Stack with a Kibana dashboard created to display interactions with various honey items.APT type manual intrusions are simulated by an experienced pen testing practitioner carrying out simulated attacks.The results show that it is possible to differentiate automatic attacks from manual structured attacks; from the natureof the interactions with the honey items. The use of honey items found in the honeypot, such as in later parts of astructured attack, have been shown to be successful in classification of manual attacks, as well as towards providingan indication of severity of the attacks.