awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com

Self-Hosted Deception And Decoy Platforms

Ranking updated Jun 30, 2026

For a deception and decoy platform, the strongest matches are telekom-security/tpotce (T-Pot is a multi-honeypot platform that deploys containerized decoy), thinkst/opencanary (OpenCanary is a self-hosted honeypot that simulates multiple network) and dtag-dev-sec/tpotce (T-Pot is a multi-honeypot orchestration platform that deploys decoy). honeytrap/honeytrap and cowrie/cowrie round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Open-source security tools that deploy fake services and honeytokens to detect and analyze unauthorized network activity.

Self-Hosted Deception And Decoy Platforms

Find the best repos with AI.We'll search the best matching repositories with AI.
  • telekom-security/tpotcetelekom-security avatar

    telekom-security/tpotce

    9,298View on GitHub↗

    T-Pot is a multi-honeypot platform and threat intelligence framework that deploys a collection of containerized decoy services to capture attacker behavior and network telemetry. It functions as a Docker-based deception system, simulating vulnerable network environments to gather intelligence on threat actors. The system features a distributed sensor network using a hub-and-spoke architecture, allowing remote sensors to transmit logs back to a central management hub. It integrates large language models to create a dynamic deception engine capable of adaptive interactions with attackers. The

    T-Pot is a multi-honeypot platform that deploys containerized decoy services to detect and log attacker behavior, with Docker-based deployment, threat intelligence integration, and monitoring dashboards — exactly the self-hosted deception platform this search targets.

    ShellMulti-Service HoneypotsNetwork Deception TechnologiesDeceptive Environments
    View on GitHub↗9,298
  • thinkst/opencanarythinkst avatar

    thinkst/opencanary

    2,776View on GitHub↗

    OpenCanary is a network service simulator and honeypot designed for network intrusion detection. It functions as a security decoy that creates fake server personalities and open ports to identify unauthorized users scanning a private network. The system uses deception technology to mimic various server protocols, luring attackers into revealing their presence and activity. When a simulated service is accessed, it acts as an intrusion alerting gateway, transmitting notifications via email or webhooks. The project covers internal network monitoring and intrusion source tracking to identify the

    OpenCanary is a self-hosted honeypot that simulates multiple network services to detect and alert on attacker activity, fitting the core need for decoy service emulation and attack detection, though it lacks a built-in real-time dashboard and traffic redirection.

    PythonDecoy ServicesNetwork Deception TechnologiesService Honeypots
    View on GitHub↗2,776
  • dtag-dev-sec/tpotcedtag-dev-sec avatar

    dtag-dev-sec/tpotce

    9,281View on GitHub↗

    T-Pot is a multi-honeypot orchestration platform and threat intelligence collector. It utilizes a Docker-based security sandbox to deploy and manage a collection of diverse decoy services that simulate vulnerable targets to lure attackers and record their activity. The system features a distributed sensor network where remote nodes capture attack logs and transmit them via encrypted communication to a central hub. This central hub employs an analytics stack to transform raw logs into geographic maps and interactive dashboards for adversary behavior visualization. To increase the realism of si

    T-Pot is a multi-honeypot orchestration platform that deploys decoy services to detect and log attacker activity, with Docker-based easy deployment, real-time dashboards, and support for multiple protocols — exactly the self-hosted deception platform with attack detection and network deception you're looking for.

    ShellDecoy ServicesDecoy Service Deployments
    View on GitHub↗9,281
  • honeytrap/honeytraphoneytrap avatar

    honeytrap/honeytrap

    1,299View on GitHub↗

    Advanced Honeypot framework.

    Honeytrap is a Go-based honeypot framework that emulates decoy services to detect attackers, fitting the category of a self-hosted deception platform. You can deploy it on-premises to run various protocol honeypots, though it may lack a built-in monitoring dashboard or Docker packaging.

    GoService Honeypots
    View on GitHub↗1,299
  • cowrie/cowriecowrie avatar

    cowrie/cowrie

    6,181View on GitHub↗

    .. SPDX-FileCopyrightText: 2014 Upi Tamminen .. SPDX-FileCopyrightText: 2014-2025 Michel Oosterhof .. .. SPDX-License-Identifier: BSD-3-Clause

    Cowrie is a well-known SSH and telnet honeypot that emulates decoy services and logs attacker activity, fitting the self-hosted honeypot category; however, it focuses on SSH/telnet and may lack a built-in monitoring dashboard, so it's a solid match but not the most comprehensive platform.

    PythonAttackerAttacker File TransfersAttacker Shell Command Loggers
    View on GitHub↗6,181
  • mushorg/conpotmushorg avatar

    mushorg/conpot

    1,489View on GitHub↗

    ICS/SCADA honeypot

    Conpot is a self-hosted honeypot that emulates ICS/SCADA services to detect and alert on attacks targeting industrial control systems, which fits your query as a deception platform, though its focus on industrial protocols means it may lack broader service emulation and a built-in dashboard.

    PythonHoneypot SystemsHoneypotsHoneypots
    View on GitHub↗1,489
  • citronneur/rdpycitronneur avatar

    citronneur/rdpy

    1,737View on GitHub↗

    Remote Desktop Protocol in Twisted Python

    rdpy is a Python library implementing the RDP protocol, not a full self-hosted deception platform — it could be a building block for a honeypot but lacks the multi-service emulation, detection, dashboard, and easy deployment required for a complete solution.

    PythonService Honeypots
    View on GitHub↗1,737

Related searches

  • Honeypots, Deception and Hardening
  • a honeypot deployment toolkit
  • a threat intelligence platform
  • an intentionally vulnerable cloud environment for practice
  • a phishing simulation platform
  • a disposable email service
  • Disposable email server
  • a malware analysis sandbox